Advanced Computer Forensics Training

Advanced Computer Forensics Training


Advanced Computer Forensics Training course with detailed hands-on labs

ENO is proud to offer the Advanced Computer Forensics Training Boot Camp. Accelerated and taught in five (5) days, this in-depth Advanced Computer Forensics Training course teaches you advanced computer forensics concepts. This Advanced Computer Forensics Training course is intended for those that have either taken the ENO Computer Forensics Boot Camp, or have experience in the computer forensic profession

Customize It:

With onsite Training, courses can be scheduled on a date that is convenient for you, and because they can be scheduled at your location, you don’t incur travel costs and students won’t be away from home. Onsite classes can also be tailored to meet your needs. You might shorten a 5-day class into a 3-day class, or combine portions of several related courses into a single course, or have the instructor vary the emphasis of topics depending on your staff’s and site’s requirements.

Audience/Target Group

• IT professionals involved with information system security, computer forensics, and incident response

Advanced Computer Forensics Training Related Courses:

Duration: 5 days

Skilled Gained:

• Apply advanced computer forensic analysis concepts to live case work
• Respond appropriately to immediate response situations
• Perform Volume Shadow Copy (VSC) analysis
• Advanced level file and data structure analysis for XP, Windows 7 and Server 2008/2012 systems
• Registry analysis for XP and Windows 7/8 systems
• Malware detection and analysis
• Timeline Analysis
• Windows Application Analysis
• Mobile Forensics

Course Content:


Module 1: Advanced Analysis Concepts

• Avoiding Speculation
• Direct and Indirect Artifacts
• Least Frequency of Occurrence
• Documentation
• Convergence
• Virtualization

Module 2: Immediate Response

• Prepared to Respond
• Questions
• The Importance of Preparation
• Logs
• Data Collection


Module 3: VSC Analysis
• Registry Keys
• Live Systems
• Pro Discover
• F-Response
• Acquired lmages
• VHD Method
• VMware Method
• Automating VSC Access
• Pro Discover

Module 4: File Analysis
• File System Tunneling
• Event Logs
• Windows Event Log
• Recycle Bin
• Prefetch Files
• Scheduled Tasks
• Skype
• Apple Products
• Image Files


Module 5: Registry Analysis
• USB Device Analysis
• System Hive
• Software Hive
• Application Analysis
• NetworkLst
• NetworkCards
• Shell bags
• MUICache
• UserAssst

Module 6: Malware
• Introduction and Overview
• Malware Characteristics
• Initial Infection Vector
• Propagation Mechanism
• Persistence Mechanism
• Artifacts
• Detecting Malware
• Log Analysis


Module 7: Timeline Analysis
• Data Sources
• Time
• User
• TLN Format
• File System Meta data
• Event Logs
• Windows

Module 8: Application Analysis
• Log Files
• Dynamic Analysis
• Network Captures
• Application Memory Analysis


Module 9: Mobile Forensics
• Keyboard caches containing usernames, passwords, search terms, and historical fragments of typed communication.
• Screenshots preserved from the last state of an application
• Deleted images from the suspect’s photo library, camera roll, and browsing cache.
• Deleted address book entries, contacts, calendar events, and other personal data.
• Exhaustive call history
• Map tile images from the iPhone’s Google Maps application,
• Lookups and longitude/latitude coordinates of previous map searches, and coordinates of the last GPS fix.
• Browser cache and deleted browser objects
• Cached and deleted email messages
• SMS messages
• Deleted voicemail recordings

Request More Information

Time Frame: 0-3 Months4-12 Months

Print Friendly, PDF & Email