Learn your way! Get started

Forensic Investigator, Part 07 of 10: Database Forensics

with expert David Bigger

Watch trailer

Course at a glance

Included in these subscriptions:

  • Dev & IT Pro Video
  • Dev & IT Pro Power Pack

Release date 8/16/2017
Level Intermediate
Runtime 0h 53m
Closed captioning N/A
Transcript N/A
eBooks / courseware N/A
Hands-on labs N/A
Sample code N/A
Exams Included

Enterprise Solutions

Need reporting, custom learning tracks, or SCORM? Learn More

Course description

MySQL, Oracle or MS SQL server….which is it running? How do you know? Oracle may be the number one database on the market today, but what does that mean for us as investigators? Coming up, we will be looking at various database management systems and how they work with data. We will dive into Oracle databases, MySQL databases and MS SQL databases so we know where we can look for potential evidence. We will also take a look at some tools and techniques that will allow us to gather the data for our case against the perpetrators. This course is part of a series covering the EC-Council Computer Hacking Forensic Investigator (CHFI).


Recommended: Understanding of networking; How data flows from source and destination Computer security basics such as passwords, encryption and physical security Basic understanding of computing and computer systems Experience with various operating systems

Learning Paths

This course will help you prepare for the following certification and exam:
Computer Hacking Forensic Investigator

Meet the expert

David Bigger is the lead trainer at Bigger IT Solutions. He has been information technology for a little over 20 years and has been training all over the US. He has worked with companies like US Military, Lockheed Martin, General Dynamics, Dominos Pizza, University of Utah and Expedia

Course outline

Database Forensics

Database Forensics (12:54)
  • Introduction (00:26)
  • Database Forensics (02:17)
  • Database Review (05:12)
  • Popular DBMS (04:39)
  • Summary (00:19)
Oracle (15:38)
  • Introduction (00:19)
  • Oracle (01:24)
  • Oracle Logical Structure (01:14)
  • Data Blocks (01:41)
  • System Change Number (SCN) (01:41)
  • Where to Look in Oracle (00:54)
  • System Global Area (03:23)
  • Where to Look in Oracle, Continued (03:47)
  • Oracle Forensic Tools (00:48)
  • Summary (00:22)
MySQL (13:21)
  • Introduction (00:20)
  • MySQL (01:36)
  • Data Directory (02:37)
  • Log Files for MySQL (04:02)
  • Were to Look in MySQL (01:31)
  • MySQL Forensic Tools (02:53)
  • Summary (00:19)
Microsoft SQL Server (11:27)
  • Introduction (00:24)
  • Microsoft SQL Server (01:44)
  • Data Storage (03:08)
  • Where to Look on MS SQL Server (03:18)
  • Tools for MS SQL Forensics (00:27)
  • SQL Server Management Studio (00:43)
  • ApexSQL (01:15)
  • Summary (00:25)