XWF II course info

Information below is directly from X-Ways Software Technology AG training website X-Ways Forensics 1 training     XWF 1 training

X-Ways Forensics II, 3 Days

Advanced training course for experienced users of X-Ways Forensics and previous attendees of the main course. Definitely not suitable as an introduction for new users of X-Ways Forensics. After attending this course and some self-study, you may start the X-PERT certification process.   Topics may include (not all guaranteed because of time constraints or for other reasons):

• .e01 evidence file format
• Creating skeleton images
• Creating cleansed images
• Capturing process memory
• Sector superimposition
• Working with evidence file containers
    • Creating containers, understanding the available options
    • Adding files to containers from various sources
    • Closing containers, optionally converting them
    • Using containers as evidence objects
• Finding and analyzing deleted partitions

• Capturing Memory Processes

• Reverse Imaging and Cloning Specialties

• Reconstructing RAID and Linux MD RAID systems

    • Practical examples for RAID 0 and RAID 5

    • Explanation of underlying data arrangements

    • Clues towards finding the right parameters

• FuzZyDoc

• Conditional cell coloring

• UI Text Adjustments

• Custom keyboard shortcuts

• Advanced sorting rules

• Registry Viewer and Registry Reports, Registry Report definition files

• How X-Tensions work

• Recovering deleted NTFS-compressed files manually

• Block-wise hashing and matching

• Command line usage of X-Ways Forensics

• Indexing

• Customizing the registry report

• Templates