Professional Development

Learning Computer Security Investigation and Response

A practical introduction to computer-security investigation and incident response, including forensic frameworks, evidence handling, incident-scene preservation, evidence collection and recovery, and differences in examining Windows, macOS and Linux systems.

Provider LinkedIn Learning
Instructor Sandra Toner
Completed December 29, 2017
Duration 1 hour 57 minutes
Certificate of completion for Learning Computer Security Investigation and Response
Certificate ID: AZBRWe2ruvSAlq0IVjiGiAIHYamP
View original PDF ↗

Context

Why I took this course

By the time I completed this course, I had already been doing data-recovery and evidence-sensitive investigative work for years. I took it as a structured refresher—a way to compare practices learned on the job with the investigation and response methods being taught at the time.

Takeaways

What I took away from it

  • Incident response and evidence collection have to protect the integrity of the source material, not merely recover useful data.
  • A disciplined process matters as much as the tools: preserve, collect, examine, document and report in a way another person can understand.
  • The operating system and storage environment affect how evidence is collected and interpreted, so there is no single workflow that fits every case.

Experience

How it connects to my work

My recovery work has included deliberately deleted data, hidden or deleted partitions, failed storage devices and evidence-sensitive engagements where the original media needed to remain untouched whenever possible.

Where practical, I worked from a clone rather than booting the source drive, recovered material to separate media, and documented findings for clients, private investigators or law-enforcement use as appropriate.

Contact

Have a technology problem or opportunity worth discussing?

I’m always interested in worthwhile technical problems, projects, leadership roles and collaborations where broad hands-on experience can be useful.