Computer Forensics - Comprehensive Analysis and Training by Computer Evidence Ltd
Back to Home Page Products by Computer Evidence and DIBS UK Computer Forensic Investigation by Computer Evidence Ltd Computer Forensic Training by Computer Evidence Ltd Contact Computer Evidence Ltd The DIBS® Methodology

Course 2Computer Forensic Training by Computer Evidence Ltd

Computer Forensics - The Essential Techniques

 

DIBS® Training Course in Computer Forensics

Course 2 - Computer Forensics - The Essential Techniques

  1. Course Syllabus
  2. Course Schedule
  3. Course Cost

This two-day intensive course is designed to give a solid foundation in the theory and practice of essential computer forensic techniques. Theory sessions deal with forensic principles and methodology and relate these to the functioning of the personal computer. This session occupies most of the first morning. The rest of the course is practical and teaches how to make image copies, analyze them and present the results in court. Hands-on practice is gained using the DIBS® range of equipment, and many of the techniques will transfer to the use of other equipment. During the course there are a number of simulated investigations.

The course is ideal for the beginner with little previous experience or for the more practised computer operator wishing to learn forensic techniques.

Back to Top

Course Syllabus

Topics covered in the course include:

  • The physical characteristics of the computer
  • Forensic objectives and principles
  • Evidential integrity
  • Magnetic, silicon and optical storage
  • Hard disks - heads, sectors and cylinders
  • Measuring storage capacity
  • Organizing storage space
  • Deleted files, slack space, allocated and unallocated space
  • The BIOS
  • Device drivers
  • Initialisation files
  • The boot sequence
  • Making image copies
  • The image copy process
  • Hierarchical Structured Investigation (HSI)
  • Evaluating evidence
  • Using a forensic workstation
  • Restoring image copies
  • Producing, viewing and sorting file listings
  • Viewing and printing file contents
  • Undeleting files
  • Searching for information
  • Communications - eMail, the Internet, bulletin board systems
  • Encryption, passwords, software security devices
  • Documenting the investigation
  • Statements and reports
  • Presenting evidence
  • Disclosure/unused material
Back to Top

Course Schedule

Please Contact Us for current availability.

Back to Top

Course Venue and Cost

This course is run both at the company's offices in London and also on-site when required. The cost varies according to the number of attendees and location. Please contact us for a quotation.

Click here to receive more details about this course.

 

Site Last Updated: August  2008