Course Overview

This comprehensive course delves into the specialized field of database forensics, targeting widely deployed systems such as MySQL, Microsoft SQL Server, PostgreSQL, and MongoDB. As these databases become prime targets for hackers seeking valuable enterprise and personal data, the need for forensic investigation grows. The course addresses the complexities of evidence extraction from corrupted databases, detection of data tampering, and intricate data querying processes. Specialized tools and techniques are crucial for accurate data capture, preventing data loss, and maintaining the integrity of evidence. Database forensics proves particularly valuable in cases involving Intellectual Property (IP) infringement, corporate espionage, and events like data breaches or malware infections. 

The course unfolds with an introduction to digital forensics concepts and terminologies, leading into the realm of database forensics. It emphasizes the significance of this field and outlines the responsibilities of a database forensic specialist. Participants will gain insights into various types of databases, including relational databases (PostgreSQL, SQL Server, MySQL) and non-relational databases (MongoDB, Apache CouchDB). The curriculum then progresses to database querying using SQL, covering syntax, table essentials, and data maintenance in non-relational forms. In the heart of the course, participants dive into detailed database forensics tasks. This includes creating forensic copies, recovering deleted data, detecting anomalies, performing record carving for data recovery, reconstructing databases, and identifying inconsistencies and suspicious user behavior. The course also addresses formatting, reporting, and evidence preservation. The course offers a cheat sheet for database forensics and a guide on leveraging the acquired knowledge through EC-Council’s Computer Hacking Forensic Investigator (CHFI) Certification.  

By the end of the course, participants will have a solid understanding of database forensics fundamentals and the ability to perform a myriad of database forensics tasks.

What You Will Learn

  • Use your skills to analyse and extract data from target relational and non-relational databases in the course of a digital forensic investigation
  • maintaining sufficient professional standards in so doing
  • such that your findings can constitute valid
  • submissible evidence.
  • Access and query relational databases using SQL.
  • Access and query non-relational databases using one or more development languages.
  • Access logs and other evidence to assess the degree
  • if any
  • of malicious activity on a data platform.
  • Use techniques to assess the likelihood
  • scale and degree of missing or deleted data within a database system.
  • Use techniques to recover data from both healthy and corrupt/offline database systems.
  • Present your evidence in a professional and standards-compliant manner.

Program Curriculum

  • Handling Digital Evidence
  • First Steps in Securing the Digital Scene
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Relational Databases
  • Non-Relational Databases & Other Data Stores
  • Set-based Thinking
  • Chapter 2 Quiz

  • SQL (DML) - SELECT, FROM, and WHERE; Filtering and Joining
  • SQL - Aggregation, Data Exports
  • SQL – Diagrammatic Generation
  • Chapter 3 Quiz

  • Accessing MongoDB and CouchDB; Simple Method Calls
  • Slicing, Filtering, and Aggregation; Data Export
  • Using Object Relational Mapping Tools
  • Chapter 4 Quiz

  • Basic Statistical Measures
  • Pattern Analysis
  • Inference and Imputation
  • Chapter 5 Quiz

  • RDBMS Logs and the Transaction Log
  • System and Application Logs, and Log Querying
  • Modern Logging Systems
  • Chapter 6 Quiz

  • Attaching, Restoring and Accessing Healthy Databases
  • Supported RDBMS Recovery Methods; Disk- and In-Memory Data Recovery
  • Restoring Corrupted or Partial Databases
  • Chapter 7 Quiz

  • Course Summary
  • Formatting and Documenting Evidence
  • Course Wrap-Up and Further Study
  • Chapter 8 Quiz
Load more modules

Instructor

Dr. Derek A. Colley

Dr. Derek Colley is an experienced industry data professional, and expert in database administration, data architecture, SQL and BI development, data engineering, and data analysis. Over a two-decade career, he has worked with UK and international private and public-sector clients including taking on senior leadership of data-oriented business units, hands-on construction of complex data warehouses and data flows, and expert engineering consultancy delivering improvements to critical national data infrastructure.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8