Duration: 4 Days
**Formerly EnCase v7 Computer Forensics II
This hands-on course is designed for investigators with strong computer skills, prior digital forensics training, and experience using OpenText™ EnCase™ (EnCase) software. This course builds on the skills covered in the DF120: Foundations in Digital Forensic Analysis course and enhances the examiner's ability to work efficiently using EnCase's unique features. During this course, students will develop an investigation using analysis techniques such as deleted volume recovery, registry analysis, recycle bin examination, and compound file examination. Other analysis techniques will be included, such as unallocated cluster searching, analysis of current Windows artifacts, examination of email and Internet artifacts, and analysis of USB device artifacts.
Students must understand EnCase Forensic concepts, the evidence file structure, the creation and use of case files, and data acquisition and basic analysis methods. It is also important that students are familiar with methods for recovering deleted files and folders in a FAT environment, performing indexed queries and keyword searches on logical and physical media, creating and using EnCase bookmarks, analyzing file signatures, and exporting evidence.
Delivery method: Group-Live.
NASBA-defined level: intermediate.
CPE Credits – 32
Focusing on commonly conducted investigations, students will learn the following:
How to identify and open a volume encrypted with Windows BitLocker™
How to locate and recover deleted partitions
How to deal with compound file types
How to determine time zone offsets and correctly adjust the time zone in EnCase
About the Windows® Registry
How to create and use conditions for effective searching
About the ExFAT and NTFS file systems through an overview of systems
How to identify Windows system artifacts such as user folders, pagefile.sys, the recycle bin, and other folders
How to locate and examine shortcut files
How to identify and recover data related to the use of removable USB devices
How to recover data from the Recycle Bin
How to perform an email search and email attachments search
How to examine email and Internet artifacts
How to use the EnCase Media Analyzer during an investigation
How to employ GREP operators to enhance search techniques
How to recover print queue artifacts
How to search for and recover files from unallocated space
How to use the EnCase Physical Disk Emulator (PDE) module
How to create reports to present investigation results
Audience
This course is intended for cybersecurity professionals, litigation support, and forensic investigators.
Prerequisites
DF120 – Foundations in Digital Forensic Analysis with EnCase
Participants should have attended the EnCase course, DF120: Foundations in Digital Forensic Analysis.