Skip to main content

The disk holds the key to almost everything on a system. Learn disk image acquisition and analysis, then dive deep into a data exfiltration case covering Windows and Linux systems.

This module dives into the significance of cold system forensics, focusing primarily on disk-based evidence. You will learn how to acquire a disk image and explore a popular tool for disk image analysis. At the end of this module, you will use your knowledge of Windows and Linux Endpoint Investigations to solve a high-stakes data exfiltration case.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.