Dimension Data IT Training Solutions Dimension Data - Home Dimension Data - Sitemap Contact Dimension Data

Search go


Go to EnCase Computer Forensic courses.
[Email] [Print] [Save]
EnCase® v6 Advanced Computer Forensics
Vendor Course Code:
Course Length:4 days
Course Price:$3,600.00 + GST
Availability:
 
 
 
 If your preferred city or time is not currently listed, please call DDLS on 13 12 01 and we can try to accommodate your needs.
Overview:This course is sourced from Guidance Software who are the leader in Computer Forensics and Incident Response Solutions. This live, hands-on course is designed for examiners with advanced computer skills and two or more years of experience working in the field of computer forensics. Participants learn advanced data recovery techniques of artifacts in many of the file systems supported by EnCase.

Skills Gained:After attending the "EnCase Advanced Computer Forensics" course, you will have a clear understanding of advanced data recovery techniques of artifacts in the many file systems supported by EnCase.

Key Topics:Day one provides an in-depth understanding of the NTFS data structures. The day begins with a review and update of the most current version of EnCase. Students are introduced to the methods used to store binary data on a computer system. They will use this information to interpret multi-byte values throughout the week. Students learn details of the NTFS file system, its internal files, and the methods used to administratively document files and folders on the volume. A practical exercise will demonstrate how knowledge of the NTFS file system can be used for advanced data recovery purposes.
* EnCase Software Review and Updates
* Research Techniques
* NTFS

Day two concentrates on the practical operation of the Windows NT operating system, beginning with RAIDs and moving into multi-user environments or networks. Students are shown how to link data with NT domain accounts and obtain valuable information from Windows event logs and the Windows Registry. Students are introduced to $LOGFILE, the file used for NTFS transaction logging and recoverability. Attendees learn about the history and terminology of encryption. They will also learn how to locate encryption software and encrypted data, and how to decrypt the data.
* RAID
* Windows® Event Logs
* NTFS $LOGFILE
* Encryption

On day three students learn about the Unix/Linux file system (including Linux partition recovery) and receive detailed information on Unix/Linux artifacts, including system log files and how to decode them. Participants are also shown how to use the Linux implementation of EnCase software, Linen, to acquire target media in a forensically sound manner.
* Linux/Unix History
* Linux/Unix Disk Layout and File System
* Linux/Unix User Accounts and Permissions
* Linux/Unix Password Cracking
* Linux/Unix Logging
* Linux Partition Recovery
* Forensic Acquisitions Using the Linux Version of EnCase(Linen)

Day four exposes students to Macintosh disk structure and partitions before giving them more practical training on the forensic acquisition of Macintosh data and Macintosh system artifacts. The final lesson offers an introduction to the language governing EnScript®. Students interpret and compose basic filters and queries, and then write the same filters and queries using the composition wizard feature of the newest EnCase version, Conditions.
* Macintosh® File Systems
* Macintosh Forensic Examinations
* Mac OS 8, 9, and 10 Artifacts
* Filters/Queries/Conditions

Target Audience:This course is intended for law enforcement officers, computer forensic examiners, corporate and private investigators, and network security personnel. A basic understanding of the concepts of computer forensics is required. The class curriculum builds upon the foundation of the EnCase Intermediate Analysis and Reporting courses, continuing with a focus on file system examinations.

Prerequisites:"EnCase Intermediate Analysis and Reporting" or EnCE Certification.



Training Courses:  |  Microsoft Training  |  Cisco Training  |  Citrix Training  |  Check Point Training  |  Novell Training  |  IBM Lotus Training  |  Microsoft Business Solutions Training  |  CompTIA A+ Training  |  Professional Development Training  |  ITIL Training  |  Project Management Training  |  EnCase Computer Forensics

Copyright 2007 Dimension Data Learning Solutions. All Rights Reserved. | Terms and Conditions of Use | Privacy Policy.