<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;feed=atom&amp;action=history</id>
		<title>Advanced Steganography Demystifying Steganography Investigation - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;action=history"/>
		<updated>2013-05-25T07:30:00Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;diff=8206&amp;oldid=prev</id>
		<title>Kskinner: moved Live Investigator Training to Advanced Steganography Demystifying Steganography Investigation</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;diff=8206&amp;oldid=prev"/>
				<updated>2009-10-06T20:31:02Z</updated>
		
		<summary type="html">&lt;p&gt;moved &lt;a href=&quot;/wiki/Live_Investigator_Training&quot; class=&quot;mw-redirect&quot; title=&quot;Live Investigator Training&quot;&gt;Live Investigator Training&lt;/a&gt; to &lt;a href=&quot;/wiki/Advanced_Steganography_Demystifying_Steganography_Investigation&quot; title=&quot;Advanced Steganography Demystifying Steganography Investigation&quot;&gt;Advanced Steganography Demystifying Steganography Investigation&lt;/a&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 20:31, 6 October 2009&lt;/td&gt;
			&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Kskinner</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;diff=8205&amp;oldid=prev</id>
		<title>Kskinner at 20:30, 6 October 2009</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;diff=8205&amp;oldid=prev"/>
				<updated>2009-10-06T20:30:35Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 20:30, 6 October 2009&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Live Investigator Training&lt;/del&gt;''' [&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;https&lt;/del&gt;://www.wetstonetech.com/cgi/shop.cgi?view,&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;7&lt;/del&gt;]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;'''&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Advanced Steganography Demystifying Steganography Investigation&lt;/ins&gt;''' [&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;http&lt;/ins&gt;://www.wetstonetech.com/cgi&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;-bin&lt;/ins&gt;/shop.cgi?view,&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;23&lt;/ins&gt;]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==&amp;#160;  ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==&amp;#160;  ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Live Investigator Training is designed to teach &lt;/del&gt;students &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;the techniques for acquiring digital evidence from a running suspect’s system &lt;/del&gt;in &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;an overt or covert manner. This includes acquiring running process state&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;open handles, process/port associations, system logs, installed devices, physical and logical drives&lt;/del&gt;, network &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;statistics &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;configuration, user accounts &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;logged in users.&amp;#160; Class participants &lt;/del&gt;will &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;also learn how &lt;/del&gt;to &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;acquire volatile memory &lt;/del&gt;and&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/or registry snapshots from the target host&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;This could include recently used applications and documents&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;recently visited web sites, chat logs &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;e-mails&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Physical RAM capture may contain vital password and account information, remnants &lt;/del&gt;of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;visited web sites, recent messages, phone numbers, e-mail addresses &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;chat identities&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;During this 2 day advanced class, &lt;/ins&gt;students &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;will participate &lt;/ins&gt;in &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;hands on experiments with stego’d images&lt;/ins&gt;, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;multimedia files&lt;/ins&gt;, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;advanced &lt;/ins&gt;network &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;protocols &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Steganographic file systems. Detailed analytical &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;jamming methods &lt;/ins&gt;will &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;be utilized &lt;/ins&gt;to &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;both discover &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;disrupt Steganographic operations&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Analysis of Steganographic file systems&lt;/ins&gt;, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;streaming steganography &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Voice Over Internet Protocol (VOIP) based steganography will be covered&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;A host &lt;/ins&gt;of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;both open source &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;proprietary technologies will be utilized during this class&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;'''Why Live Investigation?'''&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;As &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;many corporation’s networks are becoming large &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;often geographically divers&lt;/del&gt;, it is &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;imperative to practice &lt;/del&gt;a &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;live investigation technique&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt; LiveWire Investigator™ &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;it’s associated software bundle provides the capability &lt;/del&gt;of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;collecting &lt;/del&gt;and &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;analyzing comprehensive information regarding evidence contained on ‘live-running’ devices&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''Steganography is Evolving!'''&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;The art of analyzing steganography within images, multimedia and in network protocols is considered a black art. &lt;/ins&gt;As &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;criminals communicate &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;conceal vital information in new Steganographic file systems, voice over internet protocol (VOIP) streams and in a host of multimedia carriers&lt;/ins&gt;, it is &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;vital and urgent that &lt;/ins&gt;a &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;cadre of trained experts exist to counter this threat&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;A deep understanding &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;analysis &lt;/ins&gt;of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;images, multimedia files &lt;/ins&gt;and &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;network protocols along with clear understanding of the known methods of data hiding are essential in order to participate in this analysis&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 18:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 20:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160; ▫ Private investigators&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160; ▫ Private investigators&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160; ▫ IT security professionals&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160; ▫ IT security professionals&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;▫ Security auditors&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160; &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;'''Skills Learned'''&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Upon completion of the course, students will have gained knowledge in the fundamentals of investigating a system in it’s running state to include...&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt; ▫ Forensic network discovery&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt; ▫ Evidence collection process&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt; ▫ Acquisition of volatile data&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt; ▫ Automated audit trail&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt; ▫ Forensic reporting&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Our trainers take you inside the minds of today’s criminals and students completeing the class will be able to execute a full investigation in the respective discipline. Participants proficiency in the above skills will be tested with certification exams.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Our trainers take you inside the minds of today’s criminals and students completeing the class will be able to execute a full investigation in the respective discipline. Participants proficiency in the above skills will be tested with certification exams.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Kskinner</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;diff=8204&amp;oldid=prev</id>
		<title>Kskinner: New page: '''Live Investigator Training''' [https://www.wetstonetech.com/cgi/shop.cgi?view,7]   ==   ==  Live Investigator Training is designed to teach students the techniques for acquiring digital...</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Advanced_Steganography_Demystifying_Steganography_Investigation&amp;diff=8204&amp;oldid=prev"/>
				<updated>2008-06-13T14:54:53Z</updated>
		
		<summary type="html">&lt;p&gt;New page: &amp;#039;&amp;#039;&amp;#039;Live Investigator Training&amp;#039;&amp;#039;&amp;#039; [https://www.wetstonetech.com/cgi/shop.cgi?view,7]   ==   ==  Live Investigator Training is designed to teach students the techniques for acquiring digital...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;'''Live Investigator Training''' [https://www.wetstonetech.com/cgi/shop.cgi?view,7]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==   ==&lt;br /&gt;
&lt;br /&gt;
Live Investigator Training is designed to teach students the techniques for acquiring digital evidence from a running suspect’s system in an overt or covert manner. This includes acquiring running process state, open handles, process/port associations, system logs, installed devices, physical and logical drives, network statistics and configuration, user accounts and logged in users.  Class participants will also learn how to acquire volatile memory and/or registry snapshots from the target host. This could include recently used applications and documents, recently visited web sites, chat logs and e-mails. Physical RAM capture may contain vital password and account information, remnants of visited web sites, recent messages, phone numbers, e-mail addresses and chat identities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why Live Investigation?'''&lt;br /&gt;
&lt;br /&gt;
As many corporation’s networks are becoming large and often geographically divers, it is imperative to practice a live investigation technique. LiveWire Investigator™ and it’s associated software bundle provides the capability of collecting and analyzing comprehensive information regarding evidence contained on ‘live-running’ devices.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Who Should Attend?'''&lt;br /&gt;
&lt;br /&gt;
 ▫ Forensic Investigators&lt;br /&gt;
 ▫ Local, state and federal law enforcement&lt;br /&gt;
 ▫ Private investigators&lt;br /&gt;
 ▫ IT security professionals&lt;br /&gt;
 ▫ Security auditors&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Skills Learned'''&lt;br /&gt;
&lt;br /&gt;
Upon completion of the course, students will have gained knowledge in the fundamentals of investigating a system in it’s running state to include...&lt;br /&gt;
&lt;br /&gt;
 ▫ Forensic network discovery&lt;br /&gt;
 ▫ Evidence collection process&lt;br /&gt;
 ▫ Acquisition of volatile data&lt;br /&gt;
 ▫ Automated audit trail&lt;br /&gt;
 ▫ Forensic reporting&lt;br /&gt;
&lt;br /&gt;
Our trainers take you inside the minds of today’s criminals and students completeing the class will be able to execute a full investigation in the respective discipline. Participants proficiency in the above skills will be tested with certification exams.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
'''Contact Information:'''&lt;br /&gt;
&lt;br /&gt;
1-877-WETSTONE ext 2&lt;br /&gt;
&lt;br /&gt;
www.wetstonetech.com [https://www.wetstonetech.com/index.html]&lt;/div&gt;</summary>
		<author><name>Kskinner</name></author>	</entry>

	</feed>