NISGTC Forensics

Cybersecurity

Overview

NISGTC Forensics labs, developed by the National Information Security and Geospatial Technologies Consortium (NISGTC), provide hands-on experience in digital forensics practices. Licensed under Creative Commons Attribution 3.0 Unported. Development was funded by the Department of Labor (DOL) TAACCCT Grant No. TC-22525-11-60-A-48.

Lab Exercises (16 labs)
# Title
1 Introduction to File Systems
2 Common Locations of Windows Artifacts
3 Hashing Data Sets
4 Drive Letter Assignments in Linux
5 The Imaging Process
6 Introduction to Single Purpose Forensic Tools
7 Introduction to Autopsy Forensic Browser
8 Introduction to PTK Forensics Basic Edition
9 Analyzing a FAT Partition with Autopsy
10 Analyzing a NTFS Partition with PTK
11 Browser Artifact Analysis
12 Communication Artifacts
13 User Profiles and the Windows Registry
14 Log Analysis
15 Memory Analysis
16 Forensic Case Capstone
Pod Topology Forensics (FOR) Pod
Forensics (FOR) Pod

Virtual Machines

Forensics_Master_Deft (Deft) Forensics_Master_Backtrack5 (BackTrack) Forensics_Master_WindowsXP (Windows XP Pro) Forensics_Master_pfSense (pfSense) Forensics_Master_LinuxSniffer (Linux Sniffer) Forensics_Master_Kali (Kali) Forensics_Master_Windows7 (Windows 7)

Documentation & Resources

Setup: Install NISGTC Forensics via the Course Manager. See the Admin Guide →

Related Labs

Palette (preview)