What is another name for a forensic drive controller?
write blocker
What tool in Linux can be used to create a forensic copy of a hard drive that will be used in an investigation?
What are the 4 functions of forensic disk controller?
What does forensics deal with?
investigation, preservation, analysis, and presentation of digital evidence that will be used in an investigation
What is the goal of forensics?
establish the authenticity and integrity of the evidence, enabling it to be admissible in court, and ultimately, to assist in solving cyber crimes, intellectual property theft, fraud, and other digital-related offences
What are the 4 types of forensics?
What are the different security roles that deal with forensics?
What is the role of a Tier 1 SOC Analyst in terms of forensics?
What is the role of a Tier 2/3 SOC Analyst in terms of forensics?
Is the process of malware analysis considered forensics?
yes
What is the purpose of the KAPE (Kroll Artifact Parser and Extractor) tool and what is it used for?
What is the purpose of the FTK Imager tool and what is it used for?
What is the purpose of the EnCase tool and what is it used for?
take forensic images of computers, mobile phones, and internet-of-things devices, which can then be analyzed to collect digital evidence
What is the purpose of the Cellebrite tool and what is it used for?
suite of tools designed primarily for mobile forensics, which allows easy acquisition of data from a mobile device so it can be processed in other tools
What are the forensic tools used for evidence collection?
What is the purpose of the Autopsy tool and what is it used for?
What is the purpose of the Volatility tool and what is it used for?
What are the forensic tools used for evidence analysis?
What OSs’ are supported by Volatility?
Windows, Linux, and Mac OS
What are the two common ways of hiding data?
What basic information should be tracked to preserve the chain of custody?
What should be done with the original disk image when doing forensics?
Who’s the guy who crearted many tools for Windows forensics?
Eric Zimmerman
What is the Redline tool?