Custom Search
Provided by: ProTrain Online

Computer Forensics Level 3

Security

Online Certificate Program Provided by ProTrain Online The Level III online program is designed for people interested in becoming Computer Forensics experts and have successfully completed Level I and II training. Students move at their own pace through all 3 levels (5 modules) and learn how to forensically Exam(s)ine and recover data from DOS, Windows 95 and Windows 98 operating systems. Students learn core forensic procedures for any operating or file system, and how to conduct forensically sound Examinations to preserve evidence for admission and use in legal proceedings. Each module requires an Exam(s) and completion of practical exercises before you can move to the next module. Additionally, this course will help prepare you for the upcoming Certified Computer Examiner (CCE) Examination. 12 Months Access, Mentor Supported
This is primarily online training
on-line e-learning cbt (computer based)This is an online eLearning or CBT training program
self directedThis is a self-directed course
study at homeThis course may be available for home-study
Contact ProTrain Online for more information
Course Level:advanced
Duration:50 hours
Training Presented in:English
Computer Forensics Level 3 o How to make a Windows 98 forensic boot disk
o How to make "exact" images of media - the various imaging methods
o The use of Firewire write blockers
o The significance, location and recovering data from:
Swap Files
Temporary Files
Internet Cache Files
The various types of Email files
Internet Cookies
Internet Sites Visited
o Basic Internet issues. Doing a basic "whois" and similar Internet checks.
o How to preserve the original media.
o How to prevent inadvertent writes to the original media, virus introduction to the original media, and activation of "booby" traps on the original media.
o How to make bitstream (exact copies) of the original media.
o The safe handling of the media by the forensic examiner.
o The most common situations that an examiner may encounter during an examination.
o Finding and documenting normal data or graphical files.
o How people commonly try to hide data.
o Finding and documenting data and files in unallocated space.
o Finding hidden data.
o An overview of password protection and unlocking passwords.
o Accessing and interpreting "metadata" in MS Office documents.
o There are three practical exercises on recovering data from swap files, temporary files, etc., determining registration of a URL, finding and documenting normal data on magnetic media, finding hidden data and unlocking passwords, unlocking passwords and accessing metadata.
o A written examination regarding the material covered in this module.



Module 5

o Data formats and types.
o Basic data format conversion.
o Examining CDR media and accessing multiple unclosed sessions.
o Managing data.
o Presenting the data to the client in a useful format.
o Presenting data in court or other proceedings in a clear and understandable manner.
o The marking, storage and transmittal of evidence.
o The basic use of automated forensic suites (Access Data's Forensic Tool Kit (FTK))
o A practical exercise where you examine a specially prepared hard disk drive. This hard disk drive will contain many current "real life" issues covered in this course and will require you to conduct a complete examination of the media. You must examine this hard drive, draw the appropriate conclusions, write a good report and present the evidence found in a manner that is clear and understandable.
o A written final examination will be given.





We will provide a detailed handout for each module covered. The handouts can be used as a reference manual. Sample reports, additional practical exercises, a DOS primer, Diskedit primer and other useful information and applications will be provided. You will be subscribed to our listservers that provide both administrative and technical information. Even after you complete the course, as material is updated, you will be able to download the new material from our web site.



We will provide some forensic software that was written specifically for forensic examiners, including:

o A fast and thorough wiping program
o A fast checksum program
o A fast program that documents files (including deleted files) on a drive
o A program that will allow examination of unallocated space
o A program that will make exact forensic copies of floppy diskettes
o An excellent forensic "carving" utility
o The Passware Kit from Lost Password.com
o See hardware and software requirements for details on the software provided.

You will be required to purchase:

o Norton Utilities
o Norton Ghost
o QuickView Plus (a viewing application) QuickView
o A good virus scanning utility
o You will be required to use your own USB drive for the examinations. We recommend a size no less than 32 MB
About The Training Provider: ProTrain Online
ProTrain Online - In partnership with colleges and universities, ProTrain Online offers hundreds of non-credit online career certificate programs. Online Program Features - Most programs have 12-month online access - Mentors available live online 24X7 to provide support in a variety of courses - Hands-on exercises contained within courses - Tests and quizzes within courses - Receive a Certificate of...
Want to Sell More online learning training?
tcw11-gfc-v396M-10/26/09-21:25:10-()[B]-[B]-[B] -01:23:59