Limit search to available items
Book Cover
E-book
Author Bunting, Steve.

Title EnCase computer forensics : the official EnCE : EnCase certified examiner study guide / Steve Bunting
Edition 3rd ed
Published Hoboken, N.J. : Wiley ; Chichester : John Wiley [distributor], 2012

Copies

Description 1 online resource (1 volume)
Series Sybex serious skills
Serious skills.
Contents At a Glance -- Table of Exercises -- Introduction -- Assessment Test -- Answers to Assessment Test -- 1. : Computer Hardware -- The Boot Process -- Part itions. -- File Systems -- Summary -- Exam Essentials -- Review Questions -- Chaper 2: File Systems -- FAT Basics -- NTFS Basics -- exFAT -- Exam Essentials -- 3. : First Response -- Planning and Preparation -- The Physical Location -- Personnel -- Computer Systems -- What to Take with You Before You Leave
Recording and Photographing the SceneSeizing Computer Evidence -- Bagging and Tagging -- Summary -- Exam Essentials -- Review Questions -- 4. : Acquiring Digital Evidence -- Booting a Computer Using the℗ EnCase℗ Boot Disk -- Other Reasons for Using a DOS Boot -- Steps for Using a DOS Boot -- Drive-to-Drive DOS Acquisition -- Steps for Drive-to-Drive DOS Acquisition -- Supplemental Information About Drive-to-Drive DOS Acquisition -- Network Acquisitions -- Reasons to Use Network Acquisitions -- Preparing an EnCase Network Boot Disk -- FastBloc 2 Features -- Steps for Tableau (FastBloc) Acquisition
FastBloc SE AcquisitionsAbout FastBloc SE -- Steps for FastBloc SE Acquisitions -- LinEn Acquisitions -- Mounting a File System as Read-Only -- Updating a Linux Boot CD with the Latest Version of℗ LinEn -- Steps for LinEn Acquisition -- Enterprise and FIM Acquisitions -- Summary -- Exam Essentials -- Review Questions -- 5. : EnCase Concepts -- CRC, MD5, and SHA-1 -- EnCase Backup Utility -- Evidence Cache Folder -- Summary -- Exam Essentials -- Review Questions -- 6. : EnCase Environment -- Home Screen -- EnCase Layout -- Creating a Case -- Tree Pane Navigation -- Disk View -- View Pane Navigation -- Text View -- Hex View
Picture ViewReport View -- Doc View -- Transcript View -- File Extents View -- Permissions View -- Decode View -- Field View -- Lock Option -- Dixon Box -- Find Feature -- Other Views and Tools -- Conditions and Filters -- EnScript -- Text Styles -- Adjusting Panes -- Other Views -- Global Views and Settings -- EnCase Options -- Summary -- Exam Essentials -- Review Questions -- 7. : Understanding, Searching For, and Bookmarking Data -- Understanding Data -- Binary Numbers -- Characters -- Unicode -- Searching for Data -- GREP Keywords -- Starting a Search -- Bookmarking -- Summary -- Exam Essentials -- Review Questions
8. : File Signature Analysis and Hash AnalysisFile Signature Analysis -- Creating a New File Signature -- Conducting a File Signature Analysis -- Hash Analysis -- Summary -- Exam Essentials -- Review Questions -- 9. : Windows Operating System Artifacts -- Dates and Times -- Time Zones -- Windows℗ 64-Bit Time Stamp -- Adjusting for Time Zone Offsets -- Recycle Bin -- Determining the Owner of Files in the Recycle Bin -- Using an EnCase Evidence Processor to Determine the Status of Recycle Bin Files -- Recycle Bin Bypass -- Windows℗ Vista/Windows℗ 7 Recycle Bin -- Link Files -- Changing the Properties of a Shortcut
Forensic Importance of Link Files
Summary & B & The official, Guidance Software-approved book on the newest EnCE exam! & /b & & p & The EnCE exam tests that computer forensic analysts and examiners have thoroughly mastered computer investigation methodologies, as well as the use of Guidance Software's EnCase Forensic 7. The only official Guidance-endorsed study guide on the topic, this book prepares you for the exam with extensive coverage of all exam topics, real-world scenarios, hands-on exercises, up-to-date legal information, and sample evidence files, flashcards, and more. & ul & & li & Guides readers through preparation for the newest EnCase Ce
Notes Print version record
Subject Computer crimes -- Investigation -- Data processing -- Examinations -- Study guides
LAW -- Forensic Science.
Computer networks -- Security measures -- Examinations
Computer security -- Examinations
Electronic data processing personnel -- Certification
Genre/Form Study guides
Form Electronic book
LC no. 2012937916
ISBN 9781118219409
1118219406
9781118058985
1118058984
9781118219423
1118219422