Custom Search
Provided by: Security University

QFE Qualified Forensic Expert Certification with QFE License

Training, Instruction and Documentation

Security University
Training Provided by Security University Finally, a Forensics class that teaches hands-on Tactical Forensics skills with validating practical labs. Earn your Q/ FE Qualified/ Forensic Expert Certification & Examiner License. This class is for students who want a comprehensive understanding of Forensic Examination and not just concepts of investigations. Cyber crime is outperforming traditional crime. Qualified/ Forensics Experts & Examiners learn the knowledge & skills to identify, track and prosecute cybercriminals. You learn step-by-step Forensic tactics, methods & hands-on skills. High-profile cases of corporate malfeasance have elevated electronic evidence discovery as indispensable to your company. A recent law review claims: A lawyer or legal team without a a Qualified Forensic Experta on their case is sure to lose in today's courtroom! In our Q/ FE ® Qualified Forensics Expert Training class, you will: Discover the root of how computer crimes are committed. Learn how to find traces of illegal or illicit activities left on disk with forensics tools and manual techniques. Learn how to recover data intentionally destroyed or hidden. Multiple ways to recover encrypted data. Step-by-step procedures to collect evidence from hard drives and live systems. How to recover data from digital cameras and cell phones. You will create an effective computer crime policy and gain the hands-on skills to implement it. The only class that challenges you to provide 3 hands-on practicals to ensure you know forensic recovery skills and process. Federation of Q/ FEs for effective Forensic networking. Non LE.
This is primarily ilt training
computer labComputer Lab Work
Contact Security University for more information
Course Level:basic through advanced
Duration:5 days
Training Presented in:English
QFE Qualified Forensic Expert Certification with QFE License

Class outline of Tactical Forensics Skills necessary to respond to security incidents:
  • Overview of Computer Crime
  • Preparing sterile examination media
  • Acquisition, collection and seizure of magnetic media
  • Documenting a "Chain of Custody"
  • Windows and DOS forensics
  • Working with NTFS
  • Combing Partition table and boot record
  • Investigating The Master File Table (MFT)
  • Open source Forensics tools
  • Investigating data streams
  • File storage dates and times
  • File deletion/ recovery
  • Recovering Internet Usage Data
  • Recovering: Swap Files/ Temporary Files/ Cache Files
  • Preservation and safe handling of original media
  • Making bitstream opies of original media
  • Common data hiding techniques
  • Linux/ Unix computer forensics
  • Examining CD-ROM media
  • Carving out files "hidden" in unallocated disk space
  • Unlocking Password Protected Files
  • Recovering deleted data from a cell phone
  • Digital Camera Computer Forensics
  • PDA Computer Forensics
  • Issues when presenting data in court
  • The marking, storage and transmittal of evidence
  • Use tools from Encase Forensic Edition, X-Ways Forensic Addition, Forensic TookKit (FTK), Linux dd, etc.

Real World Case Studies

  • Theft of Intellectual Property
  • Embezzlement
  • Employment disputes
  • Destruction / alteration of data
  • E-mail misuse

Course Includes 30 day free License of AccessData's FTK 2. 0 :
AccessData's FTK suite is the premier software package for computer forensic analysis.
Also a 1-year license of LSoft's Data recovery and Security Tools

Data SecurityProducts

  • Active Boot Disk ( LiveCD )
    Data Recovery & Security Toolset
  • Active KillDisk
    Secure Disk Format Utility
  • Active Eraser
    Ultimate Data Security Solution
  • Active ZDelete
    Personal Security Manager
  • Active ZDelete. NET
    Enterprise Security Manager
  • Active Disk Wiper
    Disk Free Space Secure Cleanup

Data Recovery Products

  • Active UNDELETE 7
    Data Recovery Software
  • Active UNERASER
    Data Recovery Software for DOS
  • Active Partition Recovery
    Partition Recovery Software
  • Active File Recovery
    Data Recovery Software and Service
  • Active Floppy Recovery
    Floppy Recovery and Imaging
  • Active Password Changer
    Windows Password Recovery Software
FREEWARE Products

  • Active NTFS Reader for DOS
    Freeware Reader of NTFS partitions
  • Active ISO Burner
    Freeware tool to burn ISO image
  • Active DVD Eraser
    Freeware tool to erase DVD/ CD RW
  • Active Hard Disk Monitor
    Freeware tool to check HDD status

Data Backup Products

  • Active Disk Image
    Hard Disk Imaging & PC Backup
  • Active ISO File Manager
    CD/ DVD ISO imaging software
  • Active Data CD/ DVD Burner
    Backup your files onto CD/ DVD


Required Prerequisites:

  • Firm understanding of the Windows Operating System

Attendees can be:

  • IT managers, network administrators, Windows administrators
  • Police and other law enforcement personnel
  • Defense and Military personnel
  • e-Business Security professionals
  • Systems administrators
  • Legal professionals
  • Banking, Insurance and other professionals
  • Government agencies 
  • Desire for computer forensics training

Audience Includes:

IT consultants, IAT II, III managers, IAM II, III, CISO, CIO s, security policy writers, privacy officers, information security officers, network administrators, network security administrators, security engineers, and other security professionals positions that require the CISSP certification, or anyone who wants to improve their income.

About The Training Provider: Security University
Security University - Security University is the leading provider of Q/ISP Qualified Information Security Professional - the only Tactical Hands-on Security Skills Certifications for IT Security Professionals in the world. Get 8570 & CND certified to validate your tactical security testing, analyst & penetration tester, Forensics skills. All classes CPE & GI BILL approved. SU is a Microsoft SDL Pro Partner. ...
tcw11-gfc-v396M-10/25/09-11:32:02-()[A]-[B]-[A] -03:13:42