This hands-on EnCase computer forensics training course involves practical exercises and real-life simulations. The course provides participants with an understanding of the proper handling of digital evidence from the initial seizure of the computer/media to acquisition, and then progresses to the analysis of the data. It concludes with archiving and validating the data.

Students attending this course will learn the following:

  • What constitutes digital evidence and how computers work
  • An overview of the EnCase Computer Forensic Methodology
  • Basic structures of the FAT and NTFS file systems
  • How to create a case and how to preview/acquire media
  • How to conduct basic keyword searches
  • How to analyze file signatures and view files
  • How to restore evidence
  • How to archive files and data created through the analysis process
  • How to prepare evidence for presentation in court
  • How to verify the evidence file
Download Course Syllabus