EnCase v6 Computer Forensics I Training by GlobalKnowledge Philippines - SpeedyCourse Philippines
We've noticed this is not your region.
Redirect me to my region
What do you want to learn today?

Details

This hands-on course involves practical exercises and real-life simulations. The class provides participants with an understanding of the proper handling of digital evidence from the initial seizure of the computer/media to acquisition, and then progresses to the analysis of the data. It concludes with archiving and validating the data. Delivery method: Group-Live. NASBA defined level: basic.

Outline

Course Outline:
 

. EnCase Forensic methodology

- Creating an EnCase Forensic case file

. Navigating within the EnCase Forensic environment

. EnCase Forensic concepts

- Safeguarding and preserving evidential data

. Understanding the concept of digital evidence and its impact on an investigation

. The basics of acquiring a forensically sound copy of data from a removable disk

. Understanding how computers work

- Hardware and associated terminology

- The CMOS, BIOS and boot sequence

- Interpreting binary and hexadecimal data

- The basics of text encoding

 
. NT/FAT File Systems

- How these file systems track data on their respective volumes

as well as what occurs when a file is created as well as deleted

. Acquisition of a hard disk

- Write-blocking technologies

- Acquisition using a forensically sound Linux operating system

-Drive-to-drive acquisition » Network crossover-cable acquisition

- Previewing computer systems

- Creation of keywords and searching

- Basic book marking

. File types

- Discussion of the categories of files/folders and the icons

employed by EnCase Forensic

. Reviewing search hits and bookmarking

- A more detailed discussion of bookmarking

and related options

. Signature analysis

- An automated comparison of the displayed file

extension with the actual content of the file

. Hash analysis

- Using digital signatures to identify/exclude files

without visually examining each one

. Installing external viewers

. Detailed copy/UnErase options

. Restoring evidence

- Often required by court order; necessary to

recover data and/or examine the operation of the

host system in real-time
. Archiving and reopening an archived case

. Verification of an evidence file

. Timeline view

. Location and recovery of evidence in unallocated space

- Manually

- Using EnScript® programs

. The importance and practicalities of evidence handling


*Training Included: Materials, Food, Certificate and Trainer
Reviews
Be the first to write a review about this course.
Write a Review

Global KMC is a private training company that certifies individuals in various IT and business skills.  It is an Authorized Training Center for the International Council of E-Commerce Consultants (EC-Council) - the owner and developer of the world famous Certified Ethical Hacker (CEH) course, Computer Hacking Forensics Investigators (CHFI) program, License Penetration Tester (LPT) program and various other programs offered in over 60 countries around the globe.  It is an authority in Digital Forensics training and solutions including multi-media and mobile forensics.  The company is also anAuthorized Training Partner for CompTia offering Security+, A+, Project+, Mobile+, Network+, Cloud+.  Global also offers various technical training on Cisco (CCNA, CCNP);  Microsoft (MCSA, MCSE, Desktop Technician, etc); Linux (Fundamentals, System Admin, Network Admin); CISSPITILIBM-i2 Analysts Notebook, to name a few.

For the Softskills training, Global is known in areas of: Project Management (PMP); Six Sigma (Yellow Belt, Green Belt, Black Belt); Communication; Train-the-Trainers; Risk Management, etc. ...

Sending Message
Please wait...
× × Speedycourse.com uses cookies to deliver our services. By continuing to use the site, you are agreeing to our use of cookies, Privacy Policy, and our Terms & Conditions.