This hands-on course involves practical exercises and real-life simulations. The class provides participants with an understanding of the proper handling of digital evidence from the initial seizure of the computer/media to acquisition, and then progresses to the analysis of the data. It concludes with archiving and validating the data. Delivery method: Group-Live. NASBA defined level: basic.
Students attending this course will learn the following:
Introduction
Basic computer skills. Advance preparation for this course is not required.
This course is intended for IT security professionals, IT administrators, police officers, litigation support and forensic investigators
Participants may have minimal computer skills and may be new to the field of computer forensics.
What constitutes digital evidence and how computers work?
An overview of the EnCase Computer Forensic Methodology?
Basic structures of the FAT and NTFS file systems?
How to create a case and how to preview/acquire media?
How to conduct basic keyword searches?
How to analyze file signatures and view files?
How to restore evidence?
How to archive files and data created through the analysis process?
How to prepare evidence for presentation in court?
How to verify the evidence file ?
Class Info:
Status:Open
NEW TRAINING DATES Date: 08/03/2010 - 08/06/2010 Time: 8:00 AM until 5:00 PM
Country: Curacao Netherlands Antilles
Address:
University of the Netherlands Antilles Jan Noorduynweg 111