C)DFE: Certified Digital Forensics Examiner
Target group
- Virtualization Admins
- Cloud Security Officers
- CIO
- Virtualization and Cloud Auditors
- Virtualization and Cloud Compliance Officers
Description
The Certified Digital Forensics Examiner, C)DFE certification is designed to train Cyber Crime and Fraud Investigators. Students are taught electronic discovery and advanced investigation techniques. This course is essential to anyone encountering digital evidence while conducting an investigation. Mile2’s Certified Digital Forensics Examiner training teaches the methodology for conducting a computer forensic examination. Students will learn to use forensically sound investigative techniques in order to evaluate the scene, collect and document all relevant information, interview appropriate personnel, maintain chain-of-custody, and write a findings report. Through the use of a risk-based approach, the C)DFE is able to implement and maintain cost-effective security controls that are closely aligned with both business and industry standards.
Program
- Duration : 5 days
Module 1 – Computer Forensics Incidents
- Origins of digital forensic science
- Differences between criminal and civil incidents
- Types of computer fraud incidents
- Internal and external threats
- Investigative challenges
- Industry Standards
Module 2 – Computer Forensic Investigative Theory
- Investigative Theory
- Investigative Concepts
- Behavioral evidence analysis (BEA) & Equivocal Forensic Analysis (EFA)
Module 3 – Computer Forensic Investigative Process
- Investigative Prerequisites
- Scene Management
- The digital forensics process
- ISO 27043
Module 4 – Digital Acquisition and Analysis Tools
- Acquisition Procedures
- Computer forensics field triage process model (CFFTPM)
- Acquisition Authentication
- Forensic Tools
Module 5 – Disks and Storages
- Disk OS and Filesystems
- Spinning Disks Forensics
- SSD Forensics
- Files Management
- Handling Damaged Drives
Module 6 – Live Acquisitions
- Live Acquisition
- Apple Acquisition
- Linux/UNIX Acquisition
Module 7 – Windows Forensics
- Windows Event Viewer Overview
- EVTX and EVT Logs
- Logs Analysis to Identify Breaches and Attacks
Module 8 - Linux Forensics
- Linux Artifacts o
- File System Structure
- Basic Identifiers
- Common Log Files
Module 9 – MAC Forensics
- OSX Artifacts
- File System Structure
- Core Storage
- Default Apps
- Other Artifacts
Module 10 – Forensic Examination Protocols
- Science Applied to Forensics
- Cardinal Rules
- Alpha 5
- The 20 Basic Steps of Forensics
- Scientific Working Group on Digital Evidence (SWGDE) Standard
- International Organization on Computer Evidence (IOCE) Standard
Module 11 – Digital Evidence Protocols
- Digital Evidence Categories
- Evidence Admissibility
Module 12 – Digital Evidence Presentation
- The Best Evidence Rule
- Hearsay
- Authenticity and Alteration
Module 13 – Computer Forensic Laboratory Protocols
- Forensics Lab Standard Operating Procedures
- Quality Assurance
- Quality Control
- Peer Review
- Annual Review
- Deviations
- Lab Intake
Module 14 – Specialized Artifact Recovery
- Forensics Workstation Prep
- Windows Components with Investigative Interest
- Files Containing Historical Information
- Web Forensics
Module 15 – Advanced Search Strings and File Signatures
- Search Strings
- RegEx
- File Signatures
Module 16 – eDiscovery and ESI
- Electronically Stored Information Rules
- Legal System
- Disclosure o Rule 37
- eDiscovery Tools
Module 17 – Mobile Forensics
- Cellular Network
- Forensic Process
- Tools
- Paraben Forensics
Module 18 – Incident Handling
- What is an Incident?
- Incident Handling Steps
- Preparation
- Identification and Initial Response
- Containment
- Eradication
- Recovery
- Follow-up
Module 19 – Digital Forensics Reporting
- Report Sections and Content
Goal
Upon completion, Certified Digital Forensics Examiner students will be able to establish industry acceptable digital forensics standards with current best practices and policies. Students will also be prepared to competently take the C)DFE exam.
Prerequisites
- 1 YR experience in computers
- Mile2’s C)SP course
- Mile2’s Foundational Course Pack
Tarif
- 2999 €
- Langue : Anglais
- Niveau : Level 300
- Organisme de certification : Mile2
- Certification : Oui
- Accesibilité : Oui
- Durée : 5 Jours