
|
Quick Links
![]()
|
CHFI Exam (312-49)
Credit Towards
Certification
Exam Details
Test Objectives v3 Module 01 Computer Forensics in Today's World Summarize the History of Forensics Summarize the basic concepts of Computer Forensicso What is Computer Forensics?o Why Computer Forensics is necessary?o What are the different ways of Forensic Data Collection?o Objectives of Computer Forensicso Benefits of Forensic Readinesso Categories of Forensics Data Identify Computer Forensics Flaws and Risks Summarize the basic concepts of Computer Facilitated Crimeso Type of Computer Crimeso Cyber Crimeo Modes of Attackso Examples of Cyber Crimeo Examples of Evidence Identify the Stages of Forensic Investigation in Tracking Cyber Criminalso Key Steps in Forensics Investigationso Rules of Computer Forensicso Need for Forensic Investigatoro Accessing Computer Forensics Resources Identify the need and procedure to Maintain professional conduct Understand Corporate Investigations Define the term Digital Forensics Explain the term Enterprise Theory of Investigation (ETI) Where and when do you use Computer Forensics?Module 02 Law and Computer Forensics What privacy issues are involved in investigations? Discuss the Fourth Amendment Explain about Interpol- Information Technology Crime Center Summarize Internet Laws and Statutes How the FBI Investigates Computer Crime?o Federal Statutes Investigated by the FBI Explain about Scientific Working Group on Digital Evidence (SWGDE) Explain Federal Laws (Computer Crime) Summarize all the Intellectual Property Rights Summarize the laws about Cyber Stalking List all Crime Investigating Organizations National Infrastructure Protection Center Summarize the following acts and laws related to computer forensics:o The USA Patriot Act of 2001o The G8 Countries: Principles to Combat High-tech Crime The G8 Countries: Action Plan to Combat High-Tech Crime (International Aspects of Computer Crime)o Crime Legislation of EUo United Kingdom: Police and Justice Act 2006o Australia: The Cybercrime Act 2001o Belgiumo European Lawso Austrian Lawso Brazilian Lawso Belgium Lawso Canadian Lawso France Lawso Indian Lawso German Lawso Italian Lawso Greece Lawso Denmark Lawso Norwegian Lawso Netherlands Laws Give the brief idea about Internet Crime Schemeso Why you should report cybercrime?o What are the stages to report computer-related crimes?o Which person is assigned to report the crime?o When and How to Report an Incident?o Who to Contact at the Law Enforcement?o How to contact Federal Local Agents?Module 03 Computer Investigation Process How to investigate computer crime? Explain the importance of securing computer evidence Discuss about investigating company policy violation What are the important things before the investigation? Explain Investigation Methodology Is there need of search warrant for investigation? How can you prepared for searches? Discuss about searching without warrant What do you mean by Warning Banners? How can you collect the evidence? Discuss Chain-of Evidence Form Explain Bit-stream copies How to examine digital evidence? Discuss the example of accessing policy violation case List down the steps important for computer forensic investigation Give the brief idea about investigation processo Explain policy and procedure developmento Describe the following evidence assessment Case Assessment Processing Location Assessment Legal Considerations Evidence Assessmento How to acquire evidence? Explain Imaging Describe write protection How to acquire the subject evidence?o Explain in brief about evidence examination How can extract the evidence physically? How can you extract evidence logically? Describe the following analysis over extracted data Timeframe analysis Data hiding analysis Application and file analysis Describe about ownership and possessiono Explain documenting and reporting of evidence What should be in the final report?o When to close the case? What are important factors to maintain professional conduct?Module 04 First Responder Procedure Define Electronic Evidenceo Explain the forensic processo Describe different types of Electronic Deviceso Discuss electronic devices and collecting potential evidenceo Summarize the features and basic attributes of evidence collecting tools and equipment Describe First Response Rule Explain Incident Response for following situations:o First Response for System Administratorso First Response by Non-Laboratory Staffo First Response by Laboratory Forensic Staff How can you secure and evaluate electronic crime scene Which questions should be asked to a client? Discuss health and safety Issues Explain Consent Give the brief idea about Search and Seizureo What is the planning for search and seizing?o How to start initial search of the scene?o Discuss the importance of witness signatureso Give the overview of conducting preliminary interviews Discuss the initial interviewso Is there need of documenting electronic crime scene?o What is the importance of photographing the scene?o Describe sketching of the sceneo Discuss about collecting and preserving electronic evidence What important data is present in evidence bag? Explain order of volatility Discuss about powered OFF computers at seizure time Describe the condition with powered ON PC Explain the role computers and servers Which devices should be collected and preserved as electronic evidence? What is the idea behind seizing the portable computers Explain packaging electronic evidences Describe exhibit numberingo How can you transport electronic evidence?o How can you handle and transport the devices to forensic laboratory? Explain ‘Chain of Custody’ Give the brief overview for finding forensic examination by crime categoryModule 05 CSIRT Define of Vulnerability Discuss vulnerability statistics Give the brief idea about an Incidento How to Identify an Incident?o How to Prevent an Incident?o What is the relationship between Incident Response, Incident Handling, and Incident Managemento Give the checklist for Incident Responseo How can you handle incidentso Explain the following stages for handling incident: Preparation Identification Containment Eradication Recovery Follow-upo Explain Incident Managemento Why don’t Organizations Report Computer Crimes?o Describe about estimation of Incident costo Whom to Report an Incident?o How to report an Incident?o What are the different vulnerability resourceso Explain the following category of Incidents Category of Incidents: Low Level Category of Incidents: Mid Level Category of Incidents: High Level Explain in brief about CSIRT?o What are the goals and strategy of CSIRT?o Describe CSIRT Vision Discuss building of CSIRT Visiono Which are the motivations behind CSIRTs?o Why an Organization needs an Incident Response Team?o Who works in a CSIRT?o Staffing your Computer Security Incident Response Team: What are the basic skills needed?o Explain the team modelso What are the three categories of CSIRT Services?o Discuss CSIRT case classificationo Explain types of Incidents and level of Supporto Describe the service attributeso Explain Incident specific procedureso How CSIRT handles case: Stepso Describe US-CERT Incident Reporting System Discuss CSIRT Incident Report Form Explain CERT(R) Coordination Center: Incident Reporting Formo Give the example of CSIRTo Discuss the Best Practices for Creating a CSIRT Step 1: Obtain Management Support and Buy-in Step 2: Determine the CSIRT Development Strategic Plan Step 3: Gather Relevant Information Step 4: Design your CSIRT Vision Step 5: Communicate the CSIRT Vision Step 6: Begin CSIRT Implementation Step 7: Announce the CSIRTo What are the limits to effectiveness in CSIRTs?o Give the overview of investing in Automated Response List down the World CERTs http://www.trusted-introducer.nl/teams/country.html Discuss about http://www.first.org/about/organization/teams/ Discuss IRTs Around the WorldModule 06 Computer Forensic Lab Explain budget allocation for a Forensics Lab List down the physical location needs for a Forensic Lab Describe about work area of a computer forensics Lab Discuss about general configuration of a Forensic Lab List down the equipment required in a Forensics Lab Explains ambience of a forensics Labo Describe Ergonomics What are the environmental conditions required for proper lab functioning? What are the recommendations to avoid Eyestrain? Discuss about the structural design of Lab Explain about the electrical needs to lab Give overview for communications factors List down the basic workstation requirements in a forensic lab What are the essential hardware peripherals should be stocked as a back-up? Which are the Application Inventories and Operating System must be maintained? How can you provide physical security to your forensic lab? Explain Fire-Suppression systems Give the general recommendation for evidence locker What are the steps for auditing a computer forensics labo Auditing a Forensics Lab Explain the licensing requirements for forensic lab Summarize the features and basic attributes of following forensic laboratory requirements:o Paraben Forensics Hardware requirements: Handheld First Responder Kit Wireless StrongHold Bag Remote Charger Device Seizure Toolbox Wireless StrongHold Tent Passport StrongHold Bag Project-a-Phone SATA Adaptor Male/ Data cable for Nokia 7110/6210/6310/i Lockdown SIM Card Reader/ Sony Clie N & S Series Serial Data Cable USB Serial DB9 Adaptero Portable Forensic Systems and Towers: Forensic Air-Lite VI MKII laptop Original Forensic Tower II Portable Forensic Systems and Towers: Portable Forensic Workhorse V Portable Forensic Workhorse V: Tableau 335 Forensic Drive Bay Controller Forensic Air-Lite IV MK II Forensic Tower IIo Forensic Write Protection Devices and Kits: Ultimate Forensic Write Protection Kito Tableau T3u Forensic SATA Bridge Write Protection Kito Tableau T8 Forensic USB Bridge Kit/Addonics Mini DigiDrive READ ONLY 12-in-1 Flash Media Readero Power Supplies and Switcheso Explain DIBSŪ Mobile Forensic Workstation DIBSŪ Advanced Forensic Workstation DIBSŪ RAID: Rapid Action Imaging Deviceo Forensic Archive and Restore Robotic Devices: Forensic Archive and Restore (FAR Pro) List down the different forensic workstations Summarize the features and basic attributes of LiveWire Investigator tool What are the features of Laboratory Imaging System?o List down technical specification of the Laboratory-based Imaging System Explain about the Computer Forensic Labs, Inco Discuss procedures at Computer Forensic Labs (CFL), Inc List down Data Destruction Industry StandardsModule 07 Understanding File Systems and Hard Disks Give the overview of Disk Drive Explain in brief about Hard Disko Describe types of Hard Disk Interfaces: SCSI IDE/EIDE USB ATA Fibre Channelo What is Disk Platter? Describe Tracks Explain Tracks Numberingo Give detail idea about Sector Explain Sector Addressingo Describe in details Cluster? Cluster Size What is Slack Space? Discuss about lost Clusterso Write more about Bad Sectoro How can you calculate Disk Capacity?o Summarize the features of following forensic tools: Evidor: The Evidence Collector WinHex Understanding File Systemso Explain in details about file system: Types of File System List down the various disk file systems List down Network file systems List down special purpose file systems List down the Linux file systems? Explain Sun Solaris 10 File System: ZFS List down the Mac OS X File System List down Windows File systems Explain CD-ROM / DVD File systemo Compare different file systemso Explain Disk Partitiono Describe Master Boot Recordo Explain more about FAT Describe Boot Sectoro Give the brief idea about NTFS List down different NTFS System Files Explain NTFS partition boot sector Describe NTFS Master File Table (MFT) Write down about Metadata File Table Explain NTFS Attributes Give an idea about NTFS Data Stream-I Give the overview of NTFS Compressed Files Explain in brief about NTFS Encrypted File Systems (EFS) Discuss EFS File Structure Describe EFS Recovery Key Agent What is EFS Key? How can you delete NTFS Files?o What is Registry? How can you examine Registry Datao Compare FAT and NTFSo Describe Windows XP system fileso Write down the steps for booting Windows (XP/2003)o Explain http://www.bootdisk.comModule 08 Understanding Digital Media Devices Summarize features and basic attributes of following digital storage devices:o Magnetic Tapeo Floppy Disko Compact Disko CD-ROMo DVD DVD-R, DVD+R, and DVD+R(W) DVD-RW, DVD+RW DVD+R DL/ DVD-R DL/ DVD-RAM HD-DVD (High Definition DVD) HD-DVDo Blu-Rayo Compare the following: CD and DVD Vs Blu-Ray HD-DVD and Blu-Rayo iPodo Zuneo Explain in brief about different Flash Memory Cards Secure Digital (SD) Memory Card Compact Flash (CF) Memory Card Memory Stick (MS) Memory Card Multi Media Memory Card (MMC) xD-Picture Card (xD) SmartMedia Memory (SM) Cardo USB Flash Drives USB Flash in a PenModule 09 Windows, Linux and Macintosh Boot Processes Discuss the different terminologies Give the brief idea about:o Boot Loadero Boot Sectoro Anatomy of MBR Explain basic system boot process Give the brief idea about MS-DOS Boot Process Explain in details Windows XP Boot Process Describe in brief Linux boot processo Write down about common startup files in UNIXo List down important directories present in UNIXo Explain steps for Linux Boot Process: Step 1: The Boot Manager Step 2: init Step 2.1: /etc/inittab runlevels Step 3: Services Step 4: More inittab Give brief idea about Mac OS X:o Discuss Hidden Files in Mac OS Xo Describe booting in Mac OS Xo Explain Mac OS X Boot Optionso Write down the steps for booting Mac OS Xo How to install Mac OS X on Windows XP?o Explain PearPCo Describe MacQuisition Boot CD by BlackBago Summarize features of Macintosh Forensic Software by BlackBag Directory Scan FileSpy HeaderBuildero Summarize the features of following Mac OS forensics tools: Carbon Copy Cloner (CCC) MacDrive6Module 10 Windows Forensics Where you can find the evidence on a Windows system? How can you gathering volatile evidence? Summarize the features and advantages of Windows forensics tools:o Give brief idea about Helix List down the tools present in Helix CD for Windows forensics Discuss Helix Tool: SecReport Explain Helix Tool: Windows Forensic Toolchest (WFT)o MD5 Generator: Chaos MD5 Describe Secure Hash Signature Generator Explain MD5 Generator: Mat-MD5 Explain MD5 Checksum Verifier 2.1o Pslisto fporto Psloggedon What is File Slack? How can you investigate Windows File Slack? How to examine file systems? Discuss about built-in tool: Sigverif Discuss the Word Extractor forensic tool How can you check Registry?o Summarize features of following registry tools:o Registry Viewer Tool: RegScannero Microsoft Security ID Summarize features and importance of Memory Dumpo Pagefile.sys and PMDump What is Virtual Memory?o Discuss System Scanner Explain Integrated Windows Forensics Software: X-Ways Forensics and its features How can you investigate Internet Traces Summarize the features of following Internet tracing tools:o Traces Viewero IECookiesViewo IE History Viewero Cache Monitor Give overview about Investigating ADS Streams How can you create CD-ROM Bootable for Windows XPo Bart PE (Bart Preinstalled Environment): Screenshoto Ultimate Boot CD-ROMo List down the tools present in UB CD-ROMModule 11 Linux Forensics Why use Linux for Forensics? How to recognize partitions in Linux? Explain file system in Linuxo Describe file system Discuss mount Command Discuss the Boot Sequence in Linux Explain Linux Forensics Discuss case exampleo Explain Step-by-step approach to case What are the challenges in disk forensics with Linux Discuss Jason Smith Caseo Explain Step-by-step approach to case Summarize the features of following Linux forensics tools:o The Sleuth Kit List down the tools present in “The Sleuth Kit”o Autopsy Describe evidence analysis techniques in Autopsyo SMART for Linuxo Penguin Sleuth List down the tools included in Penguin Sleuth Kito Forensixo Maresware List down the various programs present in Mareswareo Captain Nemoo THE FARMER'S BOOT CDModule 12 Data Acquisition and Duplication What are the different acquisition methods? Explain data recovery contingencies What is the need of data duplication? Explain features of MS-DOS Data Acquisition tool: DriveSpy Give the overview of Windows Data Acquisition toolso FTK Imager Describe data acquiring in Linuxo Explain Dd Commando How can you extract the MBR?o Explain Netcat Command Discuss dd Command (Windows XP Version) Summarize the features of following data acquisition tools:o Mount Image Proo Snapshot Toolo Snapback DatArresto Data Acquisition Tool: SafeBacko Hardware Tool: Image MASSter Solo-3 Forensico Hardware Tool: LinkMASSter-2 Forensico Hardware Tool: RoadMASSter-2o Data Duplication Tool: R-drive Imageo Data Duplication Tool: DriveLooko Data Duplication Tool: DiskExplorero Save-N-Synco Hardware Tool: ImageMASSter 6007SASo Hardware Tool: Disk Jockey ITo SCSIPAKo IBM DFSMSdsso Tape Duplication System: QuickCopyModule 13 Computer Forensic Tools Part I- Software Forensics Tools Summarize the features and advantages of following software forensics tools:o Visual TimeAnalyzero X-Ways Forensicso Evidoro Slack Space & Data Recovery Tools: Ontracko Data Recovery Tools: Device Seizure 1.0 Forensic Sorter v2.0.1 Directory Snoopo Permanent Deletion of Files: PDWipe Darik's Boot and Nuke (DBAN)o File Integrity Checker: FileMon File Date Time Extractor (FDTE) Decode - Forensic Date/Time Decodero Disk Imaging Tools: Snapback Datarresto Partition Managers: Partimageo Linux/Unix Tools: Ltools and Mtoolso Password Recovery Tool: @Stake Decryption Collection Enterprise v2.5 AIM Password Decoder MS Access Database Password Decodero Internet History Viewer: CookieView - Cookie Decoder Cookie Viewer Cache View FavURLView - Favourite Viewer NetAnalysiso Multipurpose Tools: Maresware LC Technologies Software Winhex Specialist Edition Prodiscover DFTo Toolkits: NTI Tools R-Tools-I Datalifter Toolkits: Accessdata FTK- Forensic Toolkit Image Master Solo and Fastbloc Encaseo Email Recovery Tool: E-mail Examiner Network E-mail Examinero Case Agent Companiono Chat Examinero Forensic Replicatoro Registry Analyzero ASR Data’s SMARTo Oxygen Phone Managero SIM Card Seizureo Text Searchero Autorunso Autostart Viewero Belkasoft RemovExo HashDigo Inforenz Foragero KaZAlysero DiamondCS OpenPortso Pascoo Patchito PE Explorero Port Explorero PowerGREPo Process Explorero PyFLAGo Registry Analyzing Tool: Regmono Reverse Engineering Compilero SafeBacko TapeCato VisionPart II- Hardware Forensics Tools Summarize the features and advantages of following hardware computer forensic tools:o Hard Disk Write Protection Tools: Nowrite & Firewire Drivedocko LockDowno Write Protect Card Readero Drive Lock IDEo Serial-ATA DriveLock Kito Wipe MASStero ImageMASSter Solo-3 ITo ImageMASSter 4002io ImageMasster 3002SCSIo Image MASSter 3004SATA
Module 14 Forensics Investigations Using Encase What is Evidence Fileo Explain evidence file formato How can you verifying file integrity Describe Hashing How can you acquiring image? Explain configuring of Encase and discuss following:o Encase Options Screeno Encase Screenso View Menuo Device Tabo Viewing Files and Folderso Bottom Pane Viewers in Bottom Pane Status Bar Explain in brief about searching ability of Encaseo Discuss about Keywords How to add Keywords? How can you group keywords? How can you add multiple Keywords?o How to do Search?o Discuss Search Hits tab Give the brief idea about Bookmark:o What is Bookmarks?o How to create Bookmarks?o Discuss about adding Bookmarks Explain the procedure for recovering Deleted Files/folders in FAT Partitiono How can you recover folders in NTFS?o Explain Master Boot Record(MBT)o How to view Disk Geometry? Explain the recovery of deleted partitions Explain in brief about Hash Values?o How to create Hash Setso Describe MD5 Hasho How to create Hash? What do you mean by Viewers? Discuss Signature Analysis How can you view the results? Explain the process for copying files/folders Describe E-mail Recovery Discuss Reporting Explain Boot Disks in Encase What is IE Cache Images?Module 15 Recovering Deleted Files and Deleted partitions Part I: Recovering Deleted Files How can you delete the files? What happens when a File is Deleted in Windows? Give the brief idea about Recycle Bin in Windowso Discuss the storage locations of Recycle Bin in FAT and NTFS systemo How The Recycle Bin Works?o Explain damaged or deleted INFO Fileo Describe damaged files in Recycled foldero Give the overview of damaged Recycle folder How to Undelete a File? Explain Data Recovery in Linux Summarize the features of following deleted files recovery tools:o Search and Recovero Zero Assumption Digital Image Recoveryo e2Undelo R-linuxo O&O Uneraseo Restorer 2000o Badcopy Proo File Scavengero Mycroft V3o PC ParaChuteo Stellar Phoenixo Filesavero Virtual Labo Drive and Data Recoveryo Active@ UNERASER - DATA Recoveryo Restorationo PC Inspector File Recoveryo PC Inspector Smart Recoveryo Fundeleteo RecoverPlus Proo OfficeFIXo Recover My Fileso Zero Assumption Recoveryo SuperFile Recovero IsoBustero CDRollero DiskInternals Unerasero DiskInternal Flash Recoveryo DiskInternals NTFS Recoveryo Recover Lost/Deleted/Corrupted files on CDs and DVDso Undeleteo Active@ UNDELETEo CD Data Rescueo File Recovero WinUndeleteo R-Undeleteo Image Recallo eIMAGE Recoveryo File Scavengero Recover4all Professionalo eData Uneraseo Easy-Undeleteo InDisk Recoveryo Repair My Excelo Repair Microsoft Word Fileso Zip Repairo Canon RAW File Recovery SoftwarePart II: Recovering Deleted Partitions Explain deletion of partition How can you delete partition using Windows How can you delete partition using command line Describe recovery of deleted partition Summarize the features of following deleted partition recovery tools:o GetDataBacko DiskInternals Partition Recoveryo Active@ Partition Recoveryo Handy Recoveryo Acronis Recovery Experto Active Disk Imageo TestDisko Recover It All!o Scaveno Partition Table Doctoro NTFS Deleted Partition RecoveryModule 16 Image Files Forensics Define the common terminologies Give the brief idea about Image fileso What do you understand by vector images?o Explain raster images?o Discuss Metafile Graphicso Summarize the structure, features and basic attributes of following Image file formats: GIF (Graphics Interchange Format) JPEG (Joint Photographic Experts Group) JPEG 2000 BMP (Bitmap) File PNG (Portable Network Graphics) Tagged Image File Format (TIFF) ZIP (Zone Information Protocol) How file compression works? Discuss data compression and its typeso Explain following data compression algorithms: Huffman Coding Algorithm Lempel-Ziv Coding Algorithm What is mean Lossy Compressiono Explain Vector Quantization Give the overview about locating and recovering image files What is the importance of Image file headers? How can you repair the damaged headers? Explain reconstruction of file fragments Identify and discuss unknown file formatso Summarize the features of following tools to identify unknown file formats: http://www.filext.com Picture Viewer: Ifran View Picture Viewer: ACDsee Picture Viewer: Thumbsplus Picture Viewer: AD Picture Viewer: Max FastStone Image Viewer XnView Faces – Sketch Software Describe Steganography in image files Define the term Steganalysis |