Learning Objectives
At the end of this course, students will be able to:
- Define the Incident Response and Computer Forensic processes.
- Articulate basic forensic tools and methodologies.
- Build an incident response team.
- Explain appropriate methodology for gathering, protecting and presenting evidence.
- Explain basic Intrusion Detection Systems Theory.
- Make a bit-stream copy of a suspect hard drive.
- Define relevant cryptography services and terms.
- List six different data hiding techniques.
- List and explain password auditing (cracking) methodologies.
- Define hostile code.
- Explain a Denial of Service (DOS) attack.
- Identify the major forensic tool classes.
- Install and operate Windows and Linux O/S's and tools.
- Define and explain three attack phases.
- Explain how integrity checking programs, such as Tripwire, operate.
- Explain the role of logs in computer forensics.