DF320 - Advanced Analysis of Windows Artifacts with En Case

Course Overview

This hands-on course is developed for examiners with solid computer skills, searching to learn advanced concepts in analyzing Windows artifacts. The individuals will be provided instruction that includes parsing & analysis techniques on registry data, volume shadow service, random access memory, zip file structures, prefetch, & SQLite content.

Prerequisites

●    DF210 - Building an Investigation with EnCase or EnCE Certification.

Audience profile

This course is intended for law enforcement officers, corporate and private investigators, computer forensic examiners, & network security personnel. A fundamental understanding of the concepts of computer forensics is needed. The class curriculum builds upon the curriculum included in the DF210-Building an Investigation course, continuing with a focus on file and operating system examinations.

Learning Objective

Refer course overview

Content Outline

●    Understanding SQLite databases and querying their data
●    Recovering deleted SQLite data
●    The use of block-based file hash analysis for file recovery
●    Examination of the Microsoft Windows Registry
●    Analyzing Userassist and ShellBag registry data
●    The purpose & function of prefetch files & how to analyze them
●    Analyzing Windows system databases
●    Understanding and examination of the Windows timeline
●    Understanding and examining of the System Resource Usage Monitor Database
●    Identifying Windows notifications and how they can be customized
●    Understanding how the system resource usage monitor is implemented
●    Examination and recovery of Windows event logs
●    Examination of Volume Shadow Copy (VSC) and File History data
●    Identification and recovery of encrypted data
●    Understanding how BitLocker is implemented and the options for recovery and searching
●    Examination RAM using MemProcFS
●    Low-level data recovery from Zip files and the latest version of Microsoft Word documents
●    Hardware and software RAID technology, acquisition, and examination
 

FAQs

A: To attend the training session, learners should have operational Desktops or Laptops with the needed specifications and a decent internet connection to access labs.

A: We would always suggest you attend the live session to practice & clarify the doubts instantly & get more value from your investment. However, due to some contingency, if you have to skip the class, Radiant Techlearning will help you with the recorded session of that specific day. However, those recorded sessions are meant only for personal consumption & NOT for distribution or commercial use.

A: Radiant Techlearning has a data center with a Virtual Training environment for the learners.

Participants can easily access these labs over Cloud with the help of a remote desktop connection.

Radiant virtual labs allow you to learn from anywhere, globally, and in any time zone.

 A: The individuals will be enthralled as we engage them in real-world & industry Oriented projects during the training program. These projects will enhance your skills and knowledge & you will gain a better experience. These real-time projects will assist you a lot in your future tasks & assignments.

 A: Radiant Telelearning offers customized solutions and training programs for individuals, teams & businesses depending on their needs. Here is how we assist each one through our diverse formats.

Individuals / One-O-One Training
●      Focused learning sessions
●      Programmed scheduling according to your choice
●      Get personalized attention

 Opt what technology interests you
●    Teams- Enroll for our Online public or Classroom batches
●    Get our specialized updated content for various skill levels
●    Get on-demand learning & solve problems quickly
●    Get assistance from the ground level through sequential learning 

Enterprise:
●      Get customized training programmed and solutions that can be curated for your business
●      Meet the requirements of all learners
●      Let your workforce be geared up for all kinds of problem-solving
●     Inspire your teams for future
●     Update your workforce with the latest information from technology and business leadership to marketing.
 

A: Radiant Telelearning has a large pool of in-house certified trainers & consultants with solid backgrounds and working experience in the technology.

Radiant Telelearning offers more than 800+ courses & for each course, Radiant has identified ideal-in-class instructors.

Radiant has highly intensive selection criteria for Technology Trainers & Consultants who provide you with training programs. Our trainers & consultants undergo a rigorous technical & behavioral interview & assessment process before they are boarded in our company.

Our Technology experts/trainers & consultants carry a deep-dive understanding of the technical subject & are certified by the OEM. Our faculty will deliver you the knowledge of each course from the basic level in an easy way & you are free to ask your doubts any time from your respective faculty.

Our trainers have the patience & ability to explain complex concepts in a simplistic way with depth & width of knowledge.

 

A: Radiant believes in a practical & creative approach to training & development, distinguishing it from other training & development platforms. Moreover, training courses are undertaken by experts with a wide range of experience in their domain

 

Send a Message.


  • Enroll