|
|

-
Forensics Science
-
Computer Forensics
-
Security Incident Report
-
Aspects of Organizational Security
-
Evolution of Computer Forensics
-
Objective of Computer Forensics
-
Need for Compute Forensics
-
Forensics Readiness
-
Benefits of Forensics Readiness
-
Goals of Forensics Readiness
-
Forensics Readiness Planning
-
Cyber Crime
-
Computer Facilitated Crimes
-
Modes of Attacks
-
Examples of Cyber Crime
-
Types of Computer Crimes
-
Cyber Criminals
-
Organized Cyber Crime: Organizational Chart
-
How Serious are Different Types of Incidents?
-
Disruptive Incidents to the Business
-
Cost Expenditure Responding to the Security Incident
-
Cyber Crime Investigation
-
Key Steps in Forensics Investigation
-
Rules of Forensics Investigation
-
Need for Forensics Investigator
-
Role of Forensics Investigator
-
Accessing Computer Forensics Resources
-
Role of Digital Evidence
-
Corporate Investigations
-
Understanding Corporate Investigations
-
Approach to Forensics Investigation: A Case Study
-
Instructions for the Forensic Investigator to Approach the Crime Scene
-
Why and When Do You Use Computer Forensics?
-
Enterprise Theory of Investigation (ETI)
-
Legal Issues
-
Reporting the Results
-
Reporting a Cyber Crime
-
Why you Should Report Cybercrime?
-
Reporting Computer-Related Crimes
-
Person Assigned to Report the Crime
-
When and How to Report an Incident?
-
Who to Contact at the Law Enforcement?
-
Federal Local Agents Contact
-
More Contacts
-
CIO Cyberthreat Report Form


-
Searching and Seizing Computers without a Warrant
-
Searching and Seizing Computers without a Warrant
-
§ A: Fourth Amendment’s “Reasonable Expectation of Privacy” in Cases Involving Computers: General Principles
-
§ A.1: Reasonable Expectation of Privacy in Computers as Storage Devices
-
§ A.3: Reasonable Expectation of Privacy and Third-Party Possession
-
§ A.4: Private Searches
-
§ A.5 Use of Technology to Obtain Information
-
§ B: Exceptions to the Warrant Requirement in Cases Involving Computers
-
§ B.1: Consent
-
§ B.1.a: Scope of Consent
-
§ B.1.b: Third-Party Consent
-
§ B.1.c: Implied Consent
-
§ B.2: Exigent Circumstances
-
§ B.3: Plain View
-
§ B.4: Search Incident to a Lawful Arrest
-
§ B.5: Inventory Searches
-
§ B.6: Border Searches
-
§ B.7: International Issues
-
§ C: Special Case: Workplace Searches
-
§ C.1: Private Sector Workplace Searches
-
§ C.2: Public-Sector Workplace Searches
-
Searching and Seizing Computers with a Warrant
-
Searching and Seizing Computers with a Warrant
-
A: Successful Search with a Warrant
-
A.1: Basic Strategies for Executing Computer Searches
-
§ A.1.a: When Hardware is itself Contraband, Evidence, or an Instrumentality or Fruit of Crime
-
§ A.1.b: When Hardware is Merely a Storage Device for Evidence of Crime
-
§ A.2: The Privacy Protection Act
-
§ A.2.a: The Terms of the Privacy Protection Act
-
§ A.2.b: Application of the PPA to Computer Searches and Seizures
-
§ A.3: Civil Liability Under the Electronic Communications Privacy Act (ECPA)
-
§ A.4: Considering the Need for Multiple Warrants in Network Searches
-
§ A.5: No-Knock Warrants
-
§ A.6: Sneak-and-Peek Warrants
-
§ A.7: Privileged Documents
-
§ B: Drafting the Warrant and Affidavit
-
§ B.1: Accurately and Particularly Describe the Property to be Seized in the Warrant and/or Attachments to the Warrant
-
§ B.1.a: Defending Computer Search Warrants Against Challenges Based on the Description of the “Things to Be Seized”
-
§ B.2: Establish Probable Cause in the Affidavit
-
§ B.3: In the Affidavit Supporting the Warrant, include an Explanation of the Search Strategy as Well as the Practical & Legal Considerations that Will Govern the Execution of the Search
-
§ C: Post-Seizure Issues
-
§ C.1: Searching Computers Already in Law Enforcement Custody
-
§ C.2: The Permissible Time Period for Examining Seized Computers
-
§ C.3: Rule 41(e) Motions for Return of Property
-
The Electronic Communications Privacy Act
-
The Electronic Communications Privacy Act
-
§ A. Providers of Electronic Communication Service vs. Remote Computing Service
-
§ B. Classifying Types of Information Held by Service Providers
-
§ C. Compelled Disclosure Under ECPA
-
§ D. Voluntary Disclosure
-
§ E. Working with Network Providers
-
Electronic Surveillance in Communications Networks
-
Electronic Surveillance in Communications Networks
-
A. Content vs. Addressing Information
-
B. The Pen/Trap Statute, 18 U.S.C. §§ 3121-3127
-
C. The Wiretap Statute (“Title III”), 18 U.S.C. §§ 2510-2522
-
§ C.1: Exceptions to Title III
-
§ D. Remedies For Violations of Title III and the Pen/Trap Statute
-
Evidence
-
Evidence
-
§ A. Authentication
-
§ B. Hearsay
-
§ C. Other Issues





-
Collecting Volatile Information
-
Volatile Information
-
System Time
-
Logged-on Users
-
Psloggedon
-
Net Sessions Command
-
Logonsessions Tool
-
Open Files
-
Net File Command
-
PsFile Command
-
OpenFiles Command
-
Network Information
-
Network Connections
-
Process Information
-
Process-to-Port Mapping
-
Process Memory
-
Network Status
-
Other Important Information
-
Collecting Non-volatile Information
-
Non-volatile Information
-
Examine File Systems
-
Registry Settings
-
Microsoft Security ID
-
Event Logs
-
Index.dat File
-
Devices and Other Information
-
Slack Space
-
Virtual Memory
-
Swap File
-
Windows Search Index
-
Collecting Hidden Partition Information
-
Hidden ADS Streams
-
Investigating ADS Streams: StreamArmor
-
Other Non-Volatile Information
-
Windows Memory Analysis
-
Memory Dump
-
EProcess Structure
-
Process Creation Mechanism
-
Parsing Memory Contents
-
Parsing Process Memory
-
Extracting the Process Image
-
Collecting Process Memory
-
Windows Registry Analysis
-
Inside the Registry
-
Registry Structure within a Hive File
-
The Registry as a Log File
-
Registry Analysis
-
System Information
-
TimeZone Information
-
Shares
-
Audit Policy
-
Wireless SSIDs
-
Autostart Locations
-
System Boot
-
User Login
-
User Activity
-
Enumerating Autostart Registry Locations
-
USB Removable Storage Devices
-
Mounted Devices
-
Finding Users
-
Tracking User Activity
-
The UserAssist Keys
-
MRU Lists
-
Search Assistant
-
Connecting to Other Systems
-
Analyzing Restore Point Registry Settings
-
Determining the Startup Locations
-
Cache, Cookie, and History Analysis
-
Cache, Cookie, and History Analysis in IE
-
Cache, Cookie, and History Analysis in Firefox
-
Cache, Cookie, and History Analysis in Chrome
-
Analysis Tools
-
IE Cookies View
-
IE Cache View
-
IE History Viewer
-
MozillaCookiesView
-
MozillaCacheView
-
MozillaHistoryView
-
ChromeCookiesView
-
ChromeCacheView
-
ChromeHistoryView
-
MD5 Calculation
-
Message Digest Function: MD5
-
Why MD5 Calculation?
-
MD5 Hash Calculators: HashCalc, MD5 Calculator and HashMyFiles
-
MD5 Checksum Verifier
-
ChaosMD5
-
Windows File Analysis
-
Recycle Bin
-
System Restore Points (Rp.log Files)
-
System Restore Points (Change.log.x Files)
-
Prefetch Files
-
Shortcut Files
-
Word Documents
-
PDF Documents
-
Image Files
-
File Signature Analysis
-
NTFS Alternate Data Streams
-
Executable File Analysis
-
Documentation Before Analysis
-
Static Analysis Process
-
Search Strings
-
PE Header Analysis
-
Import Table Analysis
-
Export Table Analysis
-
Dynamic Analysis Process
-
Creating Test Environment
-
Collecting Information Using Tools
-
Process of Testing the Malware
-
Metadata Investigation
-
Metadata
-
Types of Metadata
-
Metadata in Different File Systems
-
Metadata in PDF Files
-
Metadata in Word Documents
-
Tool: Metadata Analyzer
-
Text Based Logs
-
Understanding Events
-
Event Logon Types
-
Event Record Structure
-
Vista Event Logs
-
IIS Logs
-
Parsing IIS Logs
-
Parsing FTP Logs
-
FTP sc-status Codes
-
Parsing DHCP Server Logs
-
Parsing Windows Firewall Logs
-
Using the Microsoft Log Parser
-
Other Audit Events
-
Evaluating Account Management Events
-
Examining Audit Policy Change Events
-
Examining System Log Entries
-
Examining Application Log Entries
-
Forensic Analysis of Event Logs
-
Searching with Event Viewer
-
Using EnCase to Examine Windows Event Log Files
-
Windows Event Log Files Internals
-
Windows Password Issues
-
Understanding Windows Password Storage
-
Cracking Windows Passwords Stored on Running Systems
-
Exploring Windows Authentication Mechanisms
-
LanMan Authentication Process
-
NTLM Authentication Process
-
Kerberos Authentication Process
-
Sniffing and Cracking Windows Authentication Exchanges
-
Cracking Offline Passwords
-
Forensic Tools
-
Windows Forensics Tool: OS Forensics
-
Windows Forensics Tool: Helix3 Pro
-
Integrated Windows Forensics Software: X-Ways Forensics
-
X-Ways Trace
-
Windows Forensic Toolchest (WFT)
-
Built-in Tool: Sigverif
-
Computer Online Forensic Evidence Extractor (COFEE)
-
System Explorer
-
Tool: System Scanner
-
Secret Explorer
-
Registry Viewer Tool: Registry Viewer
-
Registry Viewer Tool: Reg Scanner
-
Registry Viewer Tool: Alien Registry Viewer
-
MultiMon
-
CurrProcess
-
Process Explorer
-
Security Task Manager
-
PrcView
-
ProcHeapViewer
-
Memory Viewer
-
Tool: PMDump
-
Word Extractor
-
Belkasoft Evidence Center
-
Belkasoft Browser Analyzer
-
Metadata Assistant
-
HstEx
-
XpoLog Center Suite
-
LogViewer Pro
-
Event Log Explorer
-
LogMeister
-
ProDiscover Forensics
-
PyFlag
-
LiveWire Investigator
-
ThumbsDisplay
-
DriveLook


-
Recovering the Deleted Files
-
Deleting Files
-
What Happens When a File is Deleted in Windows?
-
Recycle Bin in Windows
-
Storage Locations of Recycle Bin in FAT and NTFS System
-
How the Recycle Bin Works
-
Damaged or Deleted INFO File
-
Damaged Files in Recycled Folder
-
Damaged Recycle Folder
-
File Recovery in MAC OS X
-
File Recovery in Linux
-
File Recovery Tools for Windows
-
Recover My Files
-
EASEUS Data Recovery Wizard
-
PC INSPECTOR File Recovery
-
Recuva
-
DiskDigger
-
Handy Recovery
-
Quick Recovery
-
Stellar Phoenix Windows Data Recovery
-
Tools to Recover Deleted Files
-
Total Recall
-
Advanced Disk Recovery
-
Windows Data Recovery Software
-
R-Studio
-
PC Tools File Recover
-
Data Rescue PC
-
Smart Undelete
-
FileRestore Professional
-
Deleted File Recovery Software
-
DDR Professional Recovery Software
-
Data Recovery Pro
-
GetDataBack
-
UndeletePlus
-
Search and Recover
-
File Scavenger
-
Filesaver
-
Virtual Lab
-
Active@ UNDELETE
-
Win Undelete
-
R-Undelete
-
Recover4all Professional
-
eData Unerase
-
Active@ File Recovery
-
FinalRecovery
-
File Recovery Tools for MAC
-
MAC File Recovery
-
MAC Data Recovery
-
Boomerang Data Recovery Software
-
VirtualLab
-
File Recovery Tools for MAC OS X
-
DiskWarrior
-
AppleXsoft File Recovery for MAC
-
Disk Doctors MAC Data Recovery
-
R-Studio for MAC
-
Data Rescue
-
Stellar Phoenix MAC Data Recovery
-
FileSalvage
-
TechTool Pro
-
File Recovery Tools for Linux
-
R-Studio for Linux
-
Quick Recovery for Linux
-
Kernal for Linux Data Recovery
-
TestDisk for Linux
-
Recovering the Deleted Partitions
-
Disk Partition
-
Deletion of Partition
-
Recovery of the Deleted Partition
-
Partition Recovery Tools
-
Active@ Partition Recovery for Windows
-
Acronis Recovery Expert
-
DiskInternals Partition Recovery
-
NTFS Partition Data Recovery
-
GetDataBack
-
EASEUS Partition Recovery
-
Advanced Disk Recovery
-
Power Data Recovery
-
Remo Recover (MAC) - Pro
-
MAC Data Recovery Software
-
Quick Recovery for Linux
-
Stellar Phoenix Linux Data Recovery Software
-
Tools to Recover Deleted Partitions
-
Handy Recovery
-
TestDisk for Windows
-
Stellar Phoenix Windows Data Recovery
-
ARAX Disk Doctor
-
Power Data Recovery
-
Quick Recovery for MAC
-
Partition Find & Mount
-
Advance Data Recovery Software Tools
-
TestDisk for MAC
-
Kernel for FAT and NTFS – Windows Disk Recovery
-
Disk Drill
-
Stellar Phoenix MAC Data Recovery
-
ZAR Windows Data Recovery
-
AppleXsoft File Recovery for MAC
-
Quick Recovery for FAT & NTFS
-
TestDisk for Linux

-
Overview and Installation of FTK
-
Overview of Forensic Toolkit (FTK)
-
Features of FTK
-
Software Requirement
-
Configuration Option
-
Database Installation
-
FTK Application Installation
-
FTK Case Manager User Interface
-
Case Manager Window
-
Case Manager Database Menu
-
Setting Up Additional Users and Assigning Roles
-
Case Manager Case Menu
-
Assigning Users Shared Label Visibility
-
Case Manager Tools Menu
-
Recovering Processing Jobs
-
Restoring an Image to a Disk
-
Case Manager Manage Menu
-
Managing Carvers
-
Managing Custom Identifiers
-
FTK Examiner User Interface
-
FTK Examiner User Interface
-
Menu Bar: File Menu
-
Exporting Files
-
Exporting Case Data to a Custom Content Image
-
Exporting the Word List
-
Menu Bar: Edit Menu
-
Menu Bar: View Menu
-
Menu Bar: Evidence Menu
-
Menu Bar: Tools Menu
-
Verifying Drive Image Integrity
-
Mounting an Image to a Drive
-
File List View
-
Using Labels
-
Creating and Applying a Label
-
Starting with FTK
-
Creating a case
-
Selecting Detailed Options: Evidence Processing
-
Selecting Detailed Options: Fuzzy Hashing
-
Selecting Detailed Options: Data Carving
-
Selecting Detailed Options: Custom File Identification
-
Selecting Detailed Options: Evidence Refinement (Advanced)
-
Selecting Detailed Options: Index Refinement (Advanced)
-
FTK Interface Tabs
-
FTK Interface Tabs
-
Explore Tab
-
Overview Tab
-
Email Tab
-
Graphics Tab
-
Bookmarks Tab
-
Live Search Tabs
-
Volatile Tab
-
Adding and Processing Static, Live, and Remote Evidence
-
Adding Evidence to a Case
-
Evidence Groups
-
Acquiring Local Live Evidence
-
FTK Role Requirements For Remote Acquisition
-
Types of Remote Information
-
Acquiring Data Remotely Using Remote Device Management System (RDMS)
-
Imaging Drives
-
Mounting and Unmounting a Device
-
Using and Managing Filters
-
Accessing Filter Tools
-
Using Filters
-
Customizing Filters
-
Using Predefined Filters
-
Using Index Search and Live Search
-
Conducting an Index Search
-
Selecting Index Search Options
-
Viewing Index Search Results
-
Documenting Search Results
-
Conducting a Live Search: Live Text Search
-
Conducting a Live Search: Live Hex Search
-
Conducting a Live Search: Live Pattern Search
-
Decrypting EFS and other Encrypted Files
-
Decrypting EFS Files and Folders
-
Decrypting MS Office Files
-
Viewing Decrypted Files
-
Decrypting Domain Account EFS Files from Live Evidence
-
Decrypting Credant Files
-
Decrypting Safeboot Files
-
Working with Reports
-
Creating a Report
-
Entering Case Information
-
Managing Bookmarks in a Report
-
Managing Graphics in a Report
-
Selecting a File Path List
-
Adding a File Properties List
-
Making Registry Selections
-
Selecting the Report Output Options
-
Customizing the Formatting of Reports
-
Viewing and Distributing a Report

-
Overview of EnCase Forensic
-
Overview of EnCase Forensic
-
EnCase Forensic Features
-
EnCase Forensic Platform
-
EnCase Forensic Modules
-
Installing EnCase Forensic
-
Minimum Requirements
-
Installing the Examiner
-
Installed Files
-
Installing the EnCase Modules
-
Configuring EnCase
-
Configuring EnCase: Case Options Tab
-
Configuring EnCase: Global Tab
-
Configuring EnCase: Debug Tab
-
Configuring EnCase: Colors Tab and Fonts Tab
-
Configuring EnCase: EnScript Tab and Storage Paths Tab
-
Sharing Configuration (INI) Files
-
EnCase Interface
-
Main EnCase Window
-
System Menu Bar
-
Toolbar
-
Panes Overview
-
Tree Pane
-
Table Pane
-
Table Pane: Table Tab
-
Table Pane: Report Tab
-
Table Pane: Gallery Tab
-
Table Pane: Timeline Tab
-
Table Pane: Disk Tab and Code Tab
-
View Pane
-
Filter Pane
-
Filter Pane Tabs
-
Creating a Filter
-
Creating Conditions
-
Status Bar
-
Case Management
-
Overview of Case Structure
-
Case Management
-
Indexing a Case
-
Case Backup
-
Options Dialog Box
-
Logon Wizard
-
New Case Wizard
-
Setting Time Zones for Case Files
-
Setting Time Zone Options for Evidence Files
-
Working with Evidence
-
Types of Entries
-
Adding a Device
-
Adding a Device using Tableau Write Blocker
-
Performing a Typical Acquisition
-
Acquiring a Device
-
Canceling an Acquisition
-
Acquiring a Handsprings PDA
-
Delayed Loading of Internet Artifacts
-
Hashing the Subject Drive
-
Logical Evidence File (LEF)
-
Creating a Logical Evidence File
-
Recovering Folders on FAT Volumes
-
Restoring a Physical Drive
-
Source Processor
-
Source Processor
-
Starting to Work with Source Processor
-
Setting Case Options
-
Collection Jobs
-
Creating a Collection Job
-
Copying a Collection Job
-
Running a Collection Job
-
Analysis Jobs
-
Creating an Analysis Job
-
Running an Analysis Job
-
Creating a Report
-
Analyzing and Searching Files
-
Viewing the File Signature Directory
-
Performing a Signature Analysis
-
Hash Analysis
-
Hashing a New Case
-
Creating a Hash Set
-
Keyword Searches
-
Creating Global Keywords
-
Adding Keywords
-
Importing and Exporting Keywords
-
Searching Entries for Email and Internet Artifacts
-
Viewing Search Hits
-
Generating an Index
-
Tag Records
-
Viewing File Content
-
Viewing Files
-
Copying and Unerasing Files
-
Adding a File Viewer
-
Viewing File Content Using View Pane
-
Viewing Compound Files
-
Viewing Base64 and UUE Encoded Files
-
Bookmarking Items
-
Bookmarks Overview
-
Creating a Highlighted Data Bookmark
-
Creating a Note Bookmark
-
Creating a Folder Information/ Structure Bookmark
-
Creating a Notable File Bookmark
-
Creating a File Group Bookmark
-
Creating a Log Record Bookmark
-
Creating a Snapshot Bookmark
-
Organizing Bookmarks
-
Copying/Moving a Table Entry into a Folder
-
Viewing a Bookmark on the Table Report Tab
-
Excluding Bookmarks
-
Copying Selected Items from One Folder to Another
-
Reporting
-
Reporting
-
Report User Interface
-
Creating a Report Using the Report Tab
-
Report Single/Multiple Files
-
Viewing a Bookmark Report
-
Viewing an Email Report
-
Viewing a Webmail Report
-
Viewing a Search Hits Report
-
Creating a Quick Entry Report
-
Creating an Additional Fields Report
-
Exporting a Report










- Types of VoIP Hacking
- Stages of VoIP Hacking:
- Foot printing
- Scanning
- Enumeration
- Footprinting
- Information Sources
- Unearthing Information
- Organizational Structure and Corporate Locations
- Help Desk
- Job Listings
- Phone Numbers and Extensions
- VoIP Vendors
- Resumes
- WHOIS and DNS Analysis
- Steps to Perform Footprinting
- Scanning
- Objectives of Scanning
- Host/Device Discovery
- ICMP Ping Sweeps
- ARP Pings
- TCP Ping Scans
- SNMP Sweeps
- Port Scanning and Service Discovery
- TCP SYN Scan
- UDP Scan
- Host/Device Identification
- What is Enumeration?
- Steps to Perform Enumeration
- Banner Grabbing with Netcat
- SIP User/Extension Enumeration
- REGISTER Username Enumeration
- INVITE Username Enumeration
- OPTIONS Username Enumeration
- Automated OPTIONS Scanning with sipsak
- Automated REGISTER, INVITE and OPTIONS Scanning with SIPSCAN against SIP server
- Automated OPTIONS Scanning Using SIPSCAN against SIP Phones
- Enumerating TFTP Servers
- SNMP Enumeration
- Enumerating VxWorks VoIP Devices
- Steps to Exploit the Network
- DoS & DDoS Attacks
- Flooding Attacks
- DNS Cache Poisoning
- Sniffing TFTP Configuration File Transfers
- Performing Number Harvesting and Call Pattern Tracking
- Call Eavesdropping
- Interception through VoIP Signaling Manipulation
- Man-In-The-Middle (MITM) Attack
- Application-Level Interception Techniques
- How to Insert Rogue Application?
- SIP Rogue Application
- Listening to/Recording Calls
- Replacing/Mixing Audio
- Dropping Calls with a Rogue SIP Proxy
- Randomly Redirect Calls with a Rogue SIP Proxy
- Additional Attacks with a Rogue SIP Proxy
- What is Fuzzing?
- Why Fuzzing?
- Commercial VoIP Fuzzing tools
- Signaling and Media Manipulation
- Registration Removal with erase_registrations Tool
- Registration Addition with add_registrations Tool
- VoIP Phishing
- Covering Tracks
|
|
|