Membership

Fourth Extended File System (EXT4) Forensics (W36)

Explore forensic analysis of the EXT4 file system. Build on imaging and hashing knowledge to understand Linux file-system evidence. This is an earlier course edition; examples reflect the tools and versions used when it was recorded.

Instructor · Divya Lakshmanan

Modules:
6
Lessons:
175

eForensics learning

Practical skills.
Verified progress.

What you'll learn

  • Explain EXT4 layout and internal structures.
  • Examine file-system data at byte level.
  • Apply forensic methods to EXT4 evidence.

Prerequisites

Basics of Digital Forensics: Imaging, hashing, file naming conventions. Equipment and software: A computer with Ubuntu 16.04 LTS installed in it (It is possible to use a VM, but in this course we will be using Ubuntu 16.04 LTS installed directly on the host machine – it would be a better option for the learning process.) Good internet connection to download tools on the fly

Module 2

Module 1

Assessments

Quiz Required

(W36Q01) THE CASE OF THE CURIOUS LEARNER - solution submission

Module 3

Module 2

Assessments

Quiz Required

(W36Q02) THE CASE OF DELETION - solution submission

Module 4

Module 3

Assessments

Quiz Required

(W36Q03) THE CASE OF LINKS AND ATTRIBUTES - Solution submission

Module 5

Module 4

Assessments

Quiz Required

(W36Q04) THE CASE OF THE FILE SYSTEM JOURNAL - solution submission

Course access

Unlock Fourth Extended File System (EXT4) Forensics (W36).

Enter your email. We’ll send a sign-in code here without taking you away from this course.