Monday, October 2, 2017
Examining the data to find out “what happened” in the case of suspected misconduct, criminal activity, or a system breach is more than looking at what is displayed on screen at the time of discovery. Often it requires imaging the hard drive or other non-volatile storage device, copying specific file system structures or acquiring volatile system memory to get a more complete picture. Learn about write-blockers, imaging techniques for non-volatile drives and RAID arrays and the acquisition and basic analysis of RAM. Materials and at-home examples will be provided.
Instructor: Bryan Burkhardt, Director, Electronic Crime Institute, Des Moines Area Community College
Time: 9:00am to 4:00pm
Location: FFA Enrichment Center, 1055 SW Prairie Trail Parkway, Ankeny, IA 50023
- FFA Enrichment Center