|

Knowledge Areas Reviewed
Active, archival and latent data
Affidavits, motions, and subpoenas
Basic TCP/IP concepts
Hashes and Checksums
Conducting keyword searches
Creating understandable and accurate reports
Creating forensically sound working copies or images
of media
File Header formats
Documentation, chain of custody, and evidence handling
procedures
Questions to prepare for/advising your retaining counsel
FAT 12/16/32 file systems
File slack, ram slack, drive slack, and unallocated
space
NTFS File Systems
Compact Disc analysis
Interpretation of various log formats
Interpreting Internet History and HTTP concepts
Manual and automated data recovery
Metadata for Microsoft Office and PDF documents
Overcoming encryption mechanisms and password protection
PC hardware concepts
Privacy issues
Regulatory compliance - Gramm-Leach-Bliley, HIPPA,
Sarbanes-Oxley, SEC, NASD and ISO
Rules of evidence
Windows print spool files
Windows registry
Windows shortcuts
Windows swap file
Working as an expert technical witness
Insurance/liability issues
Viruses and malware
There will be no materials provided, so be prepared
to take notes. Recording devices are not allowed in
the classroom. Seats are available on a first come
first served basis. To reserve a seat see the information
below. You may attend as many sessions as you wish,
as long as you register for each one.
|