Guidance Software EnCase® Computer Forensics II
Deeper Knowledge...
Once students grasp the foundations of EnCase® I, it's time to enhance the use of the program and master the advanced features. Set yourself aside from the rest in your industry with the skills that you will take from this course. Now is a better time than ever to excel at digital evidence discovery.
...So You Can Say "Case Closed"
With an enhanced knowledge of EnCase® , investigators will have digital forensic data that they can trust. Powerful search capabilities and automation features take the guesswork out of digital evidence acquisition and processing, providing court-vetted data that investigators can depend upon.
IT security professionals, investigators and litigation support staff who pass this course will master how to:
- Create and use logical evidence files
- Locate and recover deleted partitions and folders
- Conduct keyword searches and advanced searches using GREP
- Understand the EnCase® Virtual File System (VFS) and Physical Disk Emulator (PDE)
- Learn about the Windows Registry
- Learn how to deal with compound file types
- Export files, directories and entire volumes
- Identify files using hash values and building hash libraries
- Identify Windows XP artifacts such as link files, recycle bin, and user folders
- Prepare reports and evidence for presentation in court
- Recover artifacts such as swap files, file slack, spooler files, printouts, and faxes
Upcoming Classes
No classes are currently scheduled. Contact us to find out when the next class will be available.