FILE-SYS-FORENSIC.AP1

File System Forensic Analysis

Be a smart learner ready to master file system forensic analysis and level up their skills with an interactive course.

  • Practice in 18 Laboratorios prácticos — nothing to install
  • 19 Lecciones interactivas y 115 topics mapped to the official exam objectives

Intermediate A tu propio ritmo · 1 año de acceso

18 LiveLabs prácticos

Practice real IT tasks in guided environments.

  • Entornos reales
  • Calificación automática
  • Sin instalación
19Lecciones interactivas
115Topics
18Laboratorio en vivo
3Vídeos
94Tarjetas didácticas
94Glosario de términos

01 / Habilidades que obtendrás

What you will be able to do

Try Free → No se requiere tarjeta de crédito

Enroll in our file system forensic analysis course to master the techniques needed to uncover hidden evidence, recover deleted data, and validate forensic evidence.

In this course, dive into hard disk acquisition, partition analysis, and file system structures from FAT and NTFS to Ext2/Ext3 and UFS. Learn how to use powerful open-source tools like the Sleuth Kit and Autopsy Forensic Browser to investigate real-world cases. 

  • Analyzing File Systems: Master the structures of FAT, NTFS, Ext2/Ext3, and UFS to locate hidden or deleted evidence.
  • Disk Acquisition & Preservation: Learn proper techniques for duplicating and handling digital evidence without corruption.
  • Partition & Volume Analysis: Decode DOS, Apple, GPT, and RAID configurations to uncover critical data.
  • Data Recovery & Metadata Examination: Recover deleted files and analyze timestamps, permissions, and file attributes.
  • Using Forensic Tools: Gain hands-on experience with The Sleuth Kit (TSK) and Autopsy Forensic Browser for investigations.
  • Validating Forensic Findings: Develop methods to verify tool accuracy and ensure evidence integrity for legal cases.

Course Highlights

  • 19 Lecciones estructuradas Cobertura completa de los objetivos principales del curso
  • 18 LiveLabs prácticos Escenarios interactivos guiados con evaluación instantánea
  • 1 año de acceso completo Aprendizaje a tu propio ritmo, accesible en cualquier momento y en todos los dispositivos

02 / Lecciones y laboratorios

See exactly what you will learn and practice

Descargar esquema (PDF)

Plan de estudios

19 Lecciones interactivas · 115 topics
01 Introduction 2 topics
  • Roadmap
  • Scope of Course
02 Digital Investigation Foundations 5 topics · 1 Laboratorio en vivo
  • Digital Investigations and Evidence
  • Digital Crime Scene Investigation Process
  • Data Analysis
  • Overview of Toolkits
  • Summary

1 Laboratorio en vivo in this lesson — see the labs panel →

03 Computer Foundations 4 topics · 1 Laboratorio en vivo
  • Data Organization
  • Booting Process
  • Hard Disk Technology
  • Summary

1 Laboratorio en vivo in this lesson — see the labs panel →

04 Hard Disk Data Acquisition 5 topics · 1 Laboratorio en vivo
  • Introduction
  • Reading the Source Data
  • Writing the Output Data
  • A Case Study Using dd
  • Summary

1 Laboratorio en vivo in this lesson — see the labs panel →

05 Volume Analysis 4 topics
  • Introduction
  • Background
  • Analysis Basics
  • Summary

Laboratorios prácticos Our edge

18 Laboratorio en vivos
  • Utilizing a Forensic Tool
  • Analyzing Hard Disk Geometry for Forensic Investigation
  • Performing Forensic Imaging and Integrity Verification of a Disk Image Using dd
  • Analyzing Partition Structures with fdisk and mmls
  • Analyzing Partitions on Removable Media and CDs
  • Analyzing GPT Disk Structure Using mmls and dd Commands
Los laboratorios se ejecutan en tu navegador; no hay nada que instalar.

03 / Preguntas frecuentes

Preguntas antes de empezar

Contáctanos ↗
What is forensic analysis of a file system?

File system forensic analysis involves examining digital storage structures (e.g., NTFS, FAT, Ext4) to recover evidence like deleted files, hidden data, and metadata (timestamps, permissions). 

It uses tools like The Sleuth Kit (TSK) and Autopsy to analyze partitions, RAID configurations, and file systems for legal or investigative purposes. Key tasks include:

  • Recovering overwritten data from slack space or unallocated clusters.
  • Validating tool accuracy to ensure evidence integrity.
What are the four types of forensic analysis?

Some of the forensic analysis methods include:

  • Disk Acquisition: Creating bit-by-bit copies of storage media using write-blockers to prevent tampering.
  • File System Analysis: Examining file structures (e.g., $MFT in NTFS) to trace file movements and timestamps.
  • Network Forensics: Analyzing traffic logs for breaches or malware communications.
  • Memory Forensics: Extracting volatile data (e.g., running processes) from RAM.
What qualifications do I need for digital forensics?

  • Education: A bachelor’s degree in computer science, cybersecurity, or digital forensics is typical. Advanced roles may require a master’s.
  • Certifications: GIAC Certified Forensic Analyst (GCFA), EnCase Certified Examiner (EnCE), or CompTIA Security+ for foundational knowledge.
  • Skills: Develop proficiency in tools like FTK, X-Ways, and scripting (Python/Bash) with our digital forensic training.
How can I become a digital forensic analyst?

To secure digital forensic analyst jobs, follow the checklist below:

  • Earn a Degree: Focus on cybersecurity or computer science.
  • Gain Experience: Start in IT roles (e.g., network analyst) to build technical skills.
  • Get Certified: Pursue GCFA or CFCE to validate expertise.
  • Specialize: Choose niches like mobile forensics or malware analysis.
  • Stay Updated: Follow trends via organizations like SWGDE or HTCIA.

Learn to Find Hidden Digital Evidence

Level up your cybersecurity skills while you dissect disks, trace timestamps, and crack cases in this hands-on file system forensic analysis course.

  • 1 año de acceso completo
  • 18 LiveLab incluido
  • Certificado de finalización
Comprar ahora — $239.99 Try Free

No se requiere tarjeta de crédito

scroll to top