All right. Welcome to handling bit. Locker and fire. All file vault to encrypted drives with elementary and mount image Pro. That's gonna be a lot of fun.
All right. I'm Brian Dykes from the CEO of Atlantic Data Forensics. Part of that was a co founder and Mandiant for that big monster.
Part of that content was a contract cybercrime instructor at the FBI academy in Quantico. Military intelligence background, whole bunch of certifications. Things like that.
Uh, and if you have any questions about this course of any of my other courses, you can reach out to me at Sai Buri at Atlantic D f dot com and I will actually email you back.
All right, so Atlantic Data Forensics. We were founded in 2007. We just celebrated our 14th birthday. Which kind of cool? We're headquartered in Elkridge, Maryland. We do computer forensics for civil and criminal litigation. We do e discovery for big law firm cases.
We do 24 7 incident response for clients all over the U. S. And some
some in Europe. In Asia,
we also do a lot of internal corporate HR investigations, employment, work, things like that. Ah, and instant response, training and exercises for our clients out there. We have offices in Denver and Detroit besides here in Maryland.
All right, let's get right into this. So prerequisites for this course, and pretty much all the other courses on forensic acquisition is you have to document the evidence, and I have heard me say this over and over and over. But it's super important. You gotta document the evidence first and then start doing the breakdown in the technical acquisition, things like that.
If questions about how to do that best see my
cyber recourse, evidence handling, doing it the right way, I explain all that break down the fields and you know what you should be capturing and all that sort of stuff.
and then also because we're going to be doing some dead boot acquisition here with ever mattress should probably take a look at my basic, ever metric dead brute forensic acquisition. Wired and local were actually to be doing a actually doing a combo today. A wired to local. That's kind of weird. Um
on Do you need a full evil copy of ever Metro? If you want to play along in the Home Edition. You get that from my elementary dot com, and there's an enquiry. Evil
there and there. Go ahead and give you a fully featured 30 day license, which is kind of cool. I like it when they don't cut out features.
If you have any questions about how the A f f for format, the advanced follow format four there were a forensic file format for that we're using here works. There's also document. They're called FF for public, where Dr Shatz explains in
aggressive detail all the all the ins and outs of that, it's actually worth worth reading. It's good to understand the format that you're putting your forensic images into
next up course materials that you're going to need for this until net connected computer Always handy. Gonna need that evil copy of ever Met Really said, If you just playing along on your own, you wanna start and stop this. Ah, you're gonna need an evil copy of Mount Image Pro. Ah, that's available from get data dot com,
you're gonna need these 7.1 or better addition of that in order to do what we're doing. The slightly older editions they available 65 or something like that.
I don't support FF four. So you don't want that?
Um, I'm you were gonna go ahead and ah, image a fully encrypted Mac computer today. So, you know, if your plan along fully, you don't wanna want a foul ball to encrypted, Mac. Ah, then I USB thumb drive for dead booting elementary. And, of course, you need a stories drive to drop all that
so kind of a laundry list of things today. If you're doing all this stuff with me
Target audience, always. Computer forensics professionals love you. There, my people. Ah, incident responders. He end up doing a lot of the same thing is lots of love for you to, and I t guys, I feel bad for you, but I know you'll get pulled into having to do some of this at the same time. So here's Here's all the tricks and tools to keep yourself on the on the right side of doing it.
All right, are learning objectives. First, we're talking about how to identify a bit. Locher file vaulted. I know that's how you spell that, but I like to use it with a possibly de, um, file vaulted despite signature. Then we're actually going to go ahead, acquire a file vaulted Mac with every metric gonna see That's fast. Easy. Simple. No, no fancy tools required.
And then we're gonna learn how to use Mount Image Pro to decrypt
Windows and Mac encrypted volumes from our forensics images After the facts, which is just a huge benefit. You run into stuff all the time. So in the elementary stack today of things were going to use, we're definitely gonna use that every metric controller up there at the top.
We're going to use the dead boot agent on your far left hand side there.
Um, and then we're just gonna dump that into a standard FF four image container. There the bottom. So, Toby, be fully encrypted, but we're gonna make it useful to us.