1.0 Advanced incident response and digital forensics
Weight not published
- 1.1Analyzing Volatile Malicious Event Artifacts
Understanding abnormal activity within the structure of Windows memory; Identifying artifacts such as malicious processes, suspicious drivers, and malware techniques such as code injection and rootkits
- 1.2Analyzing Volatile Windows Event Artifacts
Understanding normal activity within the structure of Windows memory; Identifying artifacts such as network connections, memory resident command line artifacts and processes, handles and threads
- 1.3Enterprise Environment Incident Response
Understanding the steps of the incident response process; Understanding attack progression and adversary fundamentals; Rapidly assessing and analyzing systems in an enterprise environment; Scaling tools to meet the demands of large investigations
- 1.4File System Timeline Artifact Analysis
Understanding the Windows filesystem time structure; Understanding how these artifacts are modified by system and user activity
- 1.5Identification of Malicious System and User Activity
Identifying and documenting indicators of compromise on a system; Detecting malware and attacker tools; Attributing activity to events and accounts; Identifying and compensating for anti-forensic actions using memory and disk resident artifacts
- 1.6Identification of Normal System and User Activity
Identifying, documenting, and differentiating normal and abnormal system and user activity using memory and disk resident artifacts
- 1.7Introduction to File System Timeline Forensics
Understanding the methodology required to collect and process timeline data from a Windows system
- 1.8Introduction to Memory Forensics
Understanding how and when to collect volatile data from a system; Understanding how to document and preserve the integrity of volatile evidence
- 1.9NTFS Artifact Analysis
Understanding core structures of the Windows filesystems; Identifying, recovering, and analyzing evidence from any file system layer, including the data storage layer, metadata layer, and filename layer
- 1.10Windows Artifact Analysis
Understanding Windows system artifacts; Collecting and analyzing data such as system backup and restore data and evidence of application execution