Get in Touch

Course Outline

Introduction to Kali Linux for Forensics

  • Overview of Kali Linux and its forensic features
  • Preparing a forensic-ready laptop configuration
  • Understanding chain of custody and legal considerations

Disk and File System Forensics

  • Techniques for acquiring and imaging disks
  • File system analysis using Autopsy and Sleuth Kit
  • Recovery of deleted files and extraction of hidden data

Memory and Process Analysis

  • Capture of volatile memory states
  • Investigating active processes and malware behavior
  • Application of Volatility for deep memory analysis

Network Forensics

  • Methods for capturing live network traffic
  • Packet analysis using Wireshark and tcpdump
  • Tracing intrusion activities and lateral movement patterns

Log and Artifact Analysis

  • Reviewing system and application logs for anomalies
  • Identifying key artifacts of compromise
  • Conducting timeline analysis of incident events

Incident Investigation Workflow

  • Procedures for evidence acquisition and validation
  • Applying a step-by-step investigation methodology
  • Documenting findings for effective stakeholder reporting

Advanced Tools and Techniques

  • Utilizing mobile device forensic tools within Kali
  • Analysis of steganography and encryption methods
  • Automating forensic tasks through script development

Summary and Next Steps

Requirements

  • Foundational knowledge of the Linux command line
  • Working familiarity with core cybersecurity concepts
  • Practical experience in incident response or IT security operations

Target Audience

  • Digital forensic investigators
  • Members of incident response teams
  • IT security specialists
 21 Hours

Upcoming Courses

Related Categories