This hands-on course involves practical exercises and real-life simulations in the use of EnCase® Forensic
version 7 (EnCase v7). The class provides participants with an understanding of the proper handling of digital evidence from the initial seizure of the computer/media to acquisition, including the use of FastBloc® SE and LinEn. Instruction then progresses to the analysis of the data. It concludes with archiving and validating the data.

Students attending this course will learn the following:

  • The EnCase v7 computer forensic methodology
  • What constitutes digital evidence and how computers work
  • Basic structures of the FAT, NT, and ExFAT file systems
  • How to create a case and how to preview and acquire media
  • How to conduct raw and index searches
  • How to analyze file signatures and view files
  • How to conduct hash analysis and import hash sets
  • Techniques using templates provided with EnCase v7 to create basic reports
  • How to restore evidence
  • How to archive files and data created through the analysis process
  • The proper techniques for handling and preserving evidence
Download Course Syllabus