Now that we can image a drive it is important to be able analyze the contents. Also, keep in mind that not everything you might be looking for is visible to the eye. This module will introduce you to analyzing and understanding digital evidence. We will look at steganography, which is hiding data in data. We will also cover a piece of software called Autopsy that can be used to analyze a forensic image and recover data. Finally, we will learn about metadata and magic numbers and how to view them.
Demonstrate the use of a steganography tool → LO #2
Demonstrate the ability to use a digital forensic tool to recover information → LO #2
Interpret metadata of files→ LO #2
Comprehend the Digital Forensics Process → LO #3