Home / Trainings

Learn it on our bench.

Two courses, both run on demand and deliberately kept small — no more than twelve seats, so every participant works on real hardware in a working forensics laboratory rather than watching someone else work on it.

Courses

Course 01

HDD data recovery

Forensics laboratory based
hard drive data recovery course

HDD Data Recovery TrainingBrochure · 5 pages · EN

Duration3 days · 08:45–18:00
VenueOn demand
SeatsOn demand — recommended no more than 12
LanguageEnglish / Cantonese / Mandarin
TrainerComputer forensics consultant, member of the High-Tech Crime Investigation Association (US)

A comprehensive course covering the recovery solutions for all common hard drive failures. It takes participants to practical, intermediate-to-advanced level hard drive recovery technique, plus the basic computer forensic skills needed for digital evidence preservation.

Learning objectives

  • Know all firmware components of a HDD and how they operate and interact
  • Understand how recovery tools read and diagnose each component to determine the cause of failure
  • Develop a strategy to fix the HDD from diagnostic results and the design criteria of that make and model
  • Develop and understand clean room procedure for physical HDD problems

This course is for

  • Police and law enforcement staff
  • Defence and military staff
  • Legal professionals
  • System administrators and IT department staff
  • Information security officers
  • Anyone involved or interested in the data recovery field

Prerequisites

  • Basic understanding of the computer operating system
  • Basic understanding of computer hardware

You train in our lab

  • Class 100 clean room
  • Platter and head exchanging workstation
  • Data recovery workstation with cables and drive components
  • Write blocker, forensic duplicator, password recovery tool, intelligence analysis tool, degaussers, media shredder

Course outline

Day 1

Course introduction and a full breakdown of hard drive anatomy — a starting point for beginners and a strong refresher for veterans.

Hard disk anatomy — design principles
  • History of the hard disk
  • Theory of operation
  • Basic components of a disk drive
  • Overview of disk interfaces — ST506 to SATA, SAS
  • Types of magnetic media
  • Data recovery success percentage
  • Structure of data on the platters
  • Servo information — track locating, head fine positioning, structure of servo data
  • Types of head, flying heights, and their relationship to bit density
Common file systems
  • DOS
  • FAT16 and FAT32
  • NTFS, Ext2, HFS+
Disk geometry
  • Track / sector data format
  • Physical and logical geometry — PCHS / LCHS / LBA addressing, disk System Area, zone geometry, BIOS geometry, negative cylinders
  • Sector / track / cylinder / zone / head tables
  • Types of bad sector mapping — G-List, P-List, U-List, LBA alignment
  • Translator — LBA28 / LBA48, static and dynamic translator types
HDD firmware structure
  • Embedded ROM
  • External flash ROM / NV-ROM
  • System Area raw overlay
  • Zone table

Day 2

Drive subsystems, physical diagnosis, and hands-on surface-mount rework.

Hard disk subsystem
  • Master and user password
  • High and maximum security
  • Unlock / erase / clear commands
  • Procedures to unlock an ATA drive
  • Principles of hard disks with Full Disk Encryption
Examining storage devices
  • Hard disks — 2.5" and 3.5", ATA, SATA, SCSI, SAS
  • Zip disk and LS120
  • Magneto-optical disks
  • Removable hard disks
  • Flash disks — thumb drives, SD cards
Printed circuit boards
  • PCB layout across drive brands
  • Board layers and function
  • Board layout and composition
  • Component types and their function
Diagnosing physical error
  • External visual and measurement diagnosis
  • Identifying major components and memory devices
  • Basic use of an oscilloscope
  • Determining device function
Surface mount technology
  • Operating a surface mount hot air rework station
  • Extensive training on removal of surface mount ICs
  • Hands-on practice resoldering surface mount ICs
Recovery tools on the market
  • Hardware — Atola Insight Forensic
  • Software — R-Studio

Day 3

An intense day of lectures, tutorials and practice around physical drive work and clean room procedure.

Physical data recovery flow
  • Proper HDD diagnostics
  • Platter swap
  • ATA password removal
  • PCB recovery
  • Head stack issues
  • HDD firmware recovery
  • PCB replacement
  • Preamplifier issues
  • Motor issues
  • Error prevention
Logical recovery case
  • MBR and EBR recovery
  • GPT disk introduction
  • HDD backup and duplication
  • File extraction
Clean room demonstration
  • Clean room procedure and HEPA micro filtration
  • Techniques for removal of heads
  • Re-engineering of hard disk assemblies
Hands-on practice
  • 1.8", 2.5" and 3.5" ATA / SATA hard disks
  • 2.5" SAS hard disk

Customisation

To meet different needs and help learners reach their goals, clients can customise the course attributes — time, place, language and closed-door requirements included.

Course 02

Macintosh forensic survival

Use a Mac to examine a Mac —
without expensive automated
forensic tools

Macintosh Forensic Survival CourseBrochure · 5 pages · EN

Duration5 days per level
Date & venueOn demand
SeatsOn demand — recommended no more than 12
LanguageEnglish
LevelDesigned for both the beginner Mac examiner and the advanced

The course covers examining a Macintosh computer from the first step to the last, in logical order. Surprising to most is that the entire course is taught using a Mac to examine a Mac, without expensive automated forensic tools. More surprising still is that participants find they can locate more evidence, and locate it faster.

Level 1

How and why you are missing evidence using Windows-based tools · How to use a Mac to process a Mac

#TopicDescription
01Non-Intel Mac issues — PowerPC and Classic OSIdentifying and handling antiquated Mac technology; the Classic OS review underpins modern artifacts and features.
02Overview of Mac OS X versionsFeatures of forensic importance in each Mac OS, and when they appeared.
03Understanding the Mac file systemA review of the file systems supported by Mac OS.
04Intel Mac technology and Boot CampThe forensic significance of Mac Intel technology.
05Mac security issues and FileVault attacksCurrent best practice for dealing with Mac security.
06Macintosh search and seizureBest practice for seizing Mac and iOS hardware.
07Safely obtaining system informationHow to obtain system information without making changes to the evidence.
08Bypassing Open Firmware passwordsWhat OFP is, how to remove it, and whether removal is necessary.
09Volatile data collectionBuilding a Trusted Utilities Disk and using it to collect volatile information.
10Manual and automated imagingUsing the Mac to safely image media, manually and with PALADIN.
11Imaging Mac RAMExercises in imaging Mac RAM and recovering passwords.
12Verifying and safely mounting imagesSafely mounting forensic images for processing.
13Indexing forensic imagesHow to index forensic images using Mac OS.
14Search techniques using Mac OS XCreating custom search expressions from the command line and the GUI.
15Locating evidenceIdentifying Mac artifacts in the file system — email, graphics, internet artifacts, documents, system artifacts, instant messaging, logs and more.
16Recovering deleted filesManually recovering deleted files, and the dangers of Mac optimisation.
17Examining SQLite databases and PLIST filesExamining the heart of Mac data storage.
18Using OS X for forensicsUtilising built-in Mac OS technology for forensic work.
19Report developmentCreating native reports using the Mac to properly view data.
20Examining iOS device artifactsIdentifying and examining iOS artifacts found on a Mac.
21Working with NTFSIntegrating Mac forensics into a Windows-centric forensic lab.
22Review of recommended applicationsRecommendations for commercial and non-commercial tools that assist Mac forensics.
23Review of automated forensic toolsA review of the current automated Mac forensic tools.
24Recommended Macintosh hardwareHardware recommendations for Mac forensic work.

Level 2

The forensic use and analysis of Apple hardware, technology and applications

#TopicDescription
01Advanced file system analysisThe concept of domains within Mac OS X, locating evidentiary artifacts in each, and manually deconstructing any installed application.
02Advanced command lineBeneath the Mac OS X desktop is the Unix shell. Advanced Terminal technique for forensic examination of a Mac.
03AppleScript and AutomatorCreating custom programs and workflows to automate and enhance forensic examinations.
04Identifying and using virtual machinesIdentifying VM use within Mac OS X, analysing them, and using a VM to assist examinations from within the Mac environment.
05Mac OS X Server forensicsServer technology, services and user accounts; best practice for acquiring data safely from live systems and responding to compromised ones.
06Macintosh timeline analysisBuilding a file system timeline that retraces a suspect's history minute by minute, and understanding Mac timestamps.
07iCloud forensicsFinding and analysing documents and other data synced with an Apple iCloud account.
08Unique Apple techniquesBest practice and resources for troublesome and unique Apple technology.
09Advanced search techniquesConducting advanced indexed and live searches to find any data.
10Application deconstructionFinding any or all artifacts left behind by any application.

Book a closed-door course.

Both courses run on demand, at our laboratory or at your site, in the language your team works in. Tell us how many seats you need and when.