FTK Bootcamp Advanced

Level: Advanced.

Duration: 3 days.

The AccessData BootCamp – Advanced is a three-day course providing the knowledge and skills necessary to conduct advanced and specialized functionality of FTK and PRTK.

Prerequisites

This hands-on class is intended for experienced users, particularly forensic professionals and law enforcement personnel, who use AccessData forensic software to examine, analyze, and classify digital evidence.

To obtain the maximum benefit from this class, you should meet the following requirements:

Class Materials and Software

You will receive the associated materials prior to the course.

During this three-day, hands-on course, participants will perform the following tasks:

Modules

Module 1: Introduction

Objectives:

Lab:

Participants will install the UTK components—FTK, KFF Library, PRTK, and Registry Viewer

Module 2: PRTK 201

Objectives:

Lab:

During the practical participants will decrypt files from FTK, manage dictionaries, and save decrypted copies of files once the key has been found.

Module 3: Specialized FTK Features

Objectives:

Lab:

During the practical, participants will understand the usage for the advanced features of FTK in this module.

Module 4: Cerberus

Objectives:

Lab:

Students will process a case with live malware for purposes of understanding the function of the Cerberus FTK add-on.

Module 5: Distributed Processing

Objectives:

Lab:

Students will walk through the process of setting up distributed processing workers.

Module 6: Adding Remote Data

Objectives:

Lab:

Module 7: Memory Analysis

Objectives:

Lab:

During the practical, participants will see how FTK can process a memory dump.

Module 8: Student Exercise

Objectives:

Lab:

Students will process a practice case. Students will apply all knowledge learned from all FTK courses and produced a report based on the scenario provided.

Module 9: Workflow and Theory Discussion

Objectives:

Lab:

Participants will participate in discussion about the various topics involved in processing forensic cases of different needs.