Skip to main content
00:00/00:00
Lecture 22 of 85

Getting Closer to Rootkit

Download Course (Free)

Course Content

0 / 85 completed
Section 1: Differences in Computer Based Investigations4 videos

Filesystem Structure

1h 4m

Digital Forensics 101

1h 16m

Types of Criminal Investigations

1h 30m

Identifying Files without Extensions

1h 30m
Section 2: Computer Systems3 videos

Boot Process and How not to alter Digital Evidence

1h 18m

Creating Bootable Forensics Media

1h 30m

Using Correct Tools in Specific Scenarios and Order of Volatility

1h 30m
Section 3: Storage Acquisition4 videos

Rules for Evidence Acquisition for Digital Forensics Experts

1h 30m

Hashing and Bits Explained

1h 30m

Bit by bit copy of the evidence

1h 30m

Software Write Blocker vs Hardware Write Blocker

1h 30m
Section 4: Windows Memory Forensics4 videos

Decoding the Object Header

1h 30m

Important Details about the Evidence

1h 25m

Memory Acquisition with winpmem

1h 30m

Full Volatile Memory Acquisition using Magnet

1h 30m
Section 5: Memory Analysis using Volatility8 videos

Downloading and Installing Volatility Framework Safest Option

57m

Downloading Infected Malware Samples

42m

What Happened in This 12 Seconds and What did Investigator did wrong (Scena

1h 26m

Installing and Downloading Required Resources for our Level Up

1h 27m

Analyzing our First REAL Malware

1h 30m

The Difference Between Suspicious vs Stable Processes

1h 30m

Getting Closer to Rootkit

1h 30mNow Playing

Hunting the Malware Inside Memory

1h 30m
Section 6: Windows Forensics Registry5 videos

Why Registry is so important in evidence acquisition

1h 16m

Registry Acquisition with KAPE

1h 26m

The Power of Powershell and CMD when accessing Registry

1h 30m

Structure of Windows Registry

1h 30m

Windows Registry GOLDMINE

1h 30m
Section 7: Windows Artifact Analysis4 videos

Preparing our Environment for Advanced Windows Forensics

1h 30m

This Function of Windows is not for Security but this is a nightmare for hackers

1h 14m

GUI Alternative for Viewing Prefetch Files on Live System

1h 30m

Diving into Prefetch Goldmine for Executable Evidence

1h 30m
Section 8: Introduction to Cryptography for Digital Forensics8 videos

John The Ripper

23m

Open Source Intelligence and Password Cracking

1h 30m

The Password Theory

32m

Hashcat

1h 29m

John The Ripper (Windows, Linux and Mac OS)

1h 30m

John The Ripper Rules

1h 30m

John The Ripper - Part 2

1h 30m

Hashcat - Rules, Wordlist Generation and other

1h 1m
Section 9: Windows Cryptography Masterclass for Decrypting Evidence and Hashes4 videos

Windows Security and Passwords

58m

Extracting hashes from hives

1h 21m

Win-Extracting Sam, Security and System Saves

1h 30m

Cracking NTLM with John The Ripper

1h 5m
Section 10: Linux Cryptography for Decrypting Evidence2 videos

Getting Linux Hashes and Understanding Struct

1h 30m

Cracking Linux hash, SHA256 and yescrypt

1h 30m
Section 11: Forensics Analysis of USB Devices3 videos

Difference Between MSC MTP and PTP and why PTP is not needed for evidence

1h 30m

Easiest way to analyze old USB Devices

1h 30m

Connected USB Devices History and Building a Case Report Like a Detective

1h 30m
Section 12: Network Forensics11 videos

What, Why and When's of Packet Analysis

1h 9m

Understanding Layer 1,2,3 - Hubs, Switches and Routers

41m

Traffic Classifications

35m

Difference between hubs and switches and the information they contain

22m

How Packet Analysis works and Network Forensics Work

51m

Why is Wireshark best tool for our topic

43m

Downloading and Installing Wireshark

44m

How To's of Network Sniffing

1h 30m

Installing and Configuring Wireshark and other Tools in Linux

49m

Integrated or External WiFi Adapters

52m

Customizing Wireshark

1h 30m
Section 13: Advanced Network Forensics7 videos

Merging Packets from Different Devices for Complete Forensics Analysis

58m

Capture Options

33m

Starting with Filters in Wireshark for Searching the Crime we're looking for

1h 30m

Capture Filters

59m

Installing TcpDump and Tshark

42m

Display Filters

1h 15m

Working with Tshark and TCPDump

1h 8m
Section 14: Internet Protocol and Analyzing Malicious Traffic for Digital Forensics10 videos

Address Resolution Protocol

1h 3m

Internet Protocol (IP)in Theory

58m

Structure of TCP

31m

Time to Live and Routing behaviour

1h 23m

Structure of UDP

43m

UDP Packet analysis - DNS Response

1h 28m

Detailed Analysis of TCP Packet

1h 30m

HTTP Packet Structure

30m

HTTP Communication Analysis

1h 30m

Full DHCP Communication Packet Analysis with Wireshark

1h 30m
Section 15: Packet Analysis and Network Forensics4 videos

Packets don't lie

31m

How a Failed Network Scan or DDOS Attack looks like

1h 13m

Analyzing how Port Scans work Wireshark Statistics

1h 30m

Wireshark and Threat Hunting

1h 30m
Section 16: Browser Forensics4 videos

Why Browser Forensics is a Goldmine for Catching Criminals

1h 30m

Chromium Based Browser Forensics - Extracting User Data and Detailed History

1h 30m

Chromium Based Browser Forensics - Chrome, Opera, Brave and others

1h 30m

Firefox Based Browser Forensics

1h 30m