The course will enable students to recover and examine from peer-to-peer file-sharing applications (BitTorrent, LimeWire and BearShare), instant messaging applications (Windows® Live Messenger and Yahoo! Instant Messenger) and web browsers (Microsoft Internet Explorer and Mozilla-based browsers). Students will also be able to examine computer systems with regards to Trojan viruses and key loggers. Students will also learn important information with regard to the examination of Outlook PST, web and Lotus Notes email. Students will be able to properly explain the browser caching process and rebuild cached Internet Explorer web pages. The course provides in-depth coverage on artifacts involving:
Students will learn the history, operation and artifacts associated with peer-to-peer file-sharing applications such as BitTorrent™, LimeWire™ and BearShare.
Students will learn the impact of Trojan viruses through examination of:
• Defense issues
• The Windows® Registry
• Hash analysis
• Anti-virus scanning and virus analysis using the EnCase® Virtual File System (VFS) Module and the EnCase® Physical Disk Emulator (PDE) Module
Students will learn how to examine system monitors and key loggers
Students will learn how to identify artifacts from instant message clients such as Windows® Live Messenger and Yahoo!® Messenger
Students will learn the operation of the Microsoft® Internet Explorer web browser with regards to typed URLs, password and form-data storage, cookies, internet history and cache content
Students will learn how web pages are constructed and will use this information, together with their new-found knowledge of cached internet Explorer web content to correctly rebuild web pages
Students will learn about artifacts introduced with Microsoft® Internet Explorer 7
Students will learn about the history, operation and artifacts associated with Mozilla Firefox®
Students will learn about the operation of web search engines
Students will learn about web-based email
Students will learn about the Microsoft® Outlook PST structure and about viewing Lotus® Notes email data