Module 1
New Technology File System (NTFS) Forensics (W40)
Investigate evidence stored in the New Technology File System. Explore NTFS structures and the forensic meaning of file-system artifacts.
Instructor · Divya Lakshmanan
- Modules:
- 5
- Lessons:
- 159
eForensics learning
Practical skills.
Verified progress.
What you'll learn
- Examine the structure of NTFS.
- Interpret hexadecimal file-system data.
- Apply file-carving techniques to recovery and investigation.
Prerequisites
Basics of Digital Forensics: Forensic Imaging Hashing File Naming Conventions Equipment and software: Forensic Images of NT File system will be provided to you. A computer running Ubuntu 16 LTS is required to forensically analyse the file system images. If you wish to take your own forensic images, then a computer running Windows is also required. Good internet connection to download tools as we go.
Module 2
Module 1
Assessments
(W40Q01) Hello NTFS! - Assignment 1
Module 3
Module 2
Assessments
(W40Q02) NTFS Surgery - Assignment 2
Module 4
Module 3
Assessments
(W40Q03) You seem special NTFS! - Assignment 3
Module 5
Module 4
Assessments
(W40Q04) I am NTFS and I know it! - Assignment 4
Module 6
Final Exam
Lessons will appear here after course content is added.
Assessments
(W40Q05) Final Exam
Course access
Unlock New Technology File System (NTFS) Forensics (W40).
Enter your email. We’ll send a sign-in code here without taking you away from this course.