Network Analysis and Host Forensics - 2 Day Hands On Lab
 Hands-On Lab Venues, Dates and Costs are listed below.

Fully Licensed NetScanTools Pro software included (RRP approx. A$335)
Bring Your Own Laptop: Take what you have learnt away with you. See Laptop Specs Below


Network Forensics
Network forensics is the process of listening in on the traffic to and from a victim system and to identify the communications to and from the victim. You will learn to identify OS fingerprinting processes, network flooding signatures, UDP/TCP/ICMP scans, vulnerability scans, etc. Recognizing the traffic patterns of these functions and their unique signatures enables you to block these communications inside and at the border of your network.

Host Forensics
So you have that compromised system on your desk – now what? Host forensics is the process of imaging the drive for off-line investigation of the drive contents. Where is the malware planted? Are any other files ‘of concern’ located on the victim’s drive? Host forensic tools enable us to remove the ‘known to be good’ files from the view so we can concentrate on the questionable files. You will perform host forensic analysis on the image of a victim’s drive.

What You Will Learn
Get hands-on experience and unrivaled instruction from Laura Chappell as she spends 2-days tapping into network traffic to perform network forensics and opening local images to perform host forensics. During this course students analyze suspicious traffic patterns to identify the cause for crashed systems, crashed and poorly performing networks. Students also install demo versions of several forensic tools including Forensic Toolkit, ProDiscover for Windows and X-Ways and perform host forensics to look for suspect data hidden on a drive in various forms. Tasks include

  • Identify the proper tool and location to tap into the network
  • Identify TCP/IP-based attack and interception methods
  • Capture man-in-the-middle attack sequences and analyze the methodology
  • Analyze the traffic of spyware-infected and browser-hijacked systems
  • Identify the unique signature of several hacking tools
  • Create and apply capture and display filters to isolate suspect traffic
  • Learn to protocol force to reveal tunneled or hidden communications
  • Create a host forensics case file and import an acquired image
  • Learn how KFF (Known File Format) libraries speed up forensic data reviews
  • Locate spreadsheets, emails, graphics, encrypted and deleted files in a suspect image
  • Index an image to improve search performance
  • Create a password cracking resource file from an indexed image
  • Use data carving to extract embedded files
  • Bookmark evidence and create a comprehensive forensic report
  • ...and More!
Recommended Audience
IT professionals interested in securing the network and performing investigations related to unusual network traffic and suspicious files on hosts.

Tools - You Will Use
  • Access Data's Forensic Toolkit
  • Altiris Audit Express
  • NetScan Tools Pro (fully licensed copy)
  • ProDiscover for Windows
  • Ethereal
  • WildPackets OmniPeek Personal
  • Hurricane Search
  • Davory
  • Trace
  • WinHex
  • and more...
Laura's Lab Kit
Students will receive a comprehensive lab book and other necessary materials for this class. All registrants will receive a copy of Laura's Lab Kit™ that you will be working with during the Course.
Laura's Lab Kit includes:
  • AcePasswordSniffer
  • Achilles
  • Ad-Aware
  • AIMSniffer
  • AirMagnet
  • AiroPeekNX
  • Brutus
  • CainAndAbel
  • Camtasia
  • CaptainNemo
  • Davory
  • Ethereal
  • EtherPeekNX
  • Ettercap
  • Everest
  • ForensicToolKit
  • FTKImager
  • HexWorkshop
  • HijackThis
  • HTTPSniffer
  • HurricaneSearch
  • ICQSniffer
  • Invisible Secrets
  • KeyGhost
  • KFSensor Honeypot/IDS
  • LANguard
  • MSNSniffer
  • OmniPeek Personal Edition (FREE)
  • NetScanToolsPro
  • PacketBuilder
  • PingPlotter
  • ProDiscoverWindows
  • RegistryViewer
  • RFCViewer
  • SMAC
  • SnagIt
  • SnifferProPortable
  • Specter
  • TCPView
  • Trace
  • WinHex
  • WinPcap
  • ...and more
Laptop Specs
  • Click here for specs
  • Students must install and test NetScanTools prior to class arrival. Only fully prepaid students will receive licensed copies of NetScanTools and course fees will not refunded once licensed software is delivered to the student.

Hands-On Lab Venues and Dates
CityDatesVenueMapActions
Melbourne17 Mar 2009 to 18 Mar 2009Regus Business Centre, Rialto South Tower, Level 27/F 525 Collins StreetMapRegistration Closed
Sydney19 Mar 2009 to 20 Mar 2009Regus Business Centre, Level 1, 151 Clarence StreetMapRegistration Closed

Hands-On Lab Costs
CostDescription
A$1,995.00 + GSTStandard
Notes
  • 8:30am registration
  • 9:00am to 5:00pm for training
  • Lunch, morning and afternoon tea and refreshments will be provided



  • Home | Stats Login | Refund Policy | Contact Us

    Powered by Front End Events

    Other Sites: Australian Tennis Rankings