Facebook Twitter Linked In
 

Sessions:
DF320 Advanced Analysis of Windows Artifacts with EnCase Forensic
Guidance Software
Sorry there are currently no sessions scheduled for DF320 Advanced Analysis of Windows Artifacts with EnCase Forensic.
Please let us know you are interested in this course.

Fulcrum Training Vendors
 
Training
 
DF320 Advanced Analysis of Windows Artifacts with EnCase Forensic

**Formerly EnCase Advanced Computer Forensics

This hands-on course is designed for examiners with solid computer skills, seeking to learn advanced concepts in analyzing Windows artifacts. The participants will be provided instruction that includes parsing and analysis techniques on registry data, volume shadow service, random access memory, zip file structures, prefetch, and SQLite content.


Delivery method: Group-Live. NASBA defined level: advanced.

This course provides in-depth coverage on topics, including:

  • Examination of the Microsoft Windows Registry
  • The use of block-based file hash analysis for file recovery
  • Examination of Volume Shadow Copy (VSC) data maintained by the Windows Volume Shadow Service (VSS)
  • Examination and recovery of Windows event logs
  • Hardware and software RAID technology, acquisition, and examination
  • Understanding SQLite databases and querying their data
  • Recovering deleted SQLite data
  • The purpose and function of prefetch files and how to analyze them
  • Principles of encrypted data recovery
  • Various techniques on the examination RAM
  • Low-level data recovery from Zip files and the latest version of Microsoft Word documents
Sorry - there are no sessions available to book.
 
Contact us
Australia:+61 (0)2 8012 9810
Singapore:+65 9297 1289
Customer Service:
Technical Support:
Training Bookings:
 
Register For the Fulcrum Newsletter HERE

© Fulcrum Management 2012
Name
Email
Organisation
Phone
Verification Code:
Name
Email
Organisation
Phone
Verification Code: