Digital Forensics Training

EnCase DF320

This four-day training goes further into the subject matter that has been addressed in the EnCase DF210 (previously EnCase Computer Forensics II) training and emphasises the investigation of operating systems.

For whom is this training intended?
This training is intended for experienced digital investigators and IT security experts that have completed the EnCase DF210 training (previously EnCase Computer Forensics II). Basic knowledge of computer forensics is required.

What will you learn during the training?

  • How Windows NT File Systems (NTFS) operate.
  • NTFS data recovery.
  • Investigation of Windows Register Files.
  • Analysis and recovery of the Windows event log files.
  • Hard-end Software RAID technology, acquisition and investigation.
  • The principles of Encrypted Data Recovery.
  • Understanding and writing investigation to Windows BitLocker.
  • Linux and UNIX operating systems and file information.
  • Linux partition recovery.
  • Forensic investigation of Macintosh computers.
  • The Macintosh operating system.
  • In-depth look at the EnCase computer forensic methodology.
  • Introduction of EnScript programming.

This website uses cookies

We find it very important that you are aware of which cookies our website uses and for which purposes. We use Functional Cookies to make our website function properly. In addition, we use Analytics Cookies to analyze the use of our website. We also ask your permission for the placement of cookies from third parties (social media, advertising and analytics partners) with whom we share information. By clicking 'Accept', you accept the placement of the above mentioned cookies. If you click on 'Settings', you will be taken to a page where you can specify which cookies may and may not be placed. Click here for our Privacy Statement.