[Foundational] DF120 – Foundations in Digital Forensics with EnCase

Level: Foundational
CPE Credits: 32
Duration: 4 Days
Prerequisites: Basic computer skills. Advance preparation for this course is not required.


  • City: Ottawa
    Date: 2023-10-30

Register for a Session


Training Overview

**Formerly EnCase v7 Computer Forensics I.

This hands-on course involves practical exercises and real-life simulations in the use of OpenText™ EnCase™ software (EnCase). The class provides participants with an understanding of how EnCase may be used to examine data related to an incident response, an employee misconduct investigation, and/or a law enforcement criminal and/or civil investigation. Participants create cases using EnCase, configure the application to maximize its utilization, and learn evidence acquisition concepts and how to validate the data collected. Instruction progresses to the analysis of the data whether related to criminal investigations, cybersecurity incidents, or other matters. The course will cover techniques, such as keyword or indexed searching along with hash analysis. Participants will learn how to bookmark, export, and create reports relating to examination findings. The course concludes with instruction on archiving, validating the data, and restoring the case.

After completion of this course, students may take next course in the DF-series: DF210 – Building an Investigation with EnCase.

Course Details

  • Language: English
  • Duration: 4 Days, October 30 – November 2 2023
  • Delivery: Group-Live
  • Venue: Best Western Plus Ottawa Kanata Hotel & Conference Centre, 1876 Robertson Road, Ottawa, Ontario, K2H 5B8**
  • NASBA defined level: Basic
  • Tuition: $3,200.00 USD; CAD price calculated at registration date

**Attendees staying at the hotel should ask for the EFS group rate.

Lunch is provided and included in the cost. Free parking is available at the course location.

Course Content

Course syllabus

Students attending this course will learn the following:

  • The EnCase digital forensic methodology and how to create a case
  • How to configure and navigate the EnCase interface
  • How to use case templates included with EnCase
  • How to the understand EnCase concepts
  • How to create an evidence file
  • How to install external file viewers to EnCase
  • How to create conditions within EnCase
  • How to analyze file signatures and view files
  • How to adjust time zones within EnCase
  • How to extract data and files from your evidence
  • How to decipher data allocation and file descriptions
  • How to tag and bookmark evidence files, file sets, and data structures
  • How to conduct raw and index searches
  • How to conduct hash and entropy analyses and import hash sets
  • How to import and export data
  • How to prepare reports using templates provided with EnCase
  • How to create reports
  • How to restore evidence
  • How to archive files and data created through the analysis process
  • The proper techniques for handling and preserving evidence


This course is intended for digital forensic investigators, including law enforcement, government, military, corporate, IT security, and litigation support professionals. Participants may have minimal computer skills and may be new to the field of computer forensics.


Basic computer skills. Advance preparation for this course is not required.

Students are required to bring a suitable laptop configured such that the user has admin credentials with the ability to install software without hindrance from antivirus, security software or corporate access settings.

Register for DF120 and other courses here: https://e-forensic.ca/registration/