FILE-SYS-FORENSIC.AP1
File System Forensic Analysis
Be a smart learner ready to master file system forensic analysis and level up their skills with an interactive course.
- Practice in 18 Hands-On Labs — nothing to install
- 19 Interactive Lessons and 115 topics mapped to the official exam objectives
Intermediate Self-paced · 1 year access
18 Hands-On LiveLabs
Practice real IT tasks in guided environments.
- Real environments
- Auto-graded
- No installation
01 / Skills you'll get
What you will be able to do
Enroll in our file system forensic analysis course to master the techniques needed to uncover hidden evidence, recover deleted data, and validate forensic evidence.
In this course, dive into hard disk acquisition, partition analysis, and file system structures from FAT and NTFS to Ext2/Ext3 and UFS. Learn how to use powerful open-source tools like the Sleuth Kit and Autopsy Forensic Browser to investigate real-world cases.
- Analyzing File Systems: Master the structures of FAT, NTFS, Ext2/Ext3, and UFS to locate hidden or deleted evidence.
- Disk Acquisition & Preservation: Learn proper techniques for duplicating and handling digital evidence without corruption.
- Partition & Volume Analysis: Decode DOS, Apple, GPT, and RAID configurations to uncover critical data.
- Data Recovery & Metadata Examination: Recover deleted files and analyze timestamps, permissions, and file attributes.
- Using Forensic Tools: Gain hands-on experience with The Sleuth Kit (TSK) and Autopsy Forensic Browser for investigations.
- Validating Forensic Findings: Develop methods to verify tool accuracy and ensure evidence integrity for legal cases.
Course Highlights
-
19 Structured Lessons Comprehensive coverage of core course objectives
-
18 Hands-On LiveLabs Interactive guided scenarios with instant evaluation
-
1 Year Full Access Self-paced learning accessible anytime on all devices
02 / Lessons & labs
See exactly what you will learn and practice
Lessons
19 Interactive Lessons · 115 topics01 Introduction 2 topics +
- Roadmap
- Scope of Course
02 Digital Investigation Foundations 5 topics · 1 LiveLab +
- Digital Investigations and Evidence
- Digital Crime Scene Investigation Process
- Data Analysis
- Overview of Toolkits
- Summary
1 LiveLab in this lesson — see the labs panel →
03 Computer Foundations 4 topics · 1 LiveLab +
- Data Organization
- Booting Process
- Hard Disk Technology
- Summary
1 LiveLab in this lesson — see the labs panel →
04 Hard Disk Data Acquisition 5 topics · 1 LiveLab +
- Introduction
- Reading the Source Data
- Writing the Output Data
- A Case Study Using dd
- Summary
1 LiveLab in this lesson — see the labs panel →
05 Volume Analysis 4 topics +
- Introduction
- Background
- Analysis Basics
- Summary
06 PC-based Partitions 4 topics · 2 LiveLab +
- DOS Partitions
- Apple Partitions
- Removable Media
- Summary
2 LiveLab in this lesson — see the labs panel →
07 Server-based Partitions 4 topics · 1 LiveLab +
- BSD Partitions
- Sun Solaris Slices
- GPT Partitions
- Summary
1 LiveLab in this lesson — see the labs panel →
08 Multiple Disk Volumes 3 topics · 1 LiveLab +
- RAID
- Disk Spanning
- Summary
1 LiveLab in this lesson — see the labs panel →
09 File System Analysis 9 topics · 2 LiveLab +
- What Is a File System?
- File System Category
- Content Category
- Metadata Category
- File Name Category
- Application Category
- Application-level Search Techniques
- Specific File Systems
- Summary
2 LiveLab in this lesson — see the labs panel →
10 FAT Concepts and Analysis 8 topics · 1 LiveLab +
- Introduction
- File System Category
- Content Category
- Metadata Category
- File Name Category
- The Big Picture
- Other Topics
- Summary
1 LiveLab in this lesson — see the labs panel →
11 FAT Data Structures 6 topics +
- Boot Sector
- FAT32 FSINFO
- FAT
- Directory Entries
- Long File Name Directory Entries
- Summary
12 NTFS Concepts 8 topics · 1 LiveLab +
- Introduction
- Everything is a File
- MFT Concepts
- MFT Entry Attribute Concepts
- Other Attribute Concepts
- Indexes
- Analysis Tools
- Summary
1 LiveLab in this lesson — see the labs panel →
13 NTFS Analysis 8 topics · 2 LiveLab +
- File System Category
- Content Category
- Metadata Category
- File Name Category
- Application Category
- The Big Picture
- Other Topics
- Summary
2 LiveLab in this lesson — see the labs panel →
14 NTFS Data Structures 5 topics · 1 LiveLab +
- Basic Concepts
- Standard File Attributes
- Index Attributes and Data Structures
- File System Metadata Files
- Summary
1 LiveLab in this lesson — see the labs panel →
15 Ext2 and Ext3 Concepts and Analysis 9 topics · 2 LiveLab +
- Introduction
- File System Category
- Content Category
- Metadata Category
- File Name Category
- Application Category
- The Big Picture
- Other Topics
- Summary
2 LiveLab in this lesson — see the labs panel →
16 Ext2 and Ext3 Data Structures 10 topics · 2 LiveLab +
- Superblock
- Group Descriptor Tables
- Block Bitmap
- Inodes
- Extended Attributes
- Directory Entry
- Symbolic Link
- Hash Trees
- Journal Data Structures
- Summary
2 LiveLab in this lesson — see the labs panel →
17 UFS1 and UFS2 Concepts and Analysis 8 topics +
- Introduction
- File System Category
- Content Category
- Metadata Category
- File Name Category
- The Big Picture
- Other Topics
- Summary
18 UFS1 and UFS2 Data Structures 11 topics +
- UFS1 Superblock
- UFS2 Superblock
- Cylinder Group Summary
- UFS1 Group Descriptor
- UFS2 Group Descriptor
- Block and Fragment Bitmaps
- UFS1 Inodes
- UFS2 Inodes
- UFS2 Extended Attributes
- Directory Entries
- Summary
19 Appendix A: The Sleuth Kit and Autopsy 2 topics +
- The Sleuth Kit
- Autopsy
Hands-On Labs Our edge
18 LiveLabs- Utilizing a Forensic Tool
- Analyzing Hard Disk Geometry for Forensic Investigation
- Performing Forensic Imaging and Integrity Verification of a Disk Image Using dd
- Analyzing Partition Structures with fdisk and mmls
- Analyzing Partitions on Removable Media and CDs
- Analyzing GPT Disk Structure Using mmls and dd Commands
- Configuring RAID
- Analyzing and Recovering Files Using the File Name Category
- Evaluating Data Carving and File Type Sorting
- Exploring FAT File System Metadata and Directory Entries
- Exploring NTFS Metadata and File Entries with Analysis Tools
- Investigating the $Secure Metadata File in NTFS
- Exploring and Analyzing NTFS File System Metadata Files
- Exploring NTFS Index Attributes and Data Structures
- Discovering and Analyzing an ExtX File System on a Disk Without a Partition Table
- Tracking a Moved File and Determining File Deletion Order in a Linux EXT3 File System
- Analyzing Block Bitmap and Inode Information in an ext3 File System Using TSK
- Analyzing Journals and Indirect Blocks in an ext3 File System Using TSK
03 / FAQs
Questions before you start
What is forensic analysis of a file system?+
File system forensic analysis involves examining digital storage structures (e.g., NTFS, FAT, Ext4) to recover evidence like deleted files, hidden data, and metadata (timestamps, permissions).
It uses tools like The Sleuth Kit (TSK) and Autopsy to analyze partitions, RAID configurations, and file systems for legal or investigative purposes. Key tasks include:
- Recovering overwritten data from slack space or unallocated clusters.
- Validating tool accuracy to ensure evidence integrity.
What are the four types of forensic analysis?+
Some of the forensic analysis methods include:
- Disk Acquisition: Creating bit-by-bit copies of storage media using write-blockers to prevent tampering.
- File System Analysis: Examining file structures (e.g., $MFT in NTFS) to trace file movements and timestamps.
- Network Forensics: Analyzing traffic logs for breaches or malware communications.
- Memory Forensics: Extracting volatile data (e.g., running processes) from RAM.
What qualifications do I need for digital forensics?+
- Education: A bachelor’s degree in computer science, cybersecurity, or digital forensics is typical. Advanced roles may require a master’s.
- Certifications: GIAC Certified Forensic Analyst (GCFA), EnCase Certified Examiner (EnCE), or CompTIA Security+ for foundational knowledge.
- Skills: Develop proficiency in tools like FTK, X-Ways, and scripting (Python/Bash) with our digital forensic training.
How can I become a digital forensic analyst?+
To secure digital forensic analyst jobs, follow the checklist below:
- Earn a Degree: Focus on cybersecurity or computer science.
- Gain Experience: Start in IT roles (e.g., network analyst) to build technical skills.
- Get Certified: Pursue GCFA or CFCE to validate expertise.
- Specialize: Choose niches like mobile forensics or malware analysis.
- Stay Updated: Follow trends via organizations like SWGDE or HTCIA.
Learn to Find Hidden Digital Evidence
Level up your cybersecurity skills while you dissect disks, trace timestamps, and crack cases in this hands-on file system forensic analysis course.
- 1 year of full access
- 18 LiveLab included
- Certificate of completion
No credit card required