Dimension Data IT Training Solutions Dimension Data - Home Dimension Data - Sitemap Contact Dimension Data

Search go


Go to Digital Investigations courses.
Email       Print       Save
EnCase® v6 Computer Forensics I
Vendor Course Code:
Course Length:4 days
Course Price:$3,700.00 + GST
Availability:
 
 
 
 If your preferred city or time is not currently listed, please call DDLS on 13 12 01 and we can try to accommodate your needs.
Overview:This course is sourced from Guidance Software who are the leader in Computer Forensics and Incident Response Solutions.
This live, hands-on course involves practical exercises and real-life simulations. The class provides participants with an understanding of the proper handling of digital evidence from the initial seizure of the computer/media to acquisition, and then progresses to the analysis of the data. It concludes with archiving and validating the data.

Skills Gained:After attending the "Introduction to Computer Forensics" course, you will have a clear understanding of computer forensics and computer evidence. You will also have a basic understanding of the "EnCase Computer Forensic Methodology".

Key Topics:Day one provides an understanding of the proper handling of digital evidence from seizure to acquisition. Students receive a basic overview of how computers function, as well as what constitutes digital evidence.
* EnCase Concepts
* What Constitutes Digital Evidence
* How Computers Work
* EnCase Navigation
* Diskette Preview/Acquisition

Day two begins with a discussion of the FAT file systems as well as an overview of the NT file system. Hard disk acquisition is covered, using both a forensically sound boot diskette, as well as a hardware write blocking device. Attendees will learn how to properly preview a computer system prior to acquisition, as well as explore keyword searching and bookmarking of relevant data.
* NTFS/FAT File Systems
* Creating a Boot Disk
* Hard Drive Preview and Acquisitions
* Creation of Keywords and Searching
* Bookmarking/Preserving Findings

Day three includes more complex bookmarking of data, and examination of file signatures to accurately identify file types. Attendees will install external viewers within EnCase and learn how to copy data from within an evidence file. Students learn how to restore an evidence file back to physical media and reacquire an evidence file with different options.
* File Types
* Bookmarking Techniques
* Signature Analysis
* Installing External Viewers
* Copy/Unerase Options
* Restoring Evidence
* Reacquiring an Evidence File

Day four explores how to archive a completed case, as well as how to reopen this case if needed in the future. Attendees will observe how EnCase can detect and identify any changes to the content of an evidence file, as well as take a detailed look at the Timeline view within EnCase. Pertinent areas of interest within the Windows operating system and user accounts are explored as well as locating data in unallocated space.
* Archiving/Reopening an Archived Case
* Verification of Evidence File
* Timeline
* Windows Artifacts
* Searching Unallocated Space


Target Audience:This course is intended for law enforcement officers, computer forensic examiners, corporate and private investigators, and network security personnel. Participants may have minimal computer skills and may be new to the field of computer forensics.

Prerequisites:Basic computer skills


Training Courses:  |  Microsoft Training  |  Cisco Training  |  Citrix Training  |  Check Point Training  |  VMWare Training  |  IBM Lotus Training  |  Apple Training  |  Business Analysis Training  |  Professional Development Training  |  ITIL Training  |  Project Management Training  |  Prince2 Training  |  Digital Investigations Training

Copyright 2009 Dimension Data Learning Solutions. All Rights Reserved. | Terms and Conditions of Use | Privacy Policy.