Get in Touch

Course Outline

Introduction to Kali Linux for Forensics

  • Overview of Kali Linux and its forensic capabilities
  • Preparing a forensic-ready laptop
  • Chain of custody protocols and legal considerations

Disk and File System Forensics

  • Acquiring and imaging disks
  • Analyzing file systems using Autopsy and Sleuth Kit
  • Recovering deleted files and uncovering hidden data

Memory and Process Analysis

  • Capturing volatile memory
  • Investigating processes and malware activity
  • Leveraging Volatility for detailed memory analysis

Network Forensics

  • Capturing live network traffic
  • Analyzing packets with Wireshark and tcpdump
  • Tracing intrusion activities and lateral movement

Log and Artifact Analysis

  • Reviewing system and application logs
  • Identifying artifacts indicative of compromise
  • Conducting timeline analysis of incidents

Incident Investigation Workflow

  • Evidence acquisition and validation procedures
  • A step-by-step investigation methodology
  • Documenting findings for stakeholders

Advanced Tools and Techniques

  • Mobile device forensic tools available in Kali
  • Analyzing steganography and encryption
  • Automating forensic tasks using scripts

Summary and Next Steps

Requirements

  • Foundational knowledge of the Linux command line
  • Familiarity with core cybersecurity concepts
  • Practical experience in incident response or IT security operations

Target Audience

  • Digital forensic investigators
  • Members of incident response teams
  • IT security professionals
 21 Hours

Upcoming Courses

Related Categories