Date: TBA
Instructor: Zoran Illiev (Master of eForensics and Enterprise Security)
Price: AUD $2500 inc per person (TBC)
Location: CDFS Training Centre, Fyshwick ACT

X-Ways Forensics (2d)
This 2-days course include:
This course is focused on the systematic and efficient examination of computer media using our integrated computer forensics software “X-Ways Forensics”.
Advanced training course for experienced users and previous attendees of the main course. Topics may include (not all guaranteed because of time constraints or for other reasons):
• e01 evidence file format
• Creating skeleton images
• Creating cleansed images
• Sector superimposition
• Working with evidence file containers
• Creating containers, understanding the available options
• Adding files to containers from various sources
• Closing containers, optionally converting them
• Using containers as evidence objects
• Finding and analyzing deleted partitions
• Reconstructing RAID systems
• Practical examples for RAID 0 and RAID 5
• Explanation of underlying data arrangements
• Clues towards finding the right parameters
• Dynamic disks
• LVM2
• Understanding the levels at which file data is read and interpreted during analysis
• How X-Tensions work
• Recovering deleted NTFS-compressed files manually
• Block-wise hashing and matching
• Data profiles (Analyze Block functionality)
• Indexing
• Customizing the registry report
• Templates
* CHANGES TO COURSE CONTENT AND PROVIDED SOFTWARE CAN BE MADE WITH OUR PRIOR NOTICE.