Magnet Forensics

AX250 - AXIOM ADVANCED COMPUTER FORENSICS

Advanced Computer Forensics (AX250) is an expert-level course, designed for participants who are familiar with the principles of digital forensics and who are seeking to leverage Magnet AXIOM to increase their ability to investigate complex crimes utilizing AXIOM and complementary third-party tools. At the conclusion of this 4-day training course, participants will have the knowledge and skills they need to track computer access and file usage, utilizing Magnet AXIOM to explore the evidence in greater depth by learning about the newest sign-on technologies such as pin password, Windows Hello, picture password, fingerprint recognition, and Facial recognition. In this course a deeper understanding of investigating Windows computers will be provided by searching through artifacts like Windows Notification, Windows System Resource Utilization, Windows Error Reporting (WER) Logs, Event Logs (EVT), Event Tracing Logs (ETL), as well as a breakdown of the taskbar and whether an artifact was system pinned or user pinned to it. Also investigating EMDMgmt, to dig deep into tracking drives attached to the windows OS that may leave traces nowhere else. Investigating AppCompatFlags and AMCACHE, to determine executable files which were previously executed on the system but no longer exist. Tracking file and folder location on profiles based on information recovered from Shellbags. Maximizing the data from Prefetch files, Jumplists, and Recent Docs to correlate the data recovered from the previously artifacts. This course also takes a look at collecting RAM images and parsing those images for actionable intelligence in support of the investigation. Using Passware and the AXIOM Wordlist Generator to crack iTunes backups and Windows passwords from information in the Image of the suspect Hard Disk Drive including the most up to date versions of that software. Finally, participants of this course will investigate Google Drive, Modern Apps (Windows Store Apps), UsnJrnl and an in-depth look at File history and the extensible Database files tracking it.

Because AX250 is an expert-level course, it is recommended that students first complete Magnet AXIOM Examinations (AX200). AX200 will provide a thorough understanding of AXIOM that will help students focus on the mobile part of investigations in AX250. Click here to find out more about AX200.

 

OBJECTIVES OF MAGNET  ADVANCED COMPUTER FORENSICS

  • Course Scenario and overview of Windows 10 artifacts of sign in technologies, such as pin password, Windows hello, picture password, fingerprint recognition, and facial recognition and how those technologies affect the forensic community
  • Focus on utilizing not so well know registry locations to track volume serial numbers of volumes being accessed by the Windows Operating System and what files on those volumes were accessed
  • Investigate the Program Compatibility Assistant of the Windows Operating System to track software and the usage of executables on the suspect system regardless if it has since been removed
  • Interrogate Shelbags to give participants an understanding of what Shellbags are and how they can be used in an investigation to determine the if a file or path was accessed by a specific user
  • Examine prefetch files to track the use of encrypted containers as well as a wiping utility, you may or may not know is built into Windows in a much more in-depth view. Determine the secrets prefetch files may hold as well as how Windows stores and deletes them to ensure when they testify they are doing so with knowledge and confidence
  • Understanding Jumplists is just the beginning, being able to utilize the data provided to correlate information about previously existing drives and the files located on them which are no longer part of the system
  • Using Recent Docs to correlate data with the data from the previous lessons to continuously track key pieces of information across the system and see how and possibly when and where that data was accessed
  • Discuss the collection of RAM and where and why it is important. Besides collecting this lesson also goes into the basics of RAM examination using volatility and AXIOM for carving Artifacts
  • Determining when the first and last time data was shared with other devices via Sync technology as well as how settings of one Windows system can be shared with other Windows systems including live Wi-Fi profiles and deleted profiles
  • Refresher on IOS backups and use of the AXIOM Wordlist generator (AWG) and Passware to gain entry to the IOS backup and obtain the password. The password will then be used to gain access to the keychain data containing additional passwords
  • Utilization of AXIOM, the AXIOM Wordlist Generator, and a combination of software to extract the Windows 10 password from the Sam hive using the algorithm stored in the System hive and the possible uses of those passwords
  • Interrogation of Backup and Sync artifacts which will be used to investigate uploading and downloading of files to a specific computer system
  • Investigate File History, which is a Windows 10 program which regularly backs up versions of files in the Documents, Music, Pictures, Videos, and Desktop folders and the OneDrive files available offline on a PC
  • Investigating Modern Apps, participants will gain an understanding that internet history and cache for Modern Apps are not stored in the usual locations where an examiner would expect and the recovery of those artifacts
  • Examine USN journal, which is a log of changes to files on an NTFS volume. Such changes can for instance be the creation, deletion or modification of files or directories. Participants will learn how to investigate the USNJrnl to retrieve forensic Artifacts in support of their Examination
  • A final scenario-based practical exercise which represents a cumulative review of the exercises conducted in each of the individual modules of this course
Select from the sessions below to register.

Advanced Computer Forensics - AX250

29Jan Advanced Computer Forensics - AX250 (Virtual – Instructor-Led Training) - January 29 - February 1, 2019
  • Jan 29 9:00 AM to Jan 29 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • Jan 30 9:00 AM to Jan 30 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • Jan 31 9:00 AM to Jan 31 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • Feb 01 9:00 AM to Feb 01 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
Class Full
12Feb Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - Herndon, VA - February 12-15, 2019
  • Feb 12 9:00 AM to Feb 12 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
  • Feb 13 9:00 AM to Feb 13 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
  • Feb 14 9:00 AM to Feb 14 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
  • Feb 15 9:00 AM to Feb 15 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
13 of 18 seats available
Register
19Feb Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - Private Class, UK -February 19-22, 2019
  • Feb 19 9:00 AM to Feb 19 5:00 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Nodor House, South Road, Bridgend Industrial estate, Bridgend CF31 3PT
    Instructor: Saige Derhak
  • Feb 20 9:00 AM to Feb 20 5:00 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Nodor House, South Road, Bridgend Industrial estate, Bridgend CF31 3PT
    Instructor: Saige Derhak
  • Feb 21 9:00 AM to Feb 21 5:00 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Nodor House, South Road, Bridgend Industrial estate, Bridgend CF31 3PT
    Instructor: Saige Derhak
  • Feb 22 9:00 AM to Feb 22 5:00 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Nodor House, South Road, Bridgend Industrial estate, Bridgend CF31 3PT
    Instructor: Saige Derhak
05Mar Advanced Computer Forensics - AX250 (Virtual – Instructor-Led Training) - March 5-8, 2019
  • Mar 05 9:00 AM to Mar 05 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • Mar 06 9:00 AM to Mar 06 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • Mar 07 9:00 AM to Mar 07 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • Mar 08 9:00 AM to Mar 08 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
14 of 18 seats available
Register
07Mar Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - San Diego,CA - March 7-10, 2019 (Pre Techno Security & Digital Forensics Conference)
  • Mar 07 9:00 AM to Mar 07 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 10950 North Torrey Pines Road La Jolla, California 92037, USA
    Instructor: Saige Derhak
  • Mar 08 9:00 AM to Mar 08 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 10950 North Torrey Pines Road La Jolla, California 92037, USA
    Instructor: Saige Derhak
  • Mar 09 9:00 AM to Mar 09 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 10950 North Torrey Pines Road La Jolla, California 92037, USA
    Instructor: Saige Derhak
  • Mar 10 9:00 AM to Mar 10 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 10950 North Torrey Pines Road La Jolla, California 92037, USA
    Instructor: Saige Derhak
17 of 20 seats available
Register
29Mar Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - Nashville, TN - March 29 - April 1, 2019
  • Mar 29 9:00 AM to Mar 29 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 623 Union Street, Nashville, Tennessee 37219 USA
    Instructor: Saige Derhak
  • Mar 30 9:00 AM to Mar 30 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 623 Union Street, Nashville, Tennessee 37219 USA
    Instructor: Saige Derhak
  • Mar 31 9:00 AM to Mar 31 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 623 Union Street, Nashville, Tennessee 37219 USA
    Instructor: Saige Derhak
  • Apr 01 9:00 AM to Apr 01 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 623 Union Street, Nashville, Tennessee 37219 USA
    Instructor: Saige Derhak
5 of 25 seats available
Register
23Apr Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - Herndon, VA - April 23-26, 2019
  • Apr 23 9:00 AM to Apr 23 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
  • Apr 24 9:00 AM to Apr 24 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
  • Apr 25 9:00 AM to Apr 25 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
  • Apr 26 9:00 AM to Apr 26 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 2250 Corporate Park Drive, Suite 130, Herndon, VA 20171
    Instructor: Saige Derhak
15 of 18 seats available
Register
30Apr Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - Princes Risborough, UK -April 30 - May 3, 2019
  • Apr 30 8:30 AM to Apr 30 4:30 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Avatu, Unit E2 Regent Park, Summerleys Rd, Princes Risborough HP27 9LE
    Instructor: Saige Derhak
  • May 01 8:30 AM to May 01 4:30 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Avatu, Unit E2 Regent Park, Summerleys Rd, Princes Risborough HP27 9LE
    Instructor: Saige Derhak
  • May 02 8:30 AM to May 02 4:30 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Avatu, Unit E2 Regent Park, Summerleys Rd, Princes Risborough HP27 9LE
    Instructor: Saige Derhak
  • May 03 8:30 AM to May 03 4:30 PM ((UTC+00:00) Dublin, Edinburgh, Lisbon, London)
    Location: Avatu, Unit E2 Regent Park, Summerleys Rd, Princes Risborough HP27 9LE
    Instructor: Saige Derhak
12 of 12 seats available
Register
30Apr Advanced Computer Forensics - AX250 (Virtual – Instructor-Led Training) - April 30- May 3, 2019
  • Apr 30 9:00 AM to Apr 30 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • May 01 9:00 AM to May 01 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • May 02 9:00 AM to May 02 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
  • May 03 9:00 AM to May 03 5:00 PM ((UTC-06:00) Central Time (US & Canada))
    Location:
    Instructor: Saige Derhak
19 of 20 seats available
Register
11Jun Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) -Anaheim, CA- June 11-14, 2019
  • Jun 11 9:00 AM to Jun 11 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 1900 S State College Blvd, Ste 100 Anaheim, CA 92806-6136
    Instructor: Saige Derhak
  • Jun 12 9:00 AM to Jun 12 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 1900 S State College Blvd, Ste 100 Anaheim, CA 92806-6136
    Instructor: Saige Derhak
  • Jun 13 9:00 AM to Jun 13 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 1900 S State College Blvd, Ste 100 Anaheim, CA 92806-6136
    Instructor: Saige Derhak
  • Jun 14 9:00 AM to Jun 14 5:00 PM ((UTC-08:00) Pacific Time (US & Canada))
    Location: 1900 S State College Blvd, Ste 100 Anaheim, CA 92806-6136
    Instructor: Saige Derhak
15 of 15 seats available
Register
27Aug Advanced Computer Forensics - AX250 (Classroom – Instructor-Led Training) - Cary, NC - August 27-30. 2019
  • Aug 27 9:00 AM to Aug 27 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 120 Wilkinson Ave. Cary NC 27511
    Instructor: Saige Derhak
  • Aug 28 9:00 AM to Aug 28 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 120 Wilkinson Ave. Cary NC 27511
    Instructor: Saige Derhak
  • Aug 29 9:00 AM to Aug 29 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 120 Wilkinson Ave. Cary NC 27511
    Instructor: Saige Derhak
  • Aug 30 9:00 AM to Aug 30 5:00 PM ((UTC-05:00) Eastern Time (US & Canada))
    Location: 120 Wilkinson Ave. Cary NC 27511
    Instructor: Saige Derhak
18 of 18 seats available
Register