Development and Training   
Skip Navigation Links
> products and servicesExpand > products and services
Skip Navigation Links
> companyExpand > company
Skip Navigation Links
> resourcesExpand > resources
Skip Navigation Links
> contact supportExpand > contact support
Skip Navigation Links
> support portal
  
 
Mobile Training Courses EnCE Certification Course Schedule Certifying Organizations Training Partners
Home > Training Home
EnCase® v6 Network Intrusion Investigations

CPE credits: 32   |  Level: Expert   |  Prerequisites: EnCase® Computer Forensics II course or EnCE Certification. Students should have a good understanding of network topology and TCP/IP. Advance preparation for this course is not required.

This hands-on course is designed for investigators who want to learn more about network intrusions, the tools commonly used by attackers, and the forensic artifacts left behind. This course goes into not only the technical aspects of network intrusions, but also discusses the methodology commonly used by attackers. The course will begin with an overview of networking protocols and then quickly address topics such as session hijacking, capturing network traffic, and the importance of collecting volatile data (which can contain significant forensic artifacts).

The course combines forensic examinations with live response in a network environment. Students learn how to examine a compromised server or workstation in the field to obtain log files and forensic images of hard disk drives. Students examine server log files and forensic artifacts for evidence of the attacker's methods and activities.

This course covers several aspects of Trojan virus infection, as well as how investigators and examiners can combat the Trojan virus defense (“It wasn’t me!”).

Students will take part in real-world scenarios by performing several different types of attacks on a mock victim machine and then examining the victim computer using EnCase to identify the artifacts they left behind by the “attacker.” Many different types of tools and programs will be discussed and used during the course to familiarize the investigator with common tools and methods used to gain unauthorized access, and how those tools and methods can be readily identified during a forensic examination.

In addition to the various “hacker” tools, students will also utilize and discuss a variety of forensic tools, including the EnCase Enterprise Edition (network version) and network intrusion EnScripts® for live incident response and collection of volatile data important to network intrusion investigations. Students will also discuss the use of the EnCase Enterprise Edition for internal investigations over an organization's Local Area Network.

Delivery method: Group-Live. NASBA defined level: advanced.

The course will cover the following topics:

  • Use of virtualized environments in investigations
  • The hacker mind and security policy
  • Collection of volatile data from live system
  • Viruses
  • Hiding and manipulating data
  • Trojans and Malware
  • Combating the Trojan virus defense
  • Footprinting and vulnerability scanning
  • Webserver attacks
  • Wireless security and vulnerabilities
  • Analyzing network traffic (sniffing)
  • Netbios/FileSharing attacks
  • Windows® rootkits
  • Security and incident response policy
  • IRC Bots
  • Binary anlaysis
  • IP and e-mail tracing
  • DCOM vulnerabilities
  • SQL database attacks
  • FTP server compromises
  • Hacking Linux
  • Exploiting web applications
  • Pre-built penetration testing tools
WHO SHOULD ATTEND

This course is intended for corporate and government/law enforcement investigators, legal professionals and network security personnel. Incident response supervisors and team members are encouraged to attend, as are individuals working in a penetration testing or network intrusion investigation role. An understanding of the concepts of computer forensics and familiarity with the EnCase forensic software is required. Knowledge of computer networking hardware, protocols, and concepts is helpful, but not required. Class curriculum is designed to provide a good overview of network security and intrusion investigation issues, both from a forensic and intruder perspective.

Course Syllabus



Tuition is $3,750.00 per student
Government training rate is $2,498.00 per student

Available Course Schedule:

FROMTOLOCATIONCOURSE TITLESTATUSDETAILS
08/26/200808/29/2008Chicago, ILEnCase® v6 Network Intrusion InvestigationsOpenMore Info
09/30/200809/03/2008Melbourne, AustraliaEnCase® v6 Network Intrusion InvestigationsOpenMore Info
10/07/200810/10/2008The NetherlandsEnCase® v6 Network Intrusion InvestigationsOpenMore Info
10/07/200810/10/2008Washington DCEnCase® v6 Network Intrusion InvestigationsOpenMore Info
10/07/200810/10/2008The NetherlandsEnCase® v6 Network Intrusion InvestigationsOpenMore Info
11/04/200811/07/2008Houston, TXEnCase® v6 Network Intrusion InvestigationsOpenMore Info
11/11/200811/14/2008United KingdomEnCase® v6 Network Intrusion InvestigationsOpenMore Info
11/18/200811/21/2008Toronto, CanadaEnCase® v6 Network Intrusion InvestigationsOpenMore Info
12/02/200812/05/2008Los Angeles, CAEnCase® v6 Network Intrusion InvestigationsOpenMore Info
02/24/200902/27/2009Chicago, ILEnCase® v6 Network Intrusion InvestigationsOpenMore Info
03/10/200903/13/2009Washington DCEnCase® v6 Network Intrusion InvestigationsOpenMore Info
03/31/200904/03/2009Los Angeles, CAEnCase® v6 Network Intrusion InvestigationsOpenMore Info
06/02/200906/05/2009United KingdomEnCase® v6 Network Intrusion InvestigationsOpenMore Info

© 2002-2007 Guidance Software, Inc. All Rights Reserved.
Privacy Statement | Historical Information | Contact Us | Careers | Mailing List | Resellers