Simplify the art of digital forensics and analysis with Kali Linux
About This Video
Learn and practice through various tools and techniques that leverage the Kali Linux distribution
Extract and recover data and perform successful forensic analysis and investigations
Perform professional-quality forensics through ethical means, and solve forensic challenges in real-world scenarios
Kali Linux is the most comprehensive distributions for penetration testing and ethical hacking. It has some of the most popular forensics tools available to conduct formal forensics and investigations and perform professional-level forensics.
This video course teaches you all about the forensic analysis of computers and mobile devices that leverage the Kali Linux distribution. You’ll get hands-on, seeing how to conduct each phase of the digital forensics process: acquisition, extraction, analysis, and presentation, using the rich set of open source tools that Kali Linux provides for each activity.
We start by showing you how to use the tools (dc3dd in particular) to acquire images from the media to be analyzed, either hard drives, mobile devices, thumb drives, or memory cards. The course presents the Autopsy forensic suite and other specialized tools,such as the Sleuth Kit and RegRipper, to extract and analyze various artifacts from a Windows image. It also shows how to perform the analysis of an Android device image using Autopsy. Next, we cover file carving and the recovery of deleted data, and then the process of acquiring and analyzing RAM memory (live analysis) using the Volatility framework.
Another topic is treated in the course, that is network forensics; indeed, the course covers how to capture and analyze network data packets, with tools like Wireshark and Xplico.
Finally, we demonstrate how to report and present digital evidence found during the analysis. By the end of the course, you will be able to extract and recover data, analyze the acquired data, and report and present digital evidence from a device.
- 1. The Course Overview
- 2. Brief Introduction to Digital Forensics
- 3. Downloading and Installing Kali Linux
- 4. Introduction to Forensic Imaging
- 5. Overview of dcfldd and dc3dd
- 6. Drive Imaging with dc3dd
- 7. Android Device Imaging with dc3dd
- 8. Image Acquisition with Guymager
- 9. Overview of the Sleuth Kit and Filesystem Analysis
- 10. Windows Registry Analysis with RegRipper
- 11. Extracting and Analyzing Browser, E-mail, and IM Artifacts
- 12. File Analysis Tools
- 13. Building a Super-Timeline of the Events
- 14. File Carving Overview
- 15. File Carving Tools
- 16. Extracting Data with Bulk Extractor
- 17. Autopsy 4 Overview and Installation
- 18. Analysis of a Windows Image with Autopsy
- 19. Analysis of an Android Image with Autopsy
- 20. Introduction to Memory Forensics and Acquisition
- 21. Memory Acquisition
- 22. Introduction to Volatility
- 23. Memory Analysis with Volatility
- 24. Introduction to Network Forensics
- 25. Capturing Network Traffic with Wireshark
- 26. Network Traffic Analysis with Wireshark
- 27. Introduction to Reporting
- 28. Documentation and Reporting Tools