Handling BitLocker and FileVault 2: Evimetry and Mount Image Pro | Cybrary


Handling BitLocker and FileVault 2: Evimetry and Mount Image Pro | Cybrary
English | Size: 242.26 MB
Genre: eLearning

Course Description
During the course we will collect a FileVault 2 encrypted MacBook Air in minutes without breaking a sweat using Evimetry. Once we have a series of fully encrypted forensic images will use GetData Mount Image Pro to decrypt our forensic images and make the data available for further forensic analysis.

Prerequisites
Before any forensic acquisition you must document the evidence
See my Cybrary course: “Evidence Handling: Do it the Right Way”
See my Cybrary course: “Basic Evimetry Deadboot Forensic Acquisition: Wired & Local”
A full-featured, evaluation copy of Evimetry
An evaluation copy of Mount Image Pro
Internet connected computer
An encrypted Mac computer
A USB thumbdrive for dead booting
A storage drive (USB3 External)
Course Goals
By the end of this course, students should be able to:

How to identify a BitLocker’d or FileVault’d disk by signature
Acquire a FileVault’d Mac with Evimetry
Use Mount Image Pro to decrypt Windows and Mac encrypted volumes

nitroflare.com/view/1A0486C62BF08E3/CBR44997.20.7.part1.rar
nitroflare.com/view/38FE1733568495E/CBR44997.20.7.part2.rar

rapidgator.net/file/984f14cf9c03ab43bc78acdb2f17c326/CBR44997.20.7.part1.rar.html
rapidgator.net/file/36d29f2050f6f98515a59e37307bd396/CBR44997.20.7.part2.rar.html

If any links die or problem unrar, send request to
forms.gle/e557HbjJ5vatekDV9

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.