Training Calendar

Mon Tue Wed Thu Fri Sat Sun
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30

psmb

Total Visitors


Yesterday: 10
This Week: 10
Last Week: 6
This Month: 21
Last Month: 185
Total: 46492

Forensic & Anti-Forensic Data Recovery: Tools & Techniques

 

Course Overview

Forensic Data Recovery is the collection, preservation, analysis, and presentation of computer-related evidence. Computer evidence can be useful in criminal cases, civil litigation, and human resource and employment proceedings. Far more information is retained in a computer than most people realize. It's also more difficult to completely remove information than is generally thought. For these reasons, as well as others, computer forensic examinations can typically recover lost or deleted information (or at a minimum find evidence of the information) even when it has been intentionally deleted. Computer hard drive forensic examinations go far beyond normal data recovery techniques, probing areas and files on the media not normally accessed by untrained personnel. These examinations can locate whatever data a business, agency, or individual needs. Meanwhile for Anti-Forensic is a set of tools and techniques used as countermeasures for forensic analysis. Such techniques include data hiding, artefact wiping, disk cleaning utilities, file wiping utilities, disk degaussing/destruction techniques. This training course is designed to introduce the latest data recovery techniques and solutions. The training course would also offer counter countermeasures for forensic analysis.

 

 

 data recovery

Who Should Attend?

The course has been designed for IT personnel, administrators, computer support staffs and an end-user who are aware the importance of data in their storage. No previous repair or data recovery experience necessary. This training is intended to be introduced to the latest data recovery techniques and solutions. The Training Course would offer an excellent solution for Laptop / Desktop and External Hard Disk.

 

3-DaysTraining Course would offer an excellent solution for:

 

  1. Recovery of deleted hard drive files
  2. Crash/Corrupt operating system (Windows)
  3. Accidental Formatted of disks
  4. Virus Attack
  5. Partition loss or Corrupted
  6. Lost or Missing files and folders
  7. Email recovery. pst / .wab / .dbx / .mbx
  8. Password recovery (Workstation Win98/Vista/Win7/ Word/Excel/PDF )
  9. Delete/erase/wipe any file from any media easily and securely and none of the unerasers would bring it back
  10. Recover corrupted file from CD and DVD
  11. Repair corrupt Files after recover ( word/ excel/ pdf)

 

Training Methodology

 

Practical exercises combined with highly engaging activities will be used to reinforce learning objective. To highlight few of practical hands-on includes:

  • Recover deleted files
  • Recover data from CD / DVD
  • Recover data from SD Card / MicroSD
  • Recover data after MFT destroyed
  • Recover data after Hard Disk has been formatted.
  • Recover deleted Emails Outlook pst / .wab / .dbx / .mbx
  • Recover Windows XP / Win 7 Admin Password
  • Recover Windows Server Admin Password
  • Recover Password (Words /Excel )
  • Delete/erase/wipe any file from any media
  • Delete/erase/wipe all data from any media and bring it back
  • Anti-Forensic tools and techniques

 

Data Recovery – Schedule

Day 1

09.00am – 10.00am

What is a file system?

  • Attributes of a file system
  • Microsoft Operating System
10.00am – 10.30am

Breakfast

10.30am – 12.45pm

Hard Disk as a Storage Device

  • Platter/Heads/Circuit board /BIOS C-H-S Addressing

File System on-Disk format

  • Master Boot Record/OS Boot Record

Indexing Methods

  • FAT 16 – Attributes 16-bit addressing /Placement / File Entry Tables
  • FAT 32 – Attributes 32-bit addressing /Placement / File Entry Tables
  • TSF – Attributes (MFT) Database type/Placement/File Entry Tables

Data Area

  • FAT 16 – Root Directory (Static)
  • FAT 32 – Root Directory (Virtual)
  • NTSF – MFT (Virtual) /INDX (Virtual) / Data Area (Virtual)

12.45pm – 02.15pm

Lunch

02.15pm – 05.00pm

Practical Exercises I

Day 2

09.00am – 10.00am

File System Weaknesses

  • Corrupt MBR
  • Corrupt OS Boot Record
  • Corrupt FAT /NTFS
  • Corrupt MFT
  • Virus pre-empting operating system load

10.00am – 10.30am

Breakfast

10.30am – 12.45pm

Data Recovery

  • Operating system will not boot
  • MBR corrupted or missing
  • OS boot record corrupted or missing
  • OS Start up files missing or corrupted
  • Virus pre-empting operating system load

Practical Exercises II

12.45pm – 02.15pm

Lunch

02.15pm – 05.00pm

Practical Exercises III

                                                                        Day 3

09.00am – 10.00am

Anti-Forensic Data Recovery Solution

  • Data Hiding, Encryption and Steganography
  • Artefact wiping

10.00am – 10.30am

Breakfast

10.30am – 12.45pm

Anti-Forensic Data Recovery Solution (Continue)

  • Disk Cleaning Utilities
  • Disk degaussing/destruction
Practical Exercises IV

12.45pm – 02.15pm

Lunch

02.15pm – 05.00pm

Practical Exercises V