The course
On this 3 day practical computer forensics training course, gain an understanding of static computer forensics analysis by learning about forensic principles, evidence continuity and methodology to employ when conducting a forensic investigation. Using practical case scenarios, you will be guided through the process of conducting a computer forensics investigation, and will learn the principles surrounding the collection of evidence, together with the forensic tools associated with forensic analysis. Delegates who successfully complete the exam included at the end of the training course will be awarded the Certified Forensic Investigation Practitioner (CFIP) qualification.
Course Content 
- Introduction to Computer Forensics
- Introduction to Investigations
- Areas involved in a forensic investigation
- Investigation awareness phase of a forensic investigation
- Principles of forensic computing
- The 'Chain of Custody' process
- Applying the chain of custody process
- Identification and Seizure
- Common electronic evidence devices
- Seizure process of electronic evidence
- Evidential items of interest
- Actions performed on an electronic device
- Understanding Electronic Data
- Multiple bits
- Large quantities of bytes in data storage
- Decimal, Hexadecimal, ASCII, Unicode
- Storage and File Systems
- Preparing a hard drive for data storage
- Physical disks and logical drives.
- Differences between data and metadata
- Common file system metadata
- The purpose of file systems
- Various file systems' features
- Live Data, Deleted Data, Unallocated Data
- Forensic Acquisition
- Differences between a forensic image and a clone
- Hashing within the forensic acquisition process
- Common tools and hardware
- Forensic acquisition and verification of an electronic device
- Data Management
- Data backups of electronic evidence
- Logistical issues with data backups
- Working copies of electronic evidence
- Data retention periods of electronic evidence
- Forensic Analysis Techniques
- Five possible analysis environments
- Recovering data from an electronic device using data carving
- Keyword searching
- Issues associated with data extraction
- Strengths and weaknesses of hash analysis
- Common file type specific metadata
- Date and time analysis
- Recovering Forensic Artefacts
- Vista registry
- Internet history
- Data Reduction Techniques
- Filtering data
- Hash analysis
- Data interpretation process
- Dangers of data reduction
- Filtering using date and time stamps
- The use of data reduction techniques
- Forensic Challenges
- Data wiping
- Data encryption
- Malicious software
- Reporting
- Purpose of forensic reporting
- Expected outcome of a forensic investigation
- Target audience
- Reporting methods
- Defence statements
Highlights 
- The principles and guidelines for computer forensic investigations
- The process of evidence continuity
- The fundamentals of the complete forensic investigation process
- The forensic acquisition of an electronic devices
- How to store data on electronic media
- How to work with key forensic investigation products
- How to identify Windows based OS forensic artefacts
Download
PDF
|
Course outline
Read the computer forensics training course outline to find out more about the many topics covered in CFIP Forensic Investigation: Hands-On |
Frequently Asked Questions (FAQ)