Course 01
HDD data recovery
Forensics laboratory based
hard drive data recovery course
| Duration | 3 days · 08:45–18:00 |
|---|---|
| Venue | On demand |
| Seats | On demand — recommended no more than 12 |
| Language | English / Cantonese / Mandarin |
| Trainer | Computer forensics consultant, member of the High-Tech Crime Investigation Association (US) |
A comprehensive course covering the recovery solutions for all common hard drive failures. It takes participants to practical, intermediate-to-advanced level hard drive recovery technique, plus the basic computer forensic skills needed for digital evidence preservation.
Learning objectives
- Know all firmware components of a HDD and how they operate and interact
- Understand how recovery tools read and diagnose each component to determine the cause of failure
- Develop a strategy to fix the HDD from diagnostic results and the design criteria of that make and model
- Develop and understand clean room procedure for physical HDD problems
This course is for
- Police and law enforcement staff
- Defence and military staff
- Legal professionals
- System administrators and IT department staff
- Information security officers
- Anyone involved or interested in the data recovery field
Prerequisites
- Basic understanding of the computer operating system
- Basic understanding of computer hardware
You train in our lab
- Class 100 clean room
- Platter and head exchanging workstation
- Data recovery workstation with cables and drive components
- Write blocker, forensic duplicator, password recovery tool, intelligence analysis tool, degaussers, media shredder
Course outline
Day 1
Course introduction and a full breakdown of hard drive anatomy — a starting point for beginners and a strong refresher for veterans.
Hard disk anatomy — design principles
- History of the hard disk
- Theory of operation
- Basic components of a disk drive
- Overview of disk interfaces — ST506 to SATA, SAS
- Types of magnetic media
- Data recovery success percentage
- Structure of data on the platters
- Servo information — track locating, head fine positioning, structure of servo data
- Types of head, flying heights, and their relationship to bit density
Common file systems
- DOS
- FAT16 and FAT32
- NTFS, Ext2, HFS+
Disk geometry
- Track / sector data format
- Physical and logical geometry — PCHS / LCHS / LBA addressing, disk System Area, zone geometry, BIOS geometry, negative cylinders
- Sector / track / cylinder / zone / head tables
- Types of bad sector mapping — G-List, P-List, U-List, LBA alignment
- Translator — LBA28 / LBA48, static and dynamic translator types
HDD firmware structure
- Embedded ROM
- External flash ROM / NV-ROM
- System Area raw overlay
- Zone table
Day 2
Drive subsystems, physical diagnosis, and hands-on surface-mount rework.
Hard disk subsystem
- Master and user password
- High and maximum security
- Unlock / erase / clear commands
- Procedures to unlock an ATA drive
- Principles of hard disks with Full Disk Encryption
Examining storage devices
- Hard disks — 2.5" and 3.5", ATA, SATA, SCSI, SAS
- Zip disk and LS120
- Magneto-optical disks
- Removable hard disks
- Flash disks — thumb drives, SD cards
Printed circuit boards
- PCB layout across drive brands
- Board layers and function
- Board layout and composition
- Component types and their function
Diagnosing physical error
- External visual and measurement diagnosis
- Identifying major components and memory devices
- Basic use of an oscilloscope
- Determining device function
Surface mount technology
- Operating a surface mount hot air rework station
- Extensive training on removal of surface mount ICs
- Hands-on practice resoldering surface mount ICs
Recovery tools on the market
- Hardware — Atola Insight Forensic
- Software — R-Studio
Day 3
An intense day of lectures, tutorials and practice around physical drive work and clean room procedure.
Physical data recovery flow
- Proper HDD diagnostics
- Platter swap
- ATA password removal
- PCB recovery
- Head stack issues
- HDD firmware recovery
- PCB replacement
- Preamplifier issues
- Motor issues
- Error prevention
Logical recovery case
- MBR and EBR recovery
- GPT disk introduction
- HDD backup and duplication
- File extraction
Clean room demonstration
- Clean room procedure and HEPA micro filtration
- Techniques for removal of heads
- Re-engineering of hard disk assemblies
Hands-on practice
- 1.8", 2.5" and 3.5" ATA / SATA hard disks
- 2.5" SAS hard disk
Customisation
To meet different needs and help learners reach their goals, clients can customise the course attributes — time, place, language and closed-door requirements included.
Course 02
Macintosh forensic survival
Use a Mac to examine a Mac —
without expensive automated
forensic tools
| Duration | 5 days per level |
|---|---|
| Date & venue | On demand |
| Seats | On demand — recommended no more than 12 |
| Language | English |
| Level | Designed for both the beginner Mac examiner and the advanced |
The course covers examining a Macintosh computer from the first step to the last, in logical order. Surprising to most is that the entire course is taught using a Mac to examine a Mac, without expensive automated forensic tools. More surprising still is that participants find they can locate more evidence, and locate it faster.
Level 1
How and why you are missing evidence using Windows-based tools · How to use a Mac to process a Mac
| # | Topic | Description |
|---|---|---|
| 01 | Non-Intel Mac issues — PowerPC and Classic OS | Identifying and handling antiquated Mac technology; the Classic OS review underpins modern artifacts and features. |
| 02 | Overview of Mac OS X versions | Features of forensic importance in each Mac OS, and when they appeared. |
| 03 | Understanding the Mac file system | A review of the file systems supported by Mac OS. |
| 04 | Intel Mac technology and Boot Camp | The forensic significance of Mac Intel technology. |
| 05 | Mac security issues and FileVault attacks | Current best practice for dealing with Mac security. |
| 06 | Macintosh search and seizure | Best practice for seizing Mac and iOS hardware. |
| 07 | Safely obtaining system information | How to obtain system information without making changes to the evidence. |
| 08 | Bypassing Open Firmware passwords | What OFP is, how to remove it, and whether removal is necessary. |
| 09 | Volatile data collection | Building a Trusted Utilities Disk and using it to collect volatile information. |
| 10 | Manual and automated imaging | Using the Mac to safely image media, manually and with PALADIN. |
| 11 | Imaging Mac RAM | Exercises in imaging Mac RAM and recovering passwords. |
| 12 | Verifying and safely mounting images | Safely mounting forensic images for processing. |
| 13 | Indexing forensic images | How to index forensic images using Mac OS. |
| 14 | Search techniques using Mac OS X | Creating custom search expressions from the command line and the GUI. |
| 15 | Locating evidence | Identifying Mac artifacts in the file system — email, graphics, internet artifacts, documents, system artifacts, instant messaging, logs and more. |
| 16 | Recovering deleted files | Manually recovering deleted files, and the dangers of Mac optimisation. |
| 17 | Examining SQLite databases and PLIST files | Examining the heart of Mac data storage. |
| 18 | Using OS X for forensics | Utilising built-in Mac OS technology for forensic work. |
| 19 | Report development | Creating native reports using the Mac to properly view data. |
| 20 | Examining iOS device artifacts | Identifying and examining iOS artifacts found on a Mac. |
| 21 | Working with NTFS | Integrating Mac forensics into a Windows-centric forensic lab. |
| 22 | Review of recommended applications | Recommendations for commercial and non-commercial tools that assist Mac forensics. |
| 23 | Review of automated forensic tools | A review of the current automated Mac forensic tools. |
| 24 | Recommended Macintosh hardware | Hardware recommendations for Mac forensic work. |
Level 2
The forensic use and analysis of Apple hardware, technology and applications
| # | Topic | Description |
|---|---|---|
| 01 | Advanced file system analysis | The concept of domains within Mac OS X, locating evidentiary artifacts in each, and manually deconstructing any installed application. |
| 02 | Advanced command line | Beneath the Mac OS X desktop is the Unix shell. Advanced Terminal technique for forensic examination of a Mac. |
| 03 | AppleScript and Automator | Creating custom programs and workflows to automate and enhance forensic examinations. |
| 04 | Identifying and using virtual machines | Identifying VM use within Mac OS X, analysing them, and using a VM to assist examinations from within the Mac environment. |
| 05 | Mac OS X Server forensics | Server technology, services and user accounts; best practice for acquiring data safely from live systems and responding to compromised ones. |
| 06 | Macintosh timeline analysis | Building a file system timeline that retraces a suspect's history minute by minute, and understanding Mac timestamps. |
| 07 | iCloud forensics | Finding and analysing documents and other data synced with an Apple iCloud account. |
| 08 | Unique Apple techniques | Best practice and resources for troublesome and unique Apple technology. |
| 09 | Advanced search techniques | Conducting advanced indexed and live searches to find any data. |
| 10 | Application deconstruction | Finding any or all artifacts left behind by any application. |