fbpx

Course Python Forensics

Region:
  • Content
  • Training
  • Modules
  • General
    General
  • Reviews
  • Certificate
  • Course Python Forensics : Content

    In the course Python Forensics the participants learn to use the Python programming language for the investigation of data on desktop computers and mobile devices and the analysis of message traffic to support investigative research.

    Device Data Analysis

    The course targets the research and analysis of the data present on devices in file systems, browsers, log files and other data sources.

    Python Fundamentals and Libraries

    In the first place the fundamentals of the Python programming language are discussed in which data types, control flow, classes, modules, packages and comprehensions are discussed. Various Python Libraries that are important in criminal investigations are also discussed, such as the Regular Expression pattern matching library, the log library and the Date and Time library.

    File and Database Analysis

    Subsequently extensive attention is paid to the approach to the file system and the analysis of files. Special topics are the creation of Artifact Reports and the hashing of Data Streams.
    The analysis of databases such as SQLite, identifying gaps in them and data recovery are also part of the course program. Furthermore it is discussed how location data can be retrieved from Wi-Fi messages and the analysis of web server logs is treated.

    Audio and Video Analysis

    The analysis of audio and video data and the mining of PDF and Office Metadata are also part of the course schedule. The registry can also provide important information and its analysis is discussed.

    Mail Box Analysis

    Finally attention is paid to the analysis of PST and OST mail boxes, the reading and analysis of EML files and the detection and use of Key Loggers.

  • Course Python Forensics : Training

    Audience Course Python Forensics

    The course Python Forensics is designed for developers and analysts who want to learn how to use Python for criminal investigation to support the legal process.

    Prerequisites Training Python Forensics

    Knowledge and experience with Python programming is not strictly necessary to participate in this course. Experience in Python programming is beneficial to good understanding.

    Realization Training Python Forensics

    The theory in the course Python Forensics is discussed on the basis of presentation slides. Illustrative demos clarify the concepts. The theory is interchanged with exercises. Course times are from 9:30 to 16:30.

    Certificate Python Forensics

    After successful completion of the course the participants receive an official certificate Python Forensics.

    Python Forensics Course
  • Course Python Forensics : Modules

    Module 1 : Python Essentials

    Module 2 : Classes and Objects

    Module 3 : Python Libraries

    Python 2 versus Python 3
    Lines and Indentation
    Python Data Types
    Numbers and Strings
    Lists and Tuples
    Sets and Dictionaries
    Python Flow Control
    Comprehensions
    Functions
    Modules and Packages
    Exception Handling
    Python Object Orientation
    Creating Classes
    Class Members
    Creating and Using Objects
    Property Syntax
    Static Methods
    Encapsulation
    Inheritance and Polymorphism
    Constructor Chaining
    Overriding Methods
    Abstract Classes
    Regular Expressions
    Logging
    Log Configuration
    Generators
    Unit Testing
    Dates and Times
    JSON Access
    XML Access
    Numpy Library
    Pandas Library
    Plotting

    Module 4 : File Analysis

    Module 5 : DB and Mobile Data

    Module 6 : Extracting Metadata

    File I/O
    Iterating over Files
    Recording File Attributes
    Copying Files
    Attributes and Timestamps
    Hashing Data Streams
    Creating Artifact Reports
    Working with CSVs
    Visualizing Events with Excel
    Parsing PLIST Files
    Database Access
    Python DB API
    Handling SQLite Databases
    Identifying Gaps in SQLite
    Logging Results
    Putting Wi-Fi on the map
    Recover Messages
    Log-Based Artifact Recipes
    Parsing IIS Web Logs
    Interpreting daily.out Log
    Audio and Video Metadata
    Mining for PDF Metadata
    Review Executable Metadata
    Office Document Metadata
    Metadata Extractor with EnCase
    Networking Analysis
    Compromise Recipes
    Jump start with IEF
    Taking Names Recipes
    Viewing MSG Files

    Module 7 : Forensic Artifacts Recipes

    Module 8 : Parsing PST Containers

    Module 9 : Key Loggers

    Forensic Evidence Recipes
    Opening Acquisitions
    Gathering Media Information
    Processing Container Files
    Searching for Hashes
    Searching High and Low
    Reading the Registry
    Gathering User Activity
    Parsing Prefetch Files
    Indexing Internet History
    Dissecting the SRUM database
    Personal Storage Table
    PST and OST Mailboxes
    libpff and pypff
    Reading Emails
    Parsing EML files
    Traversing Folders
    Summarizing Data
    Using HTML Templates
    Heat Map
    Word Statistics
    pffexport and pffinfo
    Detecting Malicious Processes
    Hardware Keyloggers
    Software Keyloggers
    Monitoring Keyboard Events
    Capturing Screenshots
    Capturing Clipboard
    Monitoring Processes
    Multi Processing
    Keylogger Controllers
    Special Keys
    Non-English Keyboards
  • Course Python Forensics : General

    Course Forms

    All our courses are classroom courses in which the students are guided through the material on the basis of an experienced trainer with in-depth material knowledge. Theory is always interspersed with exercises.

    Customization

    We also do custom classes and then adjust the course content to your wishes. On request we will also discuss your practical cases.

    Course times

    The course times are from 9.30 to 16.30. But we are flexible in this. Sometimes people have to bring children to the daycare and other times are more convenient for them. In good consultation we can then agree on different course times.

    Hardware

    We take care of the computers on which the course can be held. The software required for the course has already been installed on these computers. You do not have to bring a laptop to participate in the course. If you prefer to work on your own laptop, you can take it with you if you wish. The required software is then installed at the start of the course.

    Software

    Our courses are generally given with Open Source software such as Eclipse, IntelliJ, Tomcat, Pycharm, Anaconda and Netbeans. You will receive the digital course material to take home after the course.

    Lunch

    The course includes lunch that we use in a restaurant within walking distance of the course room.

    Locations

    The courses are planned at various places in the country. A course takes place at a location if at least 3 people register for that location. If there are registrations for different locations, the course will take place at our main location, Houten which is just below Utrecht. A course at our main location also takes place with 2 registrations and regularly with 1 registration. And we also do courses at the customer’s location if they appreciate that.

    Evaluations

    At the end of each course, participants are requested to evaluate the course in terms of course content, course material, trainer and location. The evaluation form can be found at https://www.klantenvertellen.nl/reviews/1039545/spiraltrain?lang=en. The evaluations of previous participants and previous courses can also be found there.

    Copyright

    The intellectual property rights of the published course content, also referred to as an information sheet, belong to SpiralTrain. It is not allowed to publish the course information, the information sheet, in written or digital form without the explicit permission of SpiralTrain. The course content is to be understood as the description of the course content in sentences as well as the division of the course into modules and topics in the modules.

  • Course Python Forensics : Reviews

  • Course Python Forensics : Certificate