Learning Outcomes:
Upon successful completion of this module, students should be able to:
• Describe the live data forensic process
• Prepare teams for live data forensics on site searches
• Know how to prepare a toolkit for LDF
• Know the legal aspects of live data forensics
• Perform triage on systems/devices/networks
• Explain the order of volatility and the Chain of Custody
• Acquire and basic analyse the contents of RAM
• Gather information on running systems/devices
• Know the risks of IoT/Smart home devices in site searches
• Gather information from IoT/Smart home devices
• Detect encrypted volumes and anti-forensics
• Preserve information found on running systems in a forensically sound manner
• Analyse gathered artefacts and report their findings
• Advise an investigative team towards further investigative directions
• Research new devices or techniques in the field of live data forensics