Computer Hacking Forensic Investigator (CHFI) v9

  • Tuition USD $3,895
  • Reviews star_rate star_rate star_rate star_rate star_half 839 Ratings
  • Course Code 3401
  • Duration 5 days
  • Available Formats Virtual, Classroom

EC-Council released the most advanced computer forensic investigation program in the world. This course covers major forensic investigation scenarios that enable you to acquire hands-on experience on various forensic investigation techniques and standard tools necessary to successfully carry-out a computer forensic investigation.

Battles between corporations, governments, and countries are no longer fought using physical force. Cyber war has begun and the consequences can be seen in everyday life. With the onset of sophisticated cyber attacks, the need for advanced cybersecurity and investigation training is critical. If you or your organization requires the knowledge or skills to identify, track, and prosecute cyber criminals, then this is the course for you. You will learn how to excel in digital evidence acquisition, handling, and forensically sound analysis. These skills will lead to successful prosecutions in various types of security incidents such as data breaches, corporate espionage, insider threats, and other intricate cases involving computer systems.

This course includes one exam voucher for the CHFI - Computer Hacking Forensic Investigator v9 exam.


Skills Gained

  • The computer forensic investigation process and the various legal issues involved
  • Evidence searching, seizing and acquisition methodologies in a legal and forensically sound manner
  • Types of digital evidence, rules of evidence, digital evidence examination process, and electronic crime and digital evidence consideration by crime category
  • Roles of the first responder, first responder toolkit, securing and evaluating electronic crime scene, conducting preliminary interviews, documenting electronic crime scene, collecting and preserving electronic evidence, packaging and transporting electronic evidence, and reporting the crime scene
  • Setting up a computer forensics lab and the tools involved in it
  • Various file systems and how to boot a disk
  • Gathering volatile and non-volatile information from Windows
  • Data acquisition and duplication rules
  • Validation methods and tools required
  • Recovering deleted files and deleted partitions in Windows, Mac OS X, and Linux
  • Forensic investigation using AccessData FTK and EnCase
  • Steganography and its techniques
  • Steganalysis and image file forensics
  • Password cracking concepts, tools, and types of password attacks
  • Investigating password protected files
  • Types of log capturing, log management, time synchronization, and log capturing tools
  • Investigating logs, network traffic, wireless attacks, and web attacks
  • Tracking emails and investigate email crimes
  • Mobile forensics and mobile forensics software and hardware tools
  • Writing investigative reports

Who Can Benefit

IT professionals involved with information system security, computer forensics, and incident response

Course Details

Lab 1: Computer Forensics in Today's World

Lab 2: Learning about Computer Crime Policies, Programs, and Computer Forensics Laws

Lab 3: Reporting a Cybercrime to the FBI

Lab 4: Case Study: Child Pornography

Lab 5: Additional Reading Material

Lab 6: Computer Forensics Investigation Process

Lab 7: Recovering Data Using the Recover My Files Tool

Lab 8: Performing Hash, Checksum, or HMAC Calculations Using the HashCalc Tool

Lab 9: Generating MD5 Hashes Using MD5 Calculator

Lab 10: Additional Reading Material

Lab 11: Searching and Seizing Computers with a Search Warrant

Lab 12: Understanding an Application for a Search Warrant (Exhibit A)

Lab 13: Additional Reading Material

Lab 14: Studying the Digital Evidence Examination Process - Case Study 1

Lab 15: Studying Digital Evidence Examination Process - Case Study 2

Lab 16: Additional Reading Material

Lab 17: Studying First Responder Procedures

Lab 18: Understanding the First Responder Toolkit

Lab 19: Additional Reading Material

Lab 20: Computer Forensics Lab

Lab 21: Gathering Evidence Using the Various Tools of DataLifter

Lab 22: Viewing Files of Various Formats Using the File Viewer Tool

Lab 23: Handling Evidence Data Using the P2 Commander Tool

Lab 24: Creating a Disk Image File of a Hard Disk Partition Using the R-Drive Image Tool

Lab 25: Additional Reading Material

Lab 26: Understanding Hard Disks and File Systems

Lab 27: Recovering Deleted Files from Hard Disks Using WinHex

Lab 28: Analyzing File System Types Using The Sleuth Kit (TSK)

Lab 29: Case Study: Corporate Espionage

Lab 30: Additional Reading Material

Lab 31: Performing Windows Forensics

Lab 32: Discovering and Extracting Hidden Forensic Material on Computers Using OSForensics

Lab 33: Extracting Information about Loaded Processes Using Process Explorer

Lab 34: Investigating Metadata Using Metadata Analyzer

Lab 35: Viewing, Monitoring, and Analyzing Events Using the Event Log Explorer Tool

Lab 36: Performing a Computer Forensic Investigation Using the Helix Tool

Lab 37: Case Study: Terrorist Attack

Lab 38: Case Study: Brutal Murder

Lab 39: Forensics Challenge: Banking Troubles

Lab 40: Additional Reading Material

Lab 41: Data Acquisition and Duplication

Lab 42: Investigating NTFS Drive Using DiskExplorer for NTFS

Lab 43: Viewing Content of Forensic Image Using AccessData FTK Imager Tool

Lab 44: Searching Text Strings in the Hard Disk Partition Image Using DriveLook

Lab 45: Forensics Challenge: Forensic Analysis of a Compromised Server

Lab 46: Additional Reading Material

Lab 47: Recovering Deleted Files and Deleted Partitions

Lab 48: File Recovery Using EASEUS Data Recovery Wizard

Lab 49: File Recovery Using Quick Recovery Tool

Lab 50: Partition Recovery Using MiniTool Power Data Recovery Tool

How do I enroll?

A comprehensive listing of ExitCertified courses can be found here. You can register directly for the required course/location when you select "register". If you have any questions or prefer to speak with an ExitCertified education consultant directly, please submit your query here. A representative will contact you shortly.

How do I pay for a class?

You can pay at the time of registration using credit card (Mastercard/Visa/American Express) cheque or PO.

What if I have training credits?

ExitCertified honors all savings programs from the partners we work with. ExitCertified also offers training credits across multiple partners through our FLEX Account.

When does class start/end?

Classes begin promptly at 9:00 am, and typically end at 5:00 pm.

Does the course schedule include a Lunchbreak?

Lunch is normally an hour long and begins at noon. Coffee, tea, hot chocolate and juice are available all day in the kitchen. Fruit, muffins and bagels are served each morning. There are numerous restaurants near each of our centers, and some popular ones are indicated on the Area Map in the Student Welcome Handbooks - these can be picked up in the lobby or requested from one of our ExitCertified staff.

How can someone reach me during class?

If someone should need to contact you while you are in class, please have them call the center telephone number and leave a message with the receptionist.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

I was really happy with the overall experience of attending a remote course through ExitCeritfied.

It Interesting but the lab environment is kinda slow. I prefer to just have lab instructions since I did all my lab on my own machine

The lady at the front really nice. Everthing was always stocked up: Helpful

Course Material was well presented and labs were interesting and hand on experience

I am very satisfied with the course and teacher(Bill), and with the given option I will play with labs more after the class is over. Thank you

3 options available

  • Oct 19, 2020 Oct 23, 2020 (5 days)
    08:30 16:30 EST
  • Nov 16, 2020 Nov 20, 2020 (5 days)
    08:30 16:30 EST
  • Dec 14, 2020 Dec 18, 2020 (5 days)
    08:30 16:30 EST
Contact Us 1-800-803-3948
Contact Us Live Chat
FAQ Get immediate answers to our most frequently asked qestions. View FAQs arrow_forward