Applied NT Forensics

Who Should Attend?


This course is designed for computer forensic professionals seeking to enhance their knowledge of the evidential opportunities within the NT-based system.

Course / Module entry requirements


Designed for experienced forensic computer analysts who have attended the NPIA Core Skills in Data Recovery and Analysis course or similar and have at least 12 months experience in a forensic computing environment.

No. of courses being run


2010/11 (full year): 2

Dates and Venues


 From: 15 Mar 2010  To: 19 Mar 2010
 Venue: Wyboston  Places: Course Full

 From: 12 Jul 2010  To: 16 Jul 2010
 Venue: Wyboston  Places: Available

 From: 24 Jan 2011  To: 28 Jan 2011
 Venue: Wyboston  Places: Available

Course / Module duration

5 days

Assessment process / accreditation details

Students attending this course will undertake a final assessment.

Successful completion of this course will allow 10 credits to be obtained towards the MSc in Cybercrime Forensics offered by Canterbury Christ Church University.

Additional Information

Prices below current until 31 March 2011

For bookings and enquiries, please contact

Tel: 01480 401856
Email: 
enquiries_hightechcrime@npia.pnn.police.uk

Cost to HO Forces

£1256 Residential

£762 Non-Residential

Cost to non HO Forces

£N/A Residential


£N/A Non-Residential

Overview


In depth technical knowledge is introduced in a mixture of trainer led presentations and practical sessions allowing students to fully understand and implement their new skills with purpose and effect.

Aims


The release of Microsoft Vista and the predominance of NT-based computers running on NTFS file systems requires forensic examiners to have a robust understanding of these structures. 

This course will enable examiners to recover evidence more effectively and have a much better understanding of what their automated forensic tools are doing. 

They will be better prepared to assemble evidence for courts that is clear and supportive of evidential needs.

Objectives


  • Interrogate, interpret and recover potential evidence found on Vista and other NT-based computers running on NTFS file systems. 
  • The registry, recycle bin, master file table and other operating system and file system structures likely to hold evidential data will be examined and explained at their fundamental levels.