Difference between pages "Global Positioning System" and "Training Courses and Providers"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
(Forensics)
 
(On-going / Continuous Training)
 
Line 1: Line 1:
The '''Global Positioning System''' ('''GPS''') is a satellite navigation system.
+
This is the list of Training Providers, who offer training courses of interest to practitioners and researchers in the field of Digital Forensics.   Conferences which may include training are located on the [[Upcoming_events]] page. 
  
== Forensics ==
+
<b>PLEASE READ BEFORE YOU EDIT THE LIST BELOW</b><br>
 +
Some training providers offer on-going training courses that are available in an on-line "any time" format. Others have regularly scheduled training that is the same time each month.  Others have recurring training but are scheduled at various times throughout the year. Providers training courses should be listed in alphabetical order, and should be listed in the appropriate section.  Non-Commercial training is typically offered by governmental agencies or organizations that directly support law enforcement.  Tool Vendor training is training offered directly by a specific tool vendor, which may apply broadly, but generally is oriented to the vendor's specific tool (or tool suite).  Commercial Training is training offered by commercial companies which may or may not be oriented to a specific tool/tool suite, but is offered by a company other than a tool vendor.
  
There are several places where GPS information can found. It can be very useful for forensic investigations in certain situations. GPS devices have expanded their capabilities and features as the technology has improved. Some of the most popular GPS devices today are made by [http://www.TomTom.com TomTom]. Some of the other GPS manufacturers include [http://www.garmin.com Garmin] and [http://www.magellangps.com Magellan].
+
<i>Some training opportunities may be <u>limited</u> to <b>Law Enforcement Only</b> or to a specific audience. Such restrictions should be noted when known.</i>
 +
== On-going / Continuous Training ==
 +
{| border="0" cellpadding="2" cellspacing="2" align="top"
 +
|- style="background:#bfbfbf; font-weight: bold"
 +
! width="40%"|Title
 +
! width="20%"|Date/Location
 +
! width="40%"|Website
 +
|-
 +
|- style="background:pink;align:left"
 +
! DISTANCE LEARNING
 +
|-
 +
|Basic Computer Examiner Course - Computer Forensic Training Online
 +
|Distance Learning Format
 +
|http://www.cftco.com
 +
|-
 +
|SANS On-Demand Training
 +
|Distance Learning Format
 +
|http://www.sans.org/ondemand/?portal=69456f95660ade45be29c00b0c14aea1
 +
|-
 +
|Champlain College - CCE Course
 +
|Online / Distance Learning Format
 +
|http://online.champlain.edu/computer-forensics-digital-investigation/CFDI_440
 +
|-
 +
|National Center for Media Forensics
 +
|Distance and Concentrated Audio/Video/Image Forensics
 +
|http://cam.ucdenver.edu/ncmf
 +
|-
 +
|- style="background:pink;align:left"
 +
!RECURRING TRAINING
 +
|-
 +
|Evidence Recovery for Windows 7&reg; operating system;
 +
|First full week every month<br>Brunswick, GA
 +
|http://www.internetcrimes.net
 +
|-
 +
|Evidence Recovery for Windows 8&reg;
 +
|Second full week every month<br>Brunswick, GA
 +
|http://www.internetcrimes.net
 +
|-
 +
|Evidence Recovery for Windows Server&reg; 2008 and 2012
 +
|Third full week every month<br>Brunswick, GA
 +
|http://www.internetcrimes.net
 +
|-
 +
|}
  
[[File:http://directhitinc.com/Images/Blackthorn.gif]]
+
==Non-Commercial Training==
Berla Corp. Has has released a BETA version of their new GPS forensics tool. It integrates acquisition, examination, and analysis into one small easy to use piece of software. [http://blackthorngps.com Get your free copy today]. Blackthorn currently supports both legacy and current Garmin, TomTom, and Magellan devices.
+
{| border="0" cellpadding="2" cellspacing="2" align="top"
 +
|- style="background:#bfbfbf; font-weight: bold"
 +
! width="40%"|Title
 +
! width="40%"|Website
 +
! width="20%"|Limitation
 +
|-
 +
|Defense Cyber Investigations Training Academy (DCITA)
 +
|http://www.dc3.mil/dcita/dcitaAbout.php
 +
|Limited To Certain Roles within US Government Agencies[http://www.dc3.mil/dcita/dcitaRegistration.php (1)]
 +
|-
 +
|Federal Law Enforcement Training Center
 +
|http://www.fletc.gov/training/programs/technical-operations-division
 +
|Limited To Law Enforcement
 +
|-
 +
|MSU National Forensics Training Center
 +
|http://www.security.cse.msstate.edu/ftc
 +
|Limited To Law Enforcement
 +
|-
 +
|IACIS
 +
|http://www.iacis.com/training/course_listings
 +
|Limited To Law Enforcement and Affiliate Members of IACIS
 +
|-
 +
|SEARCH
 +
|http://www.search.org/programs/hightech/courses/
 +
|Limited To Law Enforcement
 +
|-
 +
|National White Collar Crime Center
 +
|http://www.nw3c.org/training
 +
|Limited To Law Enforcement
 +
|-
 +
|}
  
=== TomTom ===
+
==Tool Vendor Training==
 +
{| border="0" cellpadding="2" cellspacing="2" align="top"
 +
|- style="background:#bfbfbf; font-weight: bold"
 +
! width="40%"|Title
 +
! width="40%"|Website
 +
! width="20%"|Limitation
 +
|-
 +
|AccessData (Forensic Tool Kit FTK)
 +
|http://accessdata.com/training
 +
|-
 +
|ASR Data (SMART)
 +
|http://www.asrdata.com/forensic-training/overview/
 +
|-
 +
|ATC-NY (P2P Marshal, Mac Marshal)
 +
|http://p2pmarshal.atc-nycorp.com/index.php/training http://macmarshal.atc-nycorp.com/index.php/training
 +
|-
 +
|BlackBag Technologies (Mac Forensic Tools- BlackLight and SoftBlock)
 +
|https://www.blackbagtech.com/training.html
 +
|-
 +
|Cellebrite (UFED)
 +
|http://www.cellebrite.com/mobile-forensic-training.html
 +
|-
 +
|CPR Tools (Data Recovery)
 +
|http://www.cprtools.net/training.php
 +
|-
 +
|Digital Intelligence (FRED Forensics Platform)
 +
|http://www.digitalintelligence.com/forensictraining.php
 +
|-
 +
|e-fense, Inc. (Helix3 Pro)
 +
|http://www.e-fense.com/training/index.php
 +
|-
 +
|Forward Discovery (Cellebrite, EnCase, Mac Forensics)
 +
|http://www.forwarddiscovery.com/training
 +
|-
 +
|Guidance Software (EnCase)
 +
|http://www.guidancesoftware.com/computer-forensics-training-courses.htm
 +
|-
 +
|Micro Systemation (XRY)
 +
|http://www.msab.com/training/schedule
 +
|-
 +
|Nuix (eDiscovery)
 +
|http://www.nuix.com.au/training
 +
|-
 +
|Paraben (Paraben Suite)
 +
|http://www.paraben-training.com/schedule.html
 +
|-
 +
|Software Analysis & Forensic Engineering (CodeSuite)
 +
|http://www.safe-corp.biz/training.htm
 +
|-
 +
|Technology Pathways(ProDiscover)
 +
|http://www.techpathways.com/DesktopDefault.aspx?tabindex=6&tabid=9
 +
|-
 +
|Volatility Labs (Volatility Framework)
 +
|http://volatility-labs.blogspot.com/search/label/training
 +
|-
 +
|WetStone Technologies (Gargoyle, Stego Suite, LiveWire Investigator)
 +
|https://www.wetstonetech.com/trainings.html
 +
|-
 +
|X-Ways Forensics (X-Ways Forensics)
 +
|http://www.x-ways.net/training/
 +
|-
 +
|}
  
TomTom provides a wide range of devices for biking, hiking, and car navigation. Depending on the capabilities of the model, several different types of digital evidence can be located on these devices. For instance, the [http://www.tomtom.com/products/product.php?ID=212&Category=0&Lid=1 TomTom 910] is basically a 20GB external harddrive. This model can be docked with a personal computer via a USB cable or through the use of Bluetooth technology. The listed features include the ability to store pictures, play MP3 music files, and connect to certain cell phones via bluetooth technology. Data commonly found on cell phones could easily be found on the TomTom910. Via the Bluetooth, the TomTom can transfer the entire contact list from your phone. The GPS unit also records your call logs and SMS messages. Research needs to be done to see if the TomTom stores actual trips conducted with the unit. This would include routes, times, and travel speeds.
+
==Commercial Training (Non-Tool Vendor)==
 
+
{| border="0" cellpadding="2" cellspacing="2" align="top"
The TomTom unit connects to a computer via a USB base station. An examiner should be able to acquire the image of the harddrive through a USB write blocker. If not, it may be necessary to remove the hard drive from the unit.  
+
|- style="background:#bfbfbf; font-weight: bold"
 
+
! width="40%"|Title
TomTom models such the TomTom One Regional, TomTom Europe, Go 510, Go 710 and the Go 720 store map data, favourites, and recent destinations on a removable SD card.  This allows the forensic examiner to remove the SD card and make a backup with a write blocked SD card reader.  The most important file for the forensic examiner will be the CFG file that is held in the map data directory.  This holds a list of all recent destinations that the user has entered into the device.  The information is held in a hex file and stores the grid coordinates of these locations. 
+
! width="40%"|Website
 
+
! width="20%"|Limitation
Certain TomTom models (Go 510, Go 910, Go 920 etc.) allow the user to pair their mobile phone to the device so they can use the TomTom as a hands free kit.  If the user has paired their phone to the TomTom device, then the TomTom will store the Bluetooth MAC ID for up to five phones, erasing the oldest if a sixth phone is paired.  Depending on the phone model paired with the TomTom, there may also be Call lists, contacts and text messages (sent & received) stored in the device too.
+
|-
 
+
|Applied Security (Digital Forensics Training)
Automated forensic analysis for TomTom GPS units is possible with software from Digivence - Forensic Analyser - TomTom Edition.  [http://www.digivence.com/SCREEN%20OPTIMISED%20REPORT%20-%20Demo%2011072007%20163219.htm Sample Report].  Whilst not shown in the example report, call history, contacts, text messages, Bluetooth MAC ID, and unit info is also automatically processed if available.
+
|http://www.appliedsec.com/forensics/training.html
 
+
|-
Another tool for forensically analysing TomToms is [http://www.forensicnavigation.com TomTology]. This will retrieve all journey details from both live and unallocated space. It will tell you which is the home, favourites and recent destinations and will also tell you the last journey that was plotted and where the TomTom last had a GPS fix. It will also extract phone numbers if the device has been paired with a phone and will find deleted phone numbers, useful for potentially tracing a previous owner.
+
|BerlaCorp iOS and GPS Forensics Training
 
+
|http://www.berlacorp.com/training.html
=== Garmin ===
+
|-
 
+
|Computer Forensic Training Center Online (CFTCO)
Garmin units connect to a PC in the same way as TomTom, via a USB cable. The unit will mount as a Mass Storage Unit, similar to a USB Memory Stick. After drivers for the unit have loaded, it is possible to navigate the Garmin unit's file system. Many of the files inside can easily be opened in a text or Hex editor.  
+
|http://www.cftco.com/
 
+
|-
Raw trip data including waypoints, date & time stamps, latitude & longitude coordinates and elevations can be extracted from the Current.gpx file located in the \Garmin\GPX\ folder. It can be viewed by opening the file with a text editor such as [http://notepad-plus.sourceforge.net/ Notepad++]. All recent trips are stored in this file.
+
|CCE Bootcamp
 
+
|http://www.cce-bootcamp.com/
Data can also be easily viewed via [http://earth.google.com/ Google Earth]'s import feature. If available, Google Earth will import waypoints, tracks and routes from the unit. A slider bar in the program will show saved routes by date and time. When a specific waypoint is selected, a window will open that shows Lat/Long Coordinates, Altitude, Speed, Heading and Date/Time (Zulu).  
+
|-
 
+
|Cyber Security Academy
With this data, raw or when viewed in Google Earth, entire trips can easily be reproduced giving exact time and locations for the GPS unit. It is unknown how many trips the unit is capable of storing or will store by default, but the [https://buy.garmin.com/shop/shop.do?pID=37418#nuvi260w Garmin Nuvi 260W] test unit had 16 days of trip data stored to memory.  
+
|http://www.cybersecurityacademy.com/
 
+
|-
=== Magellan ===
+
|Dera Forensics Group
 
+
|http://www.deraforensicgroup.com/courses.htm
Magellan GPS units also connect to a PC via a USB cable. The [http://www.magellangps.com/products/product.asp?segID=354&prodID=2053 Magellan Roadmate 1400] unit tested runs a version of Windows CE. The operating system did not appear to be tailored to the specific unit and had options included in the menus that were not available (e.g. backup and restore functionality via a SD memory card slot that did not exist). Upon connecting the unit to a PC, it will mount as a Mass Storage Unit when and if it is recognized. 
+
|-
 
+
|e-fense Training
Files that may contain useful information when opened in a text editor:
+
|http://www.e-fense.com/training/index.php
* /App/Unit.xml
+
|-
** This file contains information about the unit such as Model and Serial number.
+
|Forward Discovery, Inc.
* /App/Media.cfg
+
|http://www.forwarddiscovery.com
** This file is a short list of what types of files are stored in the file structure. (e.g. User data is stored in /USR)
+
|-
* /Sys/USBTRANS/Unit_ID.dat
+
|H-11 Digital Forensics
** This file is similar to Unit.xml. It contains more information such as Operating System Version and Firmware version.
+
|http://www.h11-digital-forensics.com/training/viewclasses.php
* /USR/TGUSERA.dat
+
|-
** This file may contain addresses, phone numbers and some user set points such as "Home". There is no recognizable structure to this data so finding useful data is difficult.
+
|High Tech Crime Institute
* /USR/CITYHIST.dat
+
|http://www.gohtci.com
** This file may contain cities entered into the unit by a user. Like TGUSERA.dat, there is little structure here. Unfortunately, only City and State may be listed here.
+
|-
 
+
|Infosec Institute
Magellan provides [http://www.magellangps.com/products/map.asp?PRODID=1903 VantagePoint] software to view map and waypoint data. In order to use this software, the Magellan unit must be powered on prior to connecting it to a PC. It is unknown how useful the VantagePoint software is in collecting data as the software would not recognize the Roadmate 1400 unit. VantagePoint also did not support the .dat or .cfg files stored on the unit. [http://earth.google.com/ Google Earth] also supports Magellan units via its import feature. Earth lists Explorist and Serial as available import options.
+
|http://www.infosecinstitute.com/courses/security_training_courses.html
+
|-
 
+
|Intense School (a subsidiary of Infosec Institute)
=== Digital Camera Images with GPS Information ===
+
|http://www.intenseschool.com/schedules
 
+
|-
Some recent digital cameras have built-in GPS receivers (or external modules you can connect to the camera). This makes it possible for the camera to record where exactly a photo was taken. This positioning information (latitude, longitude) can be stored in the [[Exif]] [[metadata]] header of [[JPEG]] files. Tools such as [[jhead]] can display the GPS information in the [[Exif]] headers.
+
|MD5 Group (Computer Forensics and E-Discovery courses)(Dallas, TX)
 
+
|http://www.md5group.com
=== Cell Phones with GPS ===
+
|-
 
+
|Mile 2 (Security and Forensics Certification Training)
Some recent cell phones (e.g. a [http://wiki.openezx.org Motorola EZX phone] such as the Motorola A780) have a built-in GPS receiver and navigation software. This software might record the paths travelled (and the date/time), which can be very useful in forensic investigations.
+
|https://www.mile2.com/mile2-online-estore/classess.html
 
+
|-
== External Links ==
+
|Mobile Forensics, Inc
 
+
|http://mobileforensicsinc.com/
* [http://www.gpsforensics.org GPSForensics.org - A communitiy dedicated to GPS device forensics]
+
|-
 
+
|NetSecurity
* [http://en.wikipedia.org/wiki/Global_Positioning_System Wikipedia: GPS]
+
|http://www.netsecurity.com/training/registration_schedule.html
 
+
|-
* [http://www.digivence.com Digivence: TomTom Forensic Analyser]
+
|NID Forensics Academy (Certified Digital Forensic Investigator - CDFI Program)
 
+
|http://www.nidforensics.com.br/
* [http://www.paraben-forensics.com/catalog/product_info.php?cPath=25&products_id=405 Paraben's Device Seizure]
+
|-
 
+
|NTI (an Armor Forensics Company) APPEARS DEFUNCT
* [http://www.forensicnavigation.com TomTology by Forensic Navigation]
+
|http://www.forensics-intl.com/training.html
 
+
|-
* [http://www.blackthorngps.com Blackthorn | GPS Forensics]
+
|Security University
 +
|http://www.securityuniversity.net/classes.php
 +
|-
 +
|Steganography Analysis and Research Center (SARC)
 +
|http://www.sarc-wv.com/training
 +
|-
 +
|Sumuri, LLC - Mac, Mobile, iLook Training
 +
|http://www.sumuri.com/
 +
|-
 +
|SysAdmin, Audit, Network, Security Institute (SANS)
 +
|http://computer-forensics.sans.org/courses/
 +
|-
 +
|Teel Technologies Mobile Device Forensics Training
 +
|http://www.teeltech.com/tt3/training.asp
 +
|-
 +
|viaForensics Advanced Mobile Forensics Training
 +
|http://viaforensics.com/education/calendar/
 +
|-
 +
|Zeidman Consulting (MCLE)
 +
|http://www.zeidmanconsulting.com/speaking.htm
 +
|-
 +
|}

Revision as of 14:25, 13 June 2014

This is the list of Training Providers, who offer training courses of interest to practitioners and researchers in the field of Digital Forensics. Conferences which may include training are located on the Upcoming_events page.

PLEASE READ BEFORE YOU EDIT THE LIST BELOW
Some training providers offer on-going training courses that are available in an on-line "any time" format. Others have regularly scheduled training that is the same time each month. Others have recurring training but are scheduled at various times throughout the year. Providers training courses should be listed in alphabetical order, and should be listed in the appropriate section. Non-Commercial training is typically offered by governmental agencies or organizations that directly support law enforcement. Tool Vendor training is training offered directly by a specific tool vendor, which may apply broadly, but generally is oriented to the vendor's specific tool (or tool suite). Commercial Training is training offered by commercial companies which may or may not be oriented to a specific tool/tool suite, but is offered by a company other than a tool vendor.

Some training opportunities may be limited to Law Enforcement Only or to a specific audience. Such restrictions should be noted when known.

On-going / Continuous Training

Title Date/Location Website
DISTANCE LEARNING
Basic Computer Examiner Course - Computer Forensic Training Online Distance Learning Format http://www.cftco.com
SANS On-Demand Training Distance Learning Format http://www.sans.org/ondemand/?portal=69456f95660ade45be29c00b0c14aea1
Champlain College - CCE Course Online / Distance Learning Format http://online.champlain.edu/computer-forensics-digital-investigation/CFDI_440
National Center for Media Forensics Distance and Concentrated Audio/Video/Image Forensics http://cam.ucdenver.edu/ncmf
RECURRING TRAINING
Evidence Recovery for Windows 7® operating system; First full week every month
Brunswick, GA
http://www.internetcrimes.net
Evidence Recovery for Windows 8® Second full week every month
Brunswick, GA
http://www.internetcrimes.net
Evidence Recovery for Windows Server® 2008 and 2012 Third full week every month
Brunswick, GA
http://www.internetcrimes.net

Non-Commercial Training

Title Website Limitation
Defense Cyber Investigations Training Academy (DCITA) http://www.dc3.mil/dcita/dcitaAbout.php Limited To Certain Roles within US Government Agencies(1)
Federal Law Enforcement Training Center http://www.fletc.gov/training/programs/technical-operations-division Limited To Law Enforcement
MSU National Forensics Training Center http://www.security.cse.msstate.edu/ftc Limited To Law Enforcement
IACIS http://www.iacis.com/training/course_listings Limited To Law Enforcement and Affiliate Members of IACIS
SEARCH http://www.search.org/programs/hightech/courses/ Limited To Law Enforcement
National White Collar Crime Center http://www.nw3c.org/training Limited To Law Enforcement

Tool Vendor Training

Title Website Limitation
AccessData (Forensic Tool Kit FTK) http://accessdata.com/training
ASR Data (SMART) http://www.asrdata.com/forensic-training/overview/
ATC-NY (P2P Marshal, Mac Marshal) http://p2pmarshal.atc-nycorp.com/index.php/training http://macmarshal.atc-nycorp.com/index.php/training
BlackBag Technologies (Mac Forensic Tools- BlackLight and SoftBlock) https://www.blackbagtech.com/training.html
Cellebrite (UFED) http://www.cellebrite.com/mobile-forensic-training.html
CPR Tools (Data Recovery) http://www.cprtools.net/training.php
Digital Intelligence (FRED Forensics Platform) http://www.digitalintelligence.com/forensictraining.php
e-fense, Inc. (Helix3 Pro) http://www.e-fense.com/training/index.php
Forward Discovery (Cellebrite, EnCase, Mac Forensics) http://www.forwarddiscovery.com/training
Guidance Software (EnCase) http://www.guidancesoftware.com/computer-forensics-training-courses.htm
Micro Systemation (XRY) http://www.msab.com/training/schedule
Nuix (eDiscovery) http://www.nuix.com.au/training
Paraben (Paraben Suite) http://www.paraben-training.com/schedule.html
Software Analysis & Forensic Engineering (CodeSuite) http://www.safe-corp.biz/training.htm
Technology Pathways(ProDiscover) http://www.techpathways.com/DesktopDefault.aspx?tabindex=6&tabid=9
Volatility Labs (Volatility Framework) http://volatility-labs.blogspot.com/search/label/training
WetStone Technologies (Gargoyle, Stego Suite, LiveWire Investigator) https://www.wetstonetech.com/trainings.html
X-Ways Forensics (X-Ways Forensics) http://www.x-ways.net/training/

Commercial Training (Non-Tool Vendor)

Title Website Limitation
Applied Security (Digital Forensics Training) http://www.appliedsec.com/forensics/training.html
BerlaCorp iOS and GPS Forensics Training http://www.berlacorp.com/training.html
Computer Forensic Training Center Online (CFTCO) http://www.cftco.com/
CCE Bootcamp http://www.cce-bootcamp.com/
Cyber Security Academy http://www.cybersecurityacademy.com/
Dera Forensics Group http://www.deraforensicgroup.com/courses.htm
e-fense Training http://www.e-fense.com/training/index.php
Forward Discovery, Inc. http://www.forwarddiscovery.com
H-11 Digital Forensics http://www.h11-digital-forensics.com/training/viewclasses.php
High Tech Crime Institute http://www.gohtci.com
Infosec Institute http://www.infosecinstitute.com/courses/security_training_courses.html
Intense School (a subsidiary of Infosec Institute) http://www.intenseschool.com/schedules
MD5 Group (Computer Forensics and E-Discovery courses)(Dallas, TX) http://www.md5group.com
Mile 2 (Security and Forensics Certification Training) https://www.mile2.com/mile2-online-estore/classess.html
Mobile Forensics, Inc http://mobileforensicsinc.com/
NetSecurity http://www.netsecurity.com/training/registration_schedule.html
NID Forensics Academy (Certified Digital Forensic Investigator - CDFI Program) http://www.nidforensics.com.br/
NTI (an Armor Forensics Company) APPEARS DEFUNCT http://www.forensics-intl.com/training.html
Security University http://www.securityuniversity.net/classes.php
Steganography Analysis and Research Center (SARC) http://www.sarc-wv.com/training
Sumuri, LLC - Mac, Mobile, iLook Training http://www.sumuri.com/
SysAdmin, Audit, Network, Security Institute (SANS) http://computer-forensics.sans.org/courses/
Teel Technologies Mobile Device Forensics Training http://www.teeltech.com/tt3/training.asp
viaForensics Advanced Mobile Forensics Training http://viaforensics.com/education/calendar/
Zeidman Consulting (MCLE) http://www.zeidmanconsulting.com/speaking.htm