Professional Development

Learning Computer Forensics

A foundation in computer forensics covering the purpose and scope of forensic investigations, legal and procedural considerations, evidence acquisition, specialized areas such as network and operating-system forensics, analysis, searching and reporting.

Provider LinkedIn Learning
Instructor Jungwoo Ryoo
Completed December 22, 2017
Duration 1 hour 57 minutes
Certificate of completion for Learning Computer Forensics
Certificate ID: Ab-GUHrn7K6SgGIjXwqdrImMg7m3
View original PDF ↗

Context

Why I took this course

I had already handled many real data-recovery and investigative matters before taking this course. I wanted a concise refresher on the broader forensic discipline around the hands-on recovery work: acquisition, analysis, legal context and reporting, not simply whether a deleted file could be recovered.

Takeaways

What I took away from it

  • Digital forensics is broader than data recovery; acquisition, context, analysis and reporting determine whether recovered material is useful and defensible.
  • Evidence handling should separate the source, the working copy and the recovered output whenever the circumstances allow it.
  • Different evidence sources call for different techniques, but the need for repeatability and clear documentation remains consistent.

Experience

How it connects to my work

My hands-on recovery work has included hard drives, SSDs, SD cards and USB flash media, with cases ranging from accidental deletion and hardware failure to confidential investigative matters.

In evidence-sensitive cases, the objective was not just to recover files but to preserve the original source, work from a controlled copy where possible and produce findings that could support a larger investigation.

Contact

Have a technology problem or opportunity worth discussing?

I’m always interested in worthwhile technical problems, projects, leadership roles and collaborations where broad hands-on experience can be useful.