DF210 - Building an Investigation with EnCase Training Logo

DF210 - Building an Investigation with EnCase Training

Live Online & Classroom Enterprise Training

An advanced forensic analysis course where investigators build real investigations using OpenText EnCase Forensic, applying intermediate forensic techniques to recover, analyze, and interpret digital evidence from complex data sources.

Looking for a private batch ?

REQUEST A CALLBACK

Need help finding the right training?

Your Message

  • Enterprise Reporting

  • Lifetime Access

  • CloudLabs

  • 24x7 Support

  • Real-time code analysis and feedback

What is DF210 - Building an Investigation with EnCase Training about?

This hands-on training builds on foundational forensic skills to deepen your ability to conduct efficient investigations with EnCase Forensic. Students learn to recover deleted volumes, analyze system artifacts, parse registries, examine compound files, and investigate email and internet artifacts. Throughout the course, practical exercises prepare analysts for real-world cases involving encrypted volumes, unallocated space, USB devices, and more. 

What are the objectives of DF210 - Building an Investigation with EnCase Training ?

  • How to identify and open a volume that was encrypted using Windows BitLocker™
  • How to locate and recover deleted partitions
  • How to deal with compound file types
  • How to determine time zone offsets and properly adjust for the time zone in OpenText Forensic (EnCase)
  • About the Windows® Registry
  • How letters and numbers typed into a computer from a keyboard are translated into digital format
  • About the NT file system and ExFAT through an overview of the systems
  • How to identify Window system artifacts, such as the User folders, pagefile.sys, Recycle Bin, and other folders
  • How to locate and examine shortcut files
  • How to identify and recover data relating to the use of removable USB devices
  • How to recover data from the Recycle Bin
  • How to conduct a search for email and email attachments
  • How to examine email and internet artifacts
  • How to use Artifact Explorer to search, filter, tag, and bookmark artifact evidence
  • How to employ GREP operators to enhance searching techniques
  • How to employ the Media Analyzer during an investigation
  • How to search and recover files from unallocated space
  • How to use the Physical Disk Emulator (PDE) Module
  • How to create reports to present investigation findings

Who is DF210 - Building an Investigation with EnCase Training for?

This course is ideal for:

  • Digital forensic examiners and analysts.
  • Incident response and cybersecurity investigators.
  • Law enforcement personnel involved in computer crime investigations.
  • Corporate security analysts handling internal investigations.
  • IT professionals specializing in digital evidence and artifact analysis.

What are the prerequisites for DF210 - Building an Investigation with EnCase Training?

To succeed in this course, learners should have:

  • Completion of DF120 – Foundations in Digital Forensics with EnCase.
  • Solid computer skills and familiarity with Windows environments.
  • Understanding of basic forensic concepts (evidence files, case files).
  • Experience with EnCase keyword searches and bookmarks.
  • Knowledge of file systems and basic data acquisition techniques.

Available Training Modes

Live Online Training

4 Days

Who is the instructor for this training?

The trainer for this DF210 - Building an Investigation with EnCase Training has extensive experience in this domain, including years of experience training & mentoring professionals.

Course Logo

DF210 - Building an Investigation with EnCase Training - Certification & Exam

  • SpringPeople is the Authorized Training Partner of Opentext.
  • The training fees is exclusive of exam cost.
  • For any queries, feel free to reach us at Opentext@springpeople.com

Reviews