1 (888) 999-9712 |
Customer Service
|
Customer Portal
Products
EnCase® Enterprise Platform
EnCase® eDiscovery
EnCase® Cybersecurity
EnCase® Forensic
EnCase® Portable
Tableau Forensic
Services
Professional Services
Advisory Program
Implementation
Casework
Security Assessment
Data Mapping
Legal Hold & ECA Jump-Start
Integration
Staff Augmentation
Training
Training Overview
Course Offerings
Course Schedule
Training Programs
Certification Programs
Certifying Organizations
Training Partners
Resources
Webinars & Demos
Whitepapers & Briefs
Events Calendar
Digital Forensics Today Blog
Threat Response Blog
Guidance on E-Discovery Blog
Real eDiscovery Magazine
EnCase® Legal Journal
CEIC Conference 2012
CISO Conference 2012
Customer Center
Customer Service
Technical Support
CEIC Conference
Training
Professional Services
Product Registration
Partners
Channel Partner Program
Channel Partners
Channel Partner Portal
Service Providers
Law Firms
About Us
Company Overview
Management
eDiscovery Legal Team
Newsroom
Careers
Investors
Contact Us
Home
/
This hands-on course is designed for examiners with advanced computer skills and two or more years of experience working in the field of computer forensics. Participants learn to use some of the more advanced features of EnCase® Forensic version 7 (EnCase v7) while examining operating and file system artifacts from the Microsoft® Windows operating systems. The course demonstrates advanced methods of data recovery, and identification and recovery of encrypted data.
Delivery method: Group-Live. NASBA defined level: advanced.
This course provides in-depth coverage on topics, including:
32
Advanced
EnCase Computer Forensics II or EnCE Certification. Advance preparation for this course is not required.
This course is intended for law enforcement officers, computer forensic examiners, corporate and private investigators, and network security personnel. A basic understanding of the concepts of computer forensics is required. The class curriculum builds upon the foundation of the EnCase® Computer Forensics II course, continuing with a focus on file and operating system examinations.
Tuition is $2,495.00 per student.
See Class Details for Actual Tuition Costs
Advanced techniques for creating and using conditions
Creating customized reports
Examining smartphones with EnCase v7
The use of block-based file hash analysis for file recovery
Hardware and software RAID technology, acquisition and examination
Analysis and recovery of Microsoft Windows event log files
Examination of the Microsoft Windows Registry
Principles of encrypted data recovery
Understanding and examining Windows BitLocker™ volumes
The purpose and function of prefetch files and how to analyze them
Various techniques on the examination RAM
How to use the Volume Shadow Copy Service (VSS)
Recovering data from Zip files and the latest version of Microsoft® Word documents
Using Windows® Search to perform index searches
Using Windows operating system artifacts to identify the use of removable USB devices
SELECT LOCATION 
SELECT DATE
COURSE INFORMATION
Chicago, IL
Hong Kong SWP
Houston, TX
Markham, Ontario
Melbourne, Australia (invest-e-gate)
Ottawa, ON Canada
Pasadena, CA
Salt Lake City, UT
Seoul, South Korea
Switzerland (City TBA)
United Kingdom
Veenendaal, The Netherlands
Washington, DC
Xiamen, China
DIRECTIONS
For more information regarding refund concerns and program cancellation policies, contact Guidance Software Training at
training@guidancesoftware.com
or call 626.229.9191 ext. 566.