• Home
  • >
  • Training
  • >
  • File-system Post-mortem Forensic Analysis

File-system Post-mortem Forensic Analysis

File-system Post-mortem Forensic Analysis

  • Department


  • Languages

    DE ; EN


    8 hours

  • TAGS

    forensic analysis

About the training

Forensic Analysis is based on the assumption that everything leaves a trace behind. A trace in an information system can be any data that helps to identify space and time actions. Post mortem analysis is a key tool to discover and analyse security incidents. This course will teach the participant on how to find answers to what has happened by analysing different layer from the physical medium to the file system up to the application level.

Training’s benefits

  • Perform disk acquisition the right way
  • Introduce to file system analysis (NTFS/FAT)
  • Analyse operating system artifacts (MS Windows)
  • Find evidences in communication applications (e.g. browser or chat history)


  • Knowledge of operating systems and IT security is required

Meet the trainer

Computer Incident Response Center Luxembourg (CIRCL). More about CIRCL here


For more detailed information, contact us at info@circl.lu

Related Training