Course

Course Summary
Credit Type:
Course
ACE ID:
DDCI-0003
Organization's ID:
FT210
Location:
Classroom-based
Length:
In-resident: 5 days (40 hours). Online: 5 weeks (40 hours)
Dates Offered:
Credit Recommendation & Competencies
Level Credits (SH) Subject
Lower-Division Baccalaureate 4 Computer Forensics, Information System Technology, or Computer Information Systems
Description

Objective:

The course objective is to provide the student with the knowledge to conduct a successful forensic examination of multiple suspect images from a Windows operating system.

Learning Outcomes:

  • Conduct a forensic examination of an image of the Windows operating system in a lawful manner
  • List the recommended specifications for a forensic workstation
  • Examine a forensic image from a Windows computer using basic forensic processes and automated tools in EnCase
  • Demonstrate the basic functions, configurations, outputs, tools, and settings of EnCase
  • Use Password Recovery Toolkit (PRTK) to defeat protected files
  • Produce examiner notes

General Topics:

  • EnCase tool
  • Forensic workstation setup
  • Lab reports
  • Examiner notes
  • Evidence processing
  • Forensic analysis basics
  • Windows Registry
  • Generate and analyze hash sets
  • Keyword search
  • Generate EnCase report
  • Legal considerations
Instruction & Assessment

Instructional Strategies:

  • Audio Visual Materials
  • Classroom Exercise
  • Discussion
  • Laboratory
  • Lectures
  • Practical Exercises

Methods of Assessment:

  • Examinations

Minimum Passing Score:

70%
Supplemental Materials