Training Delivery - Classroom Training/Onsite

DF320 Advanced Digital Forensic Analysis: macOS

This course prepares students to identify various artifacts typically located in property lists and SQLite databases on MacOS-based computers, as well as learn how to perform forensic analysis. Students gain hands-on practical experience writing basic SQL queries and using to analyze operating system artifacts that includes, but is not limited to, user login passwords, FaceTime, messages, mail, contacts, calendars, reminders, notes, photos, Safari, Google Chrome, and Mozilla Firefox.

DF205 Intermediate Digital Forensic Analysis: SQLite Primer

Mobile devices dominate the intake list, and the desks of most digital forensics analyst globally. Devices are becoming more secure, with an increase in security the need for detailed analysis is increasing as well. SQLite is a self-contained, serverless database engine. It is found on nearly every operating system and dominates iOS, Android, and macOS as one of the most prevalent and relevant data storage mechanisms. Rather than hope our forensic tools support the newest applications or be tethered to how a certain utility parses data we can arm ourselves with the skills and techniques needed to conquer the analysis of nearly any application.

What is SQLite and how to identify and analyze logically
Recognizing relevant locations of valuable data within SQLite database.
Develop skills needed for crafting custom SQLite queries.
Learn how to recognize and decode a variety of common timestamp formats.
Learn how to perform SQLite analysis with automation.

DF203 Intermediate Digital Forensic Analysis: Forensic Video Analysis

This course provides training on digital forensics for video, specifically targeting common file formats rather than proprietary video encodings or delivery methods. It aims to prepare investigators to answer critical questions about the file and ensure key evidence is not overlooked. This training is designed to support investigations by providing the necessary expertise to handle the complexities of video evidence in the digital age, addressing possible pitfalls including deepfakes, manipulated video, and potential overlooked evidence.

Key concepts covered in this course include:
Digital video file creation
Tool and result verification
Metadata and parsing
Image classification
Hash value comparison
Image/video classification and reporting results

IA102 Introduction to Link Analysis

This course introduces analysts to the broader concepts of connecting the dots through link analysis. A critical portion of conducting a successful analytical investigation is the ability to link together and understand the complexities of the connectedness between people and organizations. Introduction to Link Analysis (ILA) expands on the basic principles of link and association analyses explored in the Foundations of Intelligence Analysis Training (FIAT) while building a framework for more advanced methods such as social network analysis.

Expanding basic knowledge of link and association analysis
Explaining the process of social network analysis
Understanding the visual mapping and mathematical components associated with link and social network analyses

FC200 Intermediate Level Spreadsheeting Skills: Assessing and Organizing Data

This intermediate spreadsheeting course uses Microsoft Excel to assess and organize data in an electronic format. The class is designed for learners who have experience using Excel and who want to increase their spreadsheeting knowledge and skills. Topics include text functions, absolute referencing, date and time functions, flash fill, handling formula errors, VLOOKUP, dynamic arrays, and data validation. The course combines live demonstrations, instructor-led exercises, and independent student exercises.

IA102 Introduction to Link Analysis

This course introduces analysts to the broader concepts of connecting the dots through link analysis. A critical portion of conducting a successful analytical investigation is the ability to link together and understand the complexities of the connectedness between people and organizations. Introduction to Link Analysis (ILA) expands on the basic principles of link and association analyses explored in the Foundations of Intelligence Analysis Training (FIAT) while building a framework for more advanced methods such as social network analysis.

Expanding basic knowledge of link and association analysis
Explaining the process of social network analysis
Understanding the visual mapping and mathematical components associated with link and social network analyses

IA200 Intermediate Analytic Techniques

This course addresses key objectives focused on training intelligence analysts working at or towards the intermediate-level (practitioner and/or experienced analyst). This course expands upon core analytic fundamentals covered in NW3C's FIAT, ISIA, and IWAB offerings. The course begins with an in-depth case study to illustrate the complexities and challenges of a major case scenario for intelligence analysts. The course then examines key concepts related to analytic thinking, cognitive biases, structured analytic techniques, and effective time and project management. Finally, the course concludes with a section on addressing analytic uncertainty in intelligence writing. With guidance from experienced experts, students gain hands-on experience in the course with a complex practical case scenario that will challenge students on both days of the course.

Key concepts covered in this course include:
*Identifying cognitive biases
*Structured analytic techniques
*Project and time management
*Conveying uncertainty in intelligence writing

FC204 Combating Transnational Crime & Terrorism Financing

An effective financial investigation can disrupt terrorism organizations and interrupt, deter, or even stop operational terrorism activities before they can begin. In this three-day course, students develop an understanding of how financial systems are used to support terrorism activities and transnational criminal organizations. Students will work with tools and methods to investigate the manipulation of financial, communication, and business systems used for illicit purposes. Students will learn how to work with suspicious activity reports, crucial financial records such as Society for Worldwide Interbank Financial Telecommunications (SWIFT) messaging, and records used in banking and money services businesses. They will also learn how to gather information and evidence on other means of value transfer methods associated with money laundering, the black-market peso and forms of trade-based money laundering, hawala, and other alternate remittance systems, and virtual assets (cryptocurrency).

IA200 Intermediate Analytic Techniques

This course addresses key objectives focused on training intelligence analysts working at or towards the intermediate-level (practitioner and/or experienced analyst). This course expands upon core analytic fundamentals covered in NW3C's FIAT, ISIA, and IWAB offerings. The course begins with an in-depth case study to illustrate the complexities and challenges of a major case scenario for intelligence analysts. The course then examines key concepts related to analytic thinking, cognitive biases, structured analytic techniques, and effective time and project management. Finally, the course concludes with a section on addressing analytic uncertainty in intelligence writing. With guidance from experienced experts, students gain hands-on experience in the course with a complex practical case scenario that will challenge students on both days of the course.

Key concepts covered in this course include:
*Identifying cognitive biases
*Structured analytic techniques
*Project and time management
*Conveying uncertainty in intelligence writing

Digital Evidence Basics for Non-Technical Investigators

This is the replacement class for Securecube.

This course will familiarize Non-Technical Investigators related to the fundamentals of handling digital evidence which may present in the course of their investigations. The course will address the digital evidence source landscape, collection and preservation, examination and authentication, and considerations for managing third party sources. The student will receive a broad and balanced understanding of how digital evidence can enhance their investigations and the fundamentals of handling such evidence.

Presented by:
Jim Emerson, Vice President, High Tech Crimes, NW3C

Pages