Skip to main content
Hackviser Training

Introduction to Forensic Analysis

11 sections4 tools

Training Overview

The "Introduction to Forensic Analysis" training comprehensively teaches the essential techniques and methods necessary for digital forensic examinations. The training covers various topics, including forensic analysis techniques on Windows and Linux systems, collection of digital evidence, memory and disk analysis, rapid incident response, and the tools used.

What you will learn

  • The core principles of digital forensic investigations.
  • How to perform evidence collection from Windows and Linux systems.
  • The basics of host-based analysis, including memory and disk forensics.
  • How to trace program execution and user activity.

Tools you will use

  • FTK Imager
  • Autopsy
  • Volatility (Conceptual)
  • PowerShell

Prerequisites

  • A solid understanding of both Windows and Linux operating systems.
  • Familiarity with file systems and basic networking.

Who this is for

  • Aspiring Digital Forensic Investigators.
  • Incident Response team members.
  • System administrators who need to investigate security incidents.

Training sections

  1. 1Introduction
  2. 2Windows Forensics
  3. 3Linux Forensics
  4. 4Evidence Collection
  5. 5Host-Based Evidence
  6. 6Memory Analysis
  7. 7Disk Analysis
  8. 8Rapid Triage
  9. 9Program Execution Traces
  10. 10PowerShell Activities
  11. 11Exam

Continue learning

Practice the topic in a lab or continue with a related Hackviser guide.