Introduction to Digital Forensics
Week 1
What is Digital Forensics?
Types of investigations
Typical investigation phases
Phase 1: Acquisition
Acquisition (2)
Acquisition (3)
Phase 2: Recovery
File systems
File deletion
Slack space
Steganography
Encrypted data
Recovery (cont.)
File residue
Phase 3: Analysis
Contraband material
Locating material
Event reconstruction
Time issues
The needle in the haystack
Compromised system
Unknown executables
Authorship analysis
Phase 4: Presentation
Forensics Tools
DF Investigator Profile
Future in DF
Future in DF (2)
Future in DF (3)
Thank You