Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Forensics
EnCase training
EH-Net
May 23, 2013, 04:18:17 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Forensics
(Moderator:
don
) >
EnCase training
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: EnCase training (Read 10457 times)
0 Members and 1 Guest are viewing this topic.
unsupported
Sr. Member
Offline
Posts: 318
Unofficial Newbie Moderator
EnCase training
«
on:
April 28, 2010, 11:41:54 AM »
I am finally getting to play with more tools at work. One of the most exciting ones is EnCase. Apparently, licensing is expensive, and training is even more so. I want to show that I am deserving of training, by being the self-starter I am. Are there any good books out there for EnCase?
I have Books24x7 through work with access to "EnCase Computer Forensics: The Official EnCE: EnCase Certified Examiner Study Guide, Second Edition". This pretty much seems to be the only book out there which deals with EnCase specifically.
Are there any other good books that deal specifically with EnCase, or even a forensics book which deals with EnCase specifically?\
Also, anyone have experience with EnCase training? I think our department may opt for the OnDemand training due to budgeting issues.
Logged
-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
Ketchup
Hero Member
Offline
Posts: 1021
Re: EnCase training
«
Reply #1 on:
April 28, 2010, 01:01:34 PM »
I haven't done EnCase training myself, but a bunch of people I work with have. It's great training. They have three levels, and specialized courses depending on what your experience level is.
This is the book that everyone recommends:
http://www.amazon.com/EnCase-Computer-Forensics-DVD-Certified/dp/0470181451/ref=sr_1_1?ie=UTF8&s=books&qid=1272477660&sr=8-1-spell
Logged
~~~~~~~~~~~~~~
Ketchup
sil
Hero Member
Offline
Posts: 549
Re: EnCase training
«
Reply #2 on:
April 28, 2010, 01:23:30 PM »
Quote from: Ketchup on April 28, 2010, 01:01:34 PM
This is the book that everyone recommends:
http://www.amazon.com/EnCase-Computer-Forensics-DVD-Certified/dp/0470181451/ref=sr_1_1?ie=UTF8&s=books&qid=1272477660&sr=8-1-spell
The EnCE book linked is obviously the route to go however I will add a few books that will teach you a lot more about the field as opposed to the reliance on one tool (EnCase). I use Access Data more than EnCase when it comes to all inclusive tools but its not always about the tools. It boils down to understanding a system, data, metadata, etc.
I recommend:
Windows Forensic Analysis Toolkit from Harlan Carvey - worth its weight in gold
http://www.amazon.com/Windows-Forensic-Analysis-Toolkit-Second/dp/1597494224/ref=pd_rhf_shvl_1
Cyber Forensics: A Field Manual for Collecting, Examining, and Preserving Evidence of Computer Crimes
http://www.amazon.com/Cyber-Forensics-Collecting-Preserving-Information/dp/0849383285/ref=sr_1_1?ie=UTF8&s=books&qid=1272478831&sr=1-1
This book has a lot more informative content you will need to know and understand in the long run: e.g.: Digital Forensic Laboratory Accreditation Standards, Forensic Black Bag (what should be in your case), Cyber Forensics and the Law: Legal Considerations, Concealment Techniques
And finally...
Computer Forensics: Computer Crime Scene Investigation
http://www.amazon.com/Computer-Forensics-Crime-Investigation-Networking/dp/1584503890/ref=pd_sim_b_2
There is more to forensics than simply starting EnCase on a captured image.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
unsupported
Sr. Member
Offline
Posts: 318
Unofficial Newbie Moderator
Re: EnCase training
«
Reply #3 on:
April 28, 2010, 01:46:14 PM »
Thank you for the good recommendations! Initially, my use for EnCase will be to look for the existence of specific files, programs in memory, and may expand from there.
Logged
-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
sil
Hero Member
Offline
Posts: 549
Re: EnCase training
«
Reply #4 on:
April 28, 2010, 02:10:17 PM »
Quote from: unsupported on April 28, 2010, 01:46:14 PM
Thank you for the good recommendations! Initially, my use for EnCase will be to look for the existence of specific files, programs in memory, and may expand from there.
I would give Access Data a whirl if you can get it. EnCase is what it is and does its job and a plus is you could create your own EnScripts to assist you when you're truly comfortable with specifics. My big problem with programs like EnCase, Acesss' FTK, etc., is the reliance on automation. I feel a lot of examiners rely too much on a program being able to "find the smoking gun" often leaving an investigator with nothing to do but point and click... At that instance, what is there really to know at the end of the day.
I know a former professor who taught forensics at John Jay College of Criminal Justice and now works for EnCase... If you need a blog on EnCase shoot me a private message as I don't want to throw her name out there like that. Anyhow, I'd get the EnCase book since after all, you won't find anything SPECIFIC about EnCase in any other book however, I would definitely pick up the other books too. Also, depending on your title/role, see about subscribing to Forensic Magazine (
http://www.forensicmag.com/
) I get my copies every month and ALWAYS learn something new. Not completely specific to IT Forensic, but they post articles on the subject matter. On other matters of forensics, (DNA, labs, laws) there is almost always some cross-talk and you begin to notice similar patterns in say DNA forensics that give you an "aha!!!" on IT forensics.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
snortymcsnort
Newbie
Offline
Posts: 17
Re: EnCase training
«
Reply #5 on:
April 28, 2010, 02:31:16 PM »
I was unable to get work to pay for training, but I did take and pass the EnCE. The practical gives you a great opportunity to try out all the tools available in EnCase. Congrats on winning the Offensive Security training!
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: EnCase training
«
Reply #6 on:
April 28, 2010, 03:57:23 PM »
The trouble with FTK is that the new versions are complete garbage. We are still using version 1.x because 2.0 was completely unusable, and 3.0 is too new and cumbersome. The newer versions come with an Oracle engine for index storage and are a complete dog when it comes to performance. FTK also sucks at handling email because it has a horribly configured DtSearch engine. Yet, FTK is great at some other things, like examining link files. It's also much better at registry analysis. You really need to have working knowledge of both products, but it's complicated by the inadequacies of the new version of FTK.
I do believe that Access Data still allows you to download a trial version of FTK that is limited to 5000 files. That's enough to get a feel for the software.
There is definitely a reliance on tools in the forensics world. Some of it has to do with the fact that these tools are well established and have been proven to use repeatable methods. Some of it is due to lack of knowledge.
Logged
~~~~~~~~~~~~~~
Ketchup
dalepearson
Sr. Member
Offline
Posts: 357
Re: EnCase training
«
Reply #7 on:
April 30, 2010, 01:27:20 AM »
Late to the party but I will still put my 2p in.
The EnCe book is the only official Encase book on the market. I did all my study with guidance software and the courses where very good, and the training material and handout was excellent. I think Encase is a good product, and its alot cheapee tha FTK.
You can contact Guidance and they will send you a demo copy, then you can play at home and increase your knowledge.
When I spoke to Access Data, you had to pay £50 for a limited demo copy, no thanks.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Editor-In-Chief
: Special Xmas Deal: 10% Off eLearnSecurity Courses
(3) by
hekvvddtest
Greetings
: Hello
(6) by
hekvvddtest
Greetings
: Obtain The Scoop On mulberry bags Before You Are Too Late
(13) by
hekvvddtest
Calendar Of Events
: HITBSecConf2013 – Amsterdam
(9) by
hekvvddtest
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
hekvvddtest
Network Pen Testing
: HackaServer - Anyone tried it?
(4) by
hekvvddtest
Greetings
: Good day ...
(7) by
hekvvddtest
Gates
: Chris Gates' Blog RSA Finalist
(5) by
hekvvddtest
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(1) by
hekvvddtest
General Certification
: nth topic on Career Advice
(9) by
hekvvddtest
General Certification
: Direction
(5) by
hekvvddtest
Hardware
: Discreet Hacking Devices
(8) by
hekvvddtest
Calendar Of Events
: CanSecWest 2013
(5) by
hekvvddtest
Forensics
: Burn Note
(5) by
hekvvddtest
Calendar Of Events
: Cyber Readiness Challenge - Rome
(1) by
hekvvddtest
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.