TechNow Training Centers

    
 

1-800-324-2294        
 

 

About Us        
 

 

Home      
  

 

Choose Your Role
 

 

Courses            
 

 

Schedule by Location          
 

 

GSA Contract
 

 

Business Continuity IT Contingency Planning            
 

 

Corporate Risk Management            
 

 

Security 
              

 

AIA IA Conference 
              

 

DoD.8570 
              

 

On-Site Training 
 

 

Travel + Training     
 

 

Events             
 

 

eNewsletter      
  

 

Request Information  
 

 

Testimonials     
     

 

Directions            
 

 

Contact Us       
 

    

TN-4035:
Incident Response, Forensic Analysis & Discovery

Security Training for Your Entire Team.   

Overview

TechNow's Incident Response, Forensic Analysis & Discovery course combines forensic examinations & digital content analysis with immediate real-time response in an enterprise LAN/WAN environment.

Duration: 5 Days

What You Will Learn

Applying investigative techniques to incident response, forensic analysis & discovery
Acquisition & verification of digital evidence across the network infrastructure
Proactive analysis for unauthorized use, malicious applications, & corporate compliance
Investigating & analysis for corporate police violations
Acquisition and reporting of terminated employees data in secure & verifiable manner
Discovering files, directories & entire volumes of live machines
Conducting keyword searches
Recognizing & validating files signatures
Browsing file system artifacts such as the swap file, file slack & spooler files
Identifying Windows NTFS artifacts
Recovering printed & faxed pages
Exporting file lists & obtaining file statistics to support discovery
Discovering web-based e-mail & other common e-mail types
Bookmarking findings & evidence & creating reports to support findings
Storage of evidence in a corporate environment
Determining whether a computer system contains evidence within the scope of your investigation
Acquiring & authenticating the most common types of media
Identifying files using hash values & building has libraries
Recovering NTFS file system artifacts such as swap file, file slack, & spooler files
Authenticating the Evidence File format using CRC & hash values
Developing an Incident Response Plan
Coordinating & Incident Response Team (CERT)
Testing the Incident Response plan
Collecting evidence
Restoration of normal business processing
Crisis management
NTFS, FAT, Ext3 filesystem analysis
Worm & Virus disassembly analysis

Prerequisites

Students must have solid computer knowledge & administration skills, with prior coursework in computer forensics.  Experience with Forensics & a good understanding of the File Allocation Table (FAT) file system is recommended.

Course Location & Price

This course can be delivered on-site anywhere in the USA and Europe, or at one of TechNow's Training Centers.  You can even purchase Ultra-Inclusive packages which include training, travel expenses and exam fees through our Travel + Training program.  For current course dates, locations and prices, click here or contact a Training Advisor at 1-800-324-2294.

Show Me the Security Courses
Show Me a Complete List of Courses
 Learn More About:
  Course Customization  
  Financing  
  FREE Travel   
  GSA Contract    
  Guarantee   
  Testimonials    
  Training Vouchers     
  Volume Discounts   
 Get the Details
  Request Information  
  Reserve a Seat  
 Security Courses
  CISSP Training  
  Complete Hack and Defend  
  Check Point Firewall-1 NG CCSA/CCSE Boot Camp  
  Security Awareness Training  
  Corporate Risk Management  
  On-Site Training  
  Other Training  
  Complete Course List  
   
   
 

Click Here to Learn More
 
CheckPoint Boot Camp has a 97% Pass Rate!  Learn More.

CISSP Training has a 92% Pass Rate!  Learn More.
 

 

  

©TechNow, Inc. 2003. All rights reserved.
The TechNow logo is a trademark of TechNow, Inc. All other brand names and trademarks are TM and/or copyright by their respective owners.

Let us know how we're doing. If you have questions, comments, or problems please click here to contact us