DF120 Foundations in Digital Forensics with EnCase

Descripción

Duration: 4 Days
**Formerly EnCase v7 Computer Forensics I.

This hands-on course includes practical exercises and real-life simulations in the use of OpenText™ EnCase™ (EnCase) software. The class provides participants with an understanding of how EnCase can be used to examine data related to an incident response, an employee misconduct investigation, and/or a criminal and/or civil law enforcement investigation. Participants create cases using EnCase, configure the application to maximize its use, and learn evidence acquisition concepts and how to validate the collected data. Instruction advances toward data analysis, whether related to criminal investigations, cybersecurity incidents, or other matters. The course covers techniques such as keywords or indexed search along with hash analysis. Participants learn to flag, export, and create reports related to examination results. The course concludes with instructions on how to archive, validate the data, and restore the case.

Delivery method: Group-Live. NASBA-defined level: basic

CPE Credits – 32

Students attending this course will learn the following:

The EnCase digital forensic methodology and how to create a case
How to configure and navigate the EnCase interface
How to use the case templates included with EnCase
How to understand EnCase concepts
How to create an evidence file
How to install external file viewers in EnCase
How to create conditions within EnCase
How to analyze file signatures and view files
How to adjust time zones within EnCase
How to extract data and files from your evidence
How to decipher data allocation and file descriptions
How to tag and bookmark evidence files, file sets, and data structures
How to perform raw and indexed searches
How to perform hash and entropy analysis and import hash sets
How to import and export data
How to prepare reports using templates provided with EnCase
How to create reports
How to restore evidence
How to archive files and data created through the analysis process
Proper techniques for the handling and preservation of evidence.

Audience
This course is intended for digital forensic investigators, including law enforcement, government, military, corporate, IT security, and litigation support professionals. Participants may have minimal computer skills and may be new to the field of computer forensics.

Prerequisites
Basic computer skills. No prior preparation is required for this course.

Contact us for more information