Advanced IT-Forensik (AITF)

Course Description Schedule

Who should attend

  • IT-Security appointees
  • EDV Revisors
  • Members of Incident Response Teams


Course Objectives

This course is based on the IT-Forensik (ITF) course and deals with the data system NTFS. In addition you will learn where and when Windows creates protocol files which can help in a detailed system analysis.

Course Content

Intensive examination with NTFS

  • Organisation of files and directories
  • EFS encrypted files
  • Comprimised files
  • Sparse files

Artefacts of user activities

  • Program starts and pre fetch files
  • Evaluation of the registry
  • User profiles
  • Link files
  • Spool files from print orders
  • Internet activities
  • Previews
  • Restore Points
Classroom Training
Modality: C

Duration 3 days

  • Australia: 3,000.- AUD
Dates and Booking
Online Training
Modality: L
  • Australia: 3,000.- AUD
Dates and Booking

Currently there are no training dates scheduled for this course.  Enquire a date