Dimension Data IT Training Solutions Dimension Data - Home Dimension Data - Sitemap Contact Dimension Data

Search go


Go to EnCase Computer Forensic courses.
[Email] [Print] [Save]
EnCase® v6 NTFS
Vendor Course Code:
Course Length:4 days
Course Price:$3,600.00 + GST
Availability:
 
 
 
 If your preferred city or time is not currently listed, please call DDLS on 13 12 01 and we can try to accommodate your needs.
Overview:This hands-on course involves practical exercises and technical information about the NTFS file system. The class addresses the technical issues of the NTFS file system, including an in-depth analysis of the Master File Table (MFT) and its components. Students will locate and recover NTFS artifacts from the MFT and understand their evidentiary value. The course will delve into the NT Registry files for data identifying the computer user, installed applications and customised configurations. Students will recover encrypted passwords, identify alternate data streams, reparse points and mapped drives, identify security permissions for users and determine if removable media was connected to a NTFS volume. In addition, students will examine partially wiped drives and recover files from partially wiped NTFS volumes.

Emphasis is placed on the meaning and relevance of the artifacts that administratively document the NTFS file system.

Skills Gained:
  • Components of the NTFS Volume Boot Record and the Master File Table
  • Definitions and purpose of NTFS internal system files
  • Characteristics and storage of NTFS resident and non-resident attributes
  • Storage of alternate data streams and reparse points
  • Addressing NTFS user account information, encryption and file system security
  • Parsing and examining the NTFS registry
  • Linking media to an NTFS volume
  • Addressing technical issues associated with NTFS file systems
  • Advanced NTFS data recovery


  • Key Topics:The day begins with a review and update of the most current version of EnCase, as well as an introduction to the NTFS data structures. Students are introduced to the methods used to store binary data on a computer system, and use this information to interpret multi-byte values throughout the week.
    - EnCase Software Review and Updates
    - Research Techniques
    - NTFS Structures
    - NTFS Metadata files
    - Master File Table

    Day two continues with the discussion of the MFT by covering the Standard Information, Filename, Volume and Data Attributes.
    - MFT Attributes; Definitions/Components
    - Resident and Non-Resident Data
    - Alternate Data Streams
    - NTFS $LOGFILE

    Day three begins with a practical exercise involving a partially wiped drive. The directory information is absent, but the MFT exists in unallocated space. Students must identify records referencing certain filenames and recover the files.
    - Recovering files from partially wiped NTFS volume using the MFT
    - Encryption
    - Reparse Points
    - NTFS Folder Information - Index Roots, Entries and Index Buffers
    - NTFS File System Security

    Day four exposes participants to NTFS registry examinations. Students will identify methods of performing registry examinations, using manual methods and EnScripts.
    - Handling NTFS Registry Examinations
    - Registry Data
    - Link files
    - Final Practical Exercise

    Target Audience:This course is intended for law enforcement officers, computer forensic examiners, corporate and private investigators and network security personnel. A basic understanding of the concepts of computer forensics and Internet-related access is required. The class curriculum builds upon the foundation of the EnCase Computer Forensics II course, continuing with a focus on NTFS file system examinations.

    Prerequisites:The EnCase® Computer Forensics II course or EnCE Certification are prerequisits for this course. Advance preparation for this course is not required.



    Training Courses:  |  Microsoft Training  |  Cisco Training  |  Citrix Training  |  Check Point Training  |  Novell Training  |  IBM Lotus Training  |  Microsoft Business Solutions Training  |  CompTIA A+ Training  |  Professional Development Training  |  ITIL Training  |  Project Management Training  |  EnCase Computer Forensics

    Copyright 2007 Dimension Data Learning Solutions. All Rights Reserved. | Terms and Conditions of Use | Privacy Policy.