The OpenText EnCase - Host Intrusion Methodology & Investigation training course is designed for investigators who want to learn more about the methodology of host intrusions and the forensic artifacts left behind. This course goes into not only the technical aspects of host intrusions, but also discusses the methodology commonly used by attackers. The course begins with an introduction and explanation of the classroom's virtual workspace. Instruction addresses topics, such as methods of reconnaissance, in-depth exploration of browser exploits triaging a live host, intrusion analysis methodology, data hiding and phishing techniques, and malware infection. Other areas of study include performing collections with OpenText EnCase Portable, various investigation techniques, and escalating privileges.
By attending OpenText EnCase - Host Intrusion Methodology & Investigation workshop, delegates will learn:
- Conducting reconnaissance activities and using honey networks
- The life cycle of a cyber attack and the anatomy of a browser exploit
- Conducting a triage of a live host
- Understanding and establishing a viable methodology for intrusion analysis
- Data hiding and phishing activities
- Identifying and combating malware infections
- Analysis of compromised systems of remote access software and drive by web browser exploits
- Analysis of memory, event logs, packet captures, and malware
- Use of tools to escalate privileges and to enhance user capabilities
- Attend a training on OpenText EnCase - Advanced Analysis of Windows Artifacts or equivalent practical experience
- Good understanding of network topology and TCP/IP
- Law Enforcement Officers, Computer Forensic Examiners, Corporate & Private Investigators & Network Security Personnel.
