From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Digital forensic tools

Digital forensic tools

- In this section of the course, we're going to continue our discussion of digital forensics by investigating some of the digital forensic tools that are used by investigators in the collection, processing, and analysis of evidence during an incident response. Now, in this section, we're going to be focused on Domain 2, Security Operations, specifically, Objective 2.9. Objective 2.9 states that, given a scenario, you must use forensic analysis tools. So as we begin this section, we're going to begin by discussing what type of components are going to be found in a basic digital forensics workstation. Then, we'll discuss file carving tools, like foremost and strings, which are used to extract data from a hard disk's image, even if those files have been previously deleted. Next, we're going to talk about binary analysis tools, which allows an investigator to look at machine-readable code of a file, and analyze the function of a particular program or piece of potential malware. This…

Contents