High Technology Crime Investigation Association

Home
Upcoming Training
Officers
Contact Us

 

Upcoming Training

 

AccessData Internet Forensics 

 

September 18-20, 2007   Coraopolis, Pennsylvania, Hosted by EDS CIRT & Forensics

  

This course provides students with the knowledge and skills necessary to conduct an effective Internet application based investigation. Students should already be conducting computer based investigations and be familiar with the AccessData suite of tools. Internet based investigations experience would provide additional background knowledge but is not necessary. This is not an undercover investigations course - it is data recovery focused. Students begin immediately working a missing person case initiated from an instant message found on the computer screen of the missing person. The case takes the student to several different machines with multiple internet chat, browsing and email platforms. In addition to using Password Recovery Toolkit (PRTK) to break sign-on passwords for the following Internet applications and Messengers:

 

 

  • MSN Instant Messenger

  • YAHOO Instant Messenger

  • America Online and AOL Instant Messenger

  • Internet Explorer and Firefox Auto-Complete

 

Students will also utilize Forensic Toolkit (FTK) to locate and decrypt YAHOO Instant Messenger .DAT files, parse Internet Explorer .DAT files (History and Temporary Files) for hit rates, use counts and more - including Firefox history files, the download manager, user favorites, etc. Students will also parse America Online client files for user history, search terms, address books, buddy lists, email and more. Students will use the Registry Viewer to analyze Instant Messenger data such as:

 

 

  • Shared file permission status and file transfer information

  • Block or allow information for user contacts (buddy lists)

  • Last user access information and Recent contacts via the messenger

  • This advanced level, hands-on intensive course is intended for Forensic Investigators, Law Enforcement Personnel and security and network administrators who desire a greater understanding of Internet artifact data recovery.

 

Courses outside North America include an overview of Peer to Peer file sharing programs such as Kazaa and Limewire and the network architecture on which they operate. America Online course content has been removed providing the ability for delegates to explore such forensic issues as:

 

  • Examining P2P actvity log files

  • Decrypting Kazaa search terms

  • Determining download file sources

  • Determining file and folder share status

  • Decoding URN values for download file comparison by hash value

 

The Internet Forensics course includes an optional Practical Skills Assessment (PSA) that requires participants to apply concepts presented during the course to complete a practical exercise. Participants who successfully complete this exercise receive a certificate of PSA completion. 

 

 

AccessData Bootcamp

 

 

December 04-06, 2007   Coraopolis, Pennsylvania, Hosted by EDS CIRT & Forensics

 

 

 

This course provides students with the knowledge and skills necessary to install, configure, and effectively use the combined abilities of AccessData's Forensic Toolkit (FTK) and Password Recovery Toolkit (PRTK) to locate and examine email messages, deleted files, free space and file slack.

 

Additionally, students will learn how to search for and export graphic files, as well as export and gain access to encrypted files from multiple industry standard applications. Documenting digital media information and working with multiple forensic image formats are also explored.

 

This intermediate level, hands-on intensive course is intended for Forensic Investigators, Law Enforcement Personnel and Security and Network Administrators that are responsible for creating cases that examine, analyze, and classify digital evidence.

 

The AccessData BootCamp course includes an optional Practical Skills Assessment (PSA) that requires participants to apply concepts presented during the course to complete a practical exercise. Participants who successfully complete this exercise receive a certificate of PSA completion.

 

 

 

Previous Training

  

 

Paraben - Knowledge is power and we want to share our power with you. Paraben offers classes on PDA Forensics, E-mail Examination, P2, and Linux.  www.paraben.com

 

John E. Reid and Associates began developing interview and interrogation techniques in 1947. The Reid Technique of Interviewing and Interrogation is now the most widely used approach to question subjects in the world. The content of our instructional material has continued to develop and change over the years. John E. Reid and Associates is the only organization that can teach the current version of our training program on The Reid Technique. 

Our firm has developed a series of specialized courses that are the exclusive proprietary property of the firm. These are programs that contain copyright protected material that no other organization can utilize.

THESE PROGRAMS INCLUDE

The Advanced Course on The Reid Technique of Interviewing and Interrogation

 

The Reid Technique of Investigative Interviewing for Child Abuse Cases

 

Hiring the Best: Applicant Interviewing Techniques and Strategies

 

Street Crimes and Surveillance Techniques

 

Visit this Vender at www.reid.com

 

TESTIMONY:  "I run with a volunteer fire company that provides ambulance service.  While I attended both the basic and advance course of interviewing and interrogations at the Reid Institute for the purposes of corporate security, their training helped me recognize and develop a theme to assist a potentially combative patient which gained trust that averted a unwanted situation.  During the course of care, it was like watching one of the Reid Case videos in the back of my mind.  I was able to quickly flow with the patient's line of thought and guide toward a desired outcome.  I am confident that this training will be a valuable tool for anybody."