Counter hack: Creating a context for a cyber forensics course
Lori L. DeLooze · 2008
A typical hacker follows the ldquohacker methodologyrdquo by going through the following distinct phases: Footprinting, Probing, Gaining Access, Escalating Privileges, Exploiting, Covering Tracks and Installing Backdoors. This hacker methodology is used to direct the overall forensic process. Many of these phases leave artifacts that can be examined by a forensic investigator to piece together an incident. We designed a cyber forensic course that begins with a background of computer media and file systems, and then looks at static files, network logs and volatile system data. Students who understand how a typical hacker operates will be able to discover appropriate clues, and may even be able to prevent future destruction or disruption.