| EnCase® Enterprise v6 - Phase I |
CPE credits: 32 | Level: Introductory to Intermediate
| Prerequisites: None. This live course is designed for senior corporate security professionals, auditors, legal professionals, and investigators. Students should currently be working with the EnCase Enterprise Edition or are employed by an organization that plans to purchase the EnCase Enterprise Edition. This course is intended for students who have not attended the five-day implementation training provided by Guidance Software's Professional Services division. Advance preparation is not required.
This basis hands-on course focuses on the use of EnCase Enterprise to conduct investigations in a live network environment. Students will learn how to use EnCase Enterprise to address internal investigations and audits in a manner consistent with recognized standards. The class makes extensive use of the Encase Enterprise to emphasize the common skills needed to conduct forensic examinations. Many of the skills taught in this course are consistent with the forensic intermediate course but have been adapted to the network forensic environment. Delivery method: Group-Live. NASBA defined level: basic to intermediate.
The following topics and skills will be covered in this course:
- Students will learn to install the EnCase SAFE and understand how data is secured in the EE environment
- Students will learn how to deploy servlets to supported operating systems (Windows®, *nix, Mac)
- Students will learn Enterprise-wide vs. "Ad-Hoc" servlet deployment methods and benefits
- Student will gain an understanding of the EnCase evidence file and examination methodology
- Students will acquire evidence using the EnCase Enterprise and non-enterprised acquisitions
- Students will learn to understand the role of volatile data on network investigations and security
- Students will use EnCase Snapshot® to capture and analyze enterprise wide volatile data
- Students will learn to bookmark files and file segments
- Students will create keywords and learn how to use them to search in an enterprise environment
- Students will identify files using hash values and building hash libraries
- Students will identify Windows XP operating system artifacts such as registry entries, link files, recycle bin, and user folders
- Students will learn how to prepare evidence for presentation in court
- Students will learn to recognize and validate file signatures
- Students will recover deleted partitions
- Students will recover NTFS file system artifacts such as swap files, file slack, and spooler files
- Students will recover printed pages
Course Syllabus
Tuition is $3,295.00 per student
Government training rate is $2,194.84 per student |
|
Available Course Schedule:
| FROM | TO | LOCATION | COURSE TITLE | STATUS | DETAILS |
| 01/20/2009 | 01/23/2009 | Los Angeles, CA | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 01/20/2009 | 01/23/2009 | Houston, TX | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 03/10/2009 | 03/13/2009 | United Kingdom | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 03/10/2009 | 03/13/2009 | United Kingdom | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 04/14/2009 | 04/17/2009 | Washington DC | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 05/05/2009 | 05/08/2009 | Chicago, IL | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 06/09/2009 | 06/12/2009 | Los Angeles, CA | EnCase® Enterprise v6 - Phase I | Open | More Info |
| 06/30/2009 | 07/03/2009 | United Kingdom | EnCase® Enterprise v6 - Phase I | Open | More Info |
|
|
|