|  | Network Analysis and Host Forensics - 2 Day Hands On Lab | | | Hands-On Lab Venues, Dates and Costs are listed below. |
 |
Fully Licensed NetScanTools Pro software included (RRP approx. A$335) Bring Your Own Laptop: Take what you have learnt away with you. See Laptop Specs Below
| | Network Forensics | Network forensics is the process of listening in on the traffic to and from a victim system and to identify the communications to and from the victim. You will learn to identify OS fingerprinting processes, network flooding signatures, UDP/TCP/ICMP scans, vulnerability scans, etc. Recognizing the traffic patterns of these functions and their unique signatures enables you to block these communications inside and at the border of your network.
| | Host Forensics | So you have that compromised system on your desk – now what? Host forensics is the process of imaging the drive for off-line investigation of the drive contents. Where is the malware planted? Are any other files ‘of concern’ located on the victim’s drive? Host forensic tools enable us to remove the ‘known to be good’ files from the view so we can concentrate on the questionable files. You will perform host forensic analysis on the image of a victim’s drive.
| | What You Will Learn | Get hands-on experience and unrivaled instruction from Laura Chappell as she spends 2-days tapping into network traffic to perform network forensics and opening local images to perform host forensics. During this course students analyze suspicious traffic patterns to identify the cause for crashed systems, crashed and poorly performing networks. Students also install demo versions of several forensic tools including Forensic Toolkit, ProDiscover for Windows and X-Ways and perform host forensics to look for suspect data hidden on a drive in various forms. Tasks include
- Identify the proper tool and location to tap into the network
- Identify TCP/IP-based attack and interception methods
- Capture man-in-the-middle attack sequences and analyze the methodology
- Analyze the traffic of spyware-infected and browser-hijacked systems
- Identify the unique signature of several hacking tools
- Create and apply capture and display filters to isolate suspect traffic
- Learn to protocol force to reveal tunneled or hidden communications
- Create a host forensics case file and import an acquired image
- Learn how KFF (Known File Format) libraries speed up forensic data reviews
- Locate spreadsheets, emails, graphics, encrypted and deleted files in a suspect image
- Index an image to improve search performance
- Create a password cracking resource file from an indexed image
- Use data carving to extract embedded files
- Bookmark evidence and create a comprehensive forensic report
- ...and More!
| | Recommended Audience | IT professionals interested in securing the network and performing investigations related to unusual network traffic and suspicious files on hosts.
| | Tools - You Will Use | - Access Data's Forensic Toolkit
- Altiris Audit Express
- NetScan Tools Pro (fully licensed copy)
- ProDiscover for Windows
- Ethereal
- WildPackets OmniPeek Personal
- Hurricane Search
- Davory
- Trace
- WinHex
- and more...
| | Laura's Lab Kit | Students will receive a comprehensive lab book and other necessary materials for this class. All registrants will receive a copy of Laura's Lab Kit™ that you will be working with during the Course. Laura's Lab Kit includes:- AcePasswordSniffer
- Achilles
- Ad-Aware
- AIMSniffer
- AirMagnet
- AiroPeekNX
- Brutus
- CainAndAbel
- Camtasia
- CaptainNemo
- Davory
- Ethereal
- EtherPeekNX
- Ettercap
- Everest
| - ForensicToolKit
- FTKImager
- HexWorkshop
- HijackThis
- HTTPSniffer
- HurricaneSearch
- ICQSniffer
- Invisible Secrets
- KeyGhost
- KFSensor Honeypot/IDS
- LANguard
- MSNSniffer
- OmniPeek Personal Edition (FREE)
- NetScanToolsPro
| - PacketBuilder
- PingPlotter
- ProDiscoverWindows
- RegistryViewer
- RFCViewer
- SMAC
- SnagIt
- SnifferProPortable
- Specter
- TCPView
- Trace
- WinHex
- WinPcap
- ...and more
|
| | Laptop Specs | - Click here for specs
- Students must install and test NetScanTools prior to class arrival. Only fully prepaid students will receive licensed copies of NetScanTools and course fees will not refunded once licensed software is delivered to the student.
|
| Hands-On Lab Venues and Dates | | Melbourne | 17 Mar 2009 to 18 Mar 2009 | Regus Business Centre, Rialto South Tower, Level 27/F 525 Collins Street | Map | Registration Closed | | Sydney | 19 Mar 2009 to 20 Mar 2009 | Regus Business Centre, Level 1, 151 Clarence Street | Map | Registration Closed |
| Hands-On Lab Costs | | A$1,995.00 + GST | Standard |
| | Notes | | 8:30am registration9:00am to 5:00pm for trainingLunch, morning and afternoon tea and refreshments will be provided |
|
|