Post-mortem analysis (also known as inforensic) of IT security incidents has become essential for preserving evidence. Following simulated attacks, you will learn how to collect and preserve evidence, analyze it and improve IS security after the intrusion.
INTER
IN-HOUSE
CUSTOM
Practical course in person or remote class
Disponible en anglais, à la demande
Post-mortem analysis (also known as inforensic) of IT security incidents has become essential for preserving evidence. Following simulated attacks, you will learn how to collect and preserve evidence, analyze it and improve IS security after the intrusion.
At the end of the training, the participant will be able to:
Master the right reflexes in the event of machine intrusion
Collect and preserve the integrity of electronic evidence
Analyze intrusion a posteriori
Intended audience
Systems and network engineer/administrator.
Prerequisites
Good knowledge of IT security and networks/systems. Must have taken the course "Collecting and analyzing logs, optimizing your IS security".
Course schedule
1
How do you manage an incident?
Signs of successful IS intrusion.
What have the hackers achieved? How far did they get?
How do you react to a successful intrusion?
Which servers are affected?
Find the entry point and fill it.
The Unix/Windows toolbox for evidence retrieval.
Clean-up and return compromised servers to production.
2
Analyze incidents for better protection: Forensic analysis
Computer forensics: types of computer crime, role of the computer investigator.
Modern cybercrime.
Digital proof.
3
Forensic analysis of a Windows operating system
Acquisition, analysis and response.
Understanding start-up processes.
Collect volatile and non-volatile data.
How the password system and Windows registry work.
Analysis of data contained in RAM and Windows files.
Cache analysis, cookie and browsing history, event history.
Hands-on work
User injection. Break password. Collect, analyze RAM data. Reference and hash all files. Explore browser and registry data.
Customer reviews
4,7 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
SEBASTIEN A.
08/06/26
4 / 5
Nothing to report
RENAUD L.
28/01/26
5 / 5
Appropriate content and highly competent trainer
JEAN-FRANÇOIS G.
28/01/26
5 / 5
very interesting, thank you to the trainer for this dive into forensic science
DJELLAL H.
15/12/25
5 / 5
Very satisfied
XAVIER N.
15/12/25
5 / 5
The teaching content is wonderfully well organised, with each practical lesson being a practical application of the lecture given by Yoann Bertrand. The content is also supplemented by additional documents to stimulate our intellectual curiosity. A very sincere thank you to our passionate teacher!
JOEL S.
15/12/25
5 / 5
The trainer is clear and the tp's are very concrete.
DAVID D.
22/10/25
5 / 5
The course content was relevant and well adapted to the level expected. The key concepts of forensics were presented clearly, with a good balance between theory and practice. The trainer's teaching methods were effective, making the explanations accessible and illustrated by concrete examples.
FARES L.
22/10/25
5 / 5
The course content is rich and coherent. The practical exercises were very well constructed and relevant. The trainer, Yohann, mastered his subject perfectly and was able to answer everyone's questions clearly.
ADRIAAN D.
22/10/25
4 / 5
a variety of exercises showing the tools needed for forensic work
PARTICIPANTS
Systems and network engineer/administrator.
PREREQUISITES
Good knowledge of IT security and networks/systems. Must have taken the course "Collecting and analyzing logs, optimizing your IS security".
TRAINER QUALIFICATIONS
The experts leading the training are specialists in the covered subjects. They have been approved by our instructional teams for both their professional knowledge and their teaching ability, for each course they teach. They have at least five to ten years of experience in their field and hold (or have held) decision-making positions in companies.
ASSESSMENT TERMS
The trainer evaluates each participant’s academic progress throughout the training using multiple choice, scenarios, hands-on work and more.
Participants also complete a placement test before and after the course to measure the skills they’ve developed.
TEACHING AIDS AND TECHNICAL RESOURCES • The main teaching aids and instructional methods used in the training are audiovisual aids, documentation and course material, hands-on application exercises and corrected exercises for practical training courses, case studies and coverage of real cases for training seminars.
• At the end of each course or seminar, ORSYS provides participants with a course evaluation questionnaire that is analysed by our instructional teams.
• A check-in sheet for each half-day of attendance is provided at the end of the training, along with a course completion certificate if the trainee attended the entire session.
TERMS AND DEADLINES
Registration must be completed 24 hours before the start of the training.
ACCESSIBILITY FOR PEOPLE WITH DISABILITIES
Do you need special accessibility accommodations? Contact Mrs. Fosse, Disability Manager, at psh-accueil@orsys.fr to review your request and its feasibility.
This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.
Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class
Dernières places
Date garantie en présentiel ou à distance
Session garantie
No session at the moment, we invite you to consult the schedule of distance classes.
13
This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.