Coming soon… all labs and lectures will be ranked according to skill level as basic, intermediate, and advanced.
Tentative agenda — all tracks subject to change
| |
Enterprise Lab |
Forensics Lab |
General Lab I |
General Lab II |
General Lab III |
Fundamentals Lab |
eDiscovery Track |
Most Popular Lab Track |
Lecture |
|
3:00pm -
4:30pm |
**
Detecting Malicious Code: The Next Generation of Physical Memory Analysis - Rich Cummings, Jim Butterworth
VIEW DETAILS |
**
How to Forensically Acquire Data Using Software and Hardware Write-block Solutions - Chris Hapsas
VIEW DETAILS |
*/**
MySpace® Investigations - Frank Zellers
VIEW DETAILS |
**
EnCE® Workshop - Kirk Hunter
VIEW DETAILS |
*
The Analysis-powered Internal Investigation: How Analytics Can Find the Smoking Gun - Jason Reeve
VIEW DETAILS |
*
Basic Investigator Skills: How to Not Spend Your Life Sorting Through Search Hits - Matt McFadden
VIEW DETAILS |
*
Introduction to EnCase eDiscovery Suite v3 - Brent Botta, Frank Lin
VIEW DETAILS |
**
Essential Macintosh® Forensics - David York
VIEW DETAILS |
*
The Etiquette of Being Deposed - Andy Spruill
VIEW DETAILS |
4:45pm - 6:00pm |
**
Lose the GeekSpeak: Creating Client Friendly Forensic Reports - Jerry Hatchett
VIEW DETAILS |
*
Taking the Pain & Expense Out of In-House eDiscovery - Cyndie Zikmund
VIEW DETAILS |
*
Search Engine and Indexing - Dominik Weber
VIEW DETAILS |
**
Lessons Learned in E-Discovery and Corporate Investigations: A Panel Discussion
VIEW DETAILS |
*
Forensic Investigation 101: Where to Start Looking - Chris Hapsas
VIEW DETAILS |
All Skill Levels
Developing an Effective Collection Strategy and Ensuring Your ESI is Admissible in Court - Scott A. Carlson, Patrick E. Zeller
VIEW DETAILS |
**
Email Investigations - James Habben
VIEW DETAILS |
*
Corporate Investigations in the 21st Century - James Doyle
VIEW DETAILS |
|
7:30am - 8:50am |
**
Mastering Conditions Enterprise - Jon Stewart
VIEW DETAILS |
***
How to Create and Perform Effective Keyword Searches (Advanced Searching) - Daniel Smyth
VIEW DETAILS |
**
Foreign Language Challenges - Dominik Weber
VIEW DETAILS |
* / **
First Looks at Windows® 2008 Server - John Marsh
VIEW DETAILS |
*
The Analysis-powered Internal Investigation: How Analytics Can Find the Smoking Gun - Jason Reeve
VIEW DETAILS |
**
Basic RAID Acquisition and Analysis - Simon Key
VIEW DETAILS |
**
Planning for eDiscovery: Requirements for a Successful Project - Geoff Black, Brent Botta
VIEW DETAILS |
*
iPhone® Forensics, New Handheld Devices, New Issues - Amber Shroader
VIEW DETAILS |
**
The Next Generation of Incident Response: Convergence of the Forensic Analyst and Incident Responder - Jim Butterworth
VIEW DETAILS |
9:00am - 10:00am |
KEYNOTE - JIM LOVELL, COMMANDER OF THE APOLLO 13 MISSION |
10:00am - 10:30am |
EXHIBIT HALL REFRESHMENT BREAK |
10:30am - 11:30am |
**
Pre-incident Response Planning - Benjamin Denkers
VIEW DETAILS |
**
Using EnCase® Field Intelligence Model (FIM) Live Forensic Examinations - Larry Sewell
VIEW DETAILS |
**
CyberChild Exploitation - Part I: Investigations in the Workplace IT Focus (Lecure) - Robert Monsour
VIEW DETAILS |
***
How to Create and Perform Effective Keyword Searches (Advanced Searching)
- Daniel Smyth
VIEW DETAILS |
** / ***
Best Practices Using the Clearwell® eDiscovery Platform - Jason Reeve
VIEW DETAILS |
*
Digital Forensic Triage - Jennifer Hicks
VIEW DETAILS |
All Skill Levels
Building a Successful Corporate Team and Partnership with IT & Legal - Jack Halprin
VIEW DETAILS |
***
Advanced Tips and Tricks of Forensics
- Chris Paven, Nick Ringold
VIEW DETAILS |
***
Unpublished NTFS Forensic Artifacts - Dominik Weber
VIEW DETAILS |
11:45am - 12:45pm |
* / **
Malware Analysis Workshop - Yogesh Khatri
VIEW DETAILS |
*
Super Basic Stuff: What you could do with EnScript - James Habben
VIEW DETAILS |
*
CyberChild Exploitation - Part II: Computer Forensics and Child Rescue, Law Enforcement Focus - Matt McFadden
VIEW DETAILS |
**
EnCE® Workshop - Kirk Hunter
VIEW DETAILS |
**
Lessons Learned in E-Discovery and Corporate Investigations -A Panel Discussion
VIEW DETAILS |
*/**
MySpace® Investigations - Frank Zellers
VIEW DETAILS |
All Skill Levels
The EDRM: Electronic Discovery Reference Model and the Future of eDiscovery - George Socha, Tom Gelbman
VIEW DETAILS |
*
Vista® Deep Dive I: Basic Investigations of Windows® Vista® - Mike Fowler
VIEW DETAILS |
*
What's Lurking in Your Enterprise - Chet Hosmer
VIEW DETAILS |
12:45pm - 2:00pm |
LUNCH BREAK |
| Technology Forum-EnCase |
2:00pm - 3:30pm |
**
Covert Remote Examinations - Walker Johnson
VIEW DETAILS |
**
Mastering Conditions Forensics - Jon Stewart
VIEW DETAILS |
*
Network Forensics Techniques: How it Differs from Host Level Forensics - MJ Staggs
VIEW DETAILS |
*
Outsourcing Your Case: Real World Handling - David Shin
VIEW DETAILS |
**
Guidance EnCase eDiscovery® & the Clearwell® eDiscovery Platform: Real Cases from Identification to Review - Jason Reeve
VIEW DETAILS |
*
Introduction to Common File Systems and their Structure - Larry Sewell
VIEW DETAILS |
*
Condition Series, Part I: Understanding Conditions and How They Lead You to Success - Brent Botta, Daniel Smyth
VIEW DETAILS |
**
Vista® Deep Dive II: Bitlocker - Details and Forensic Considerations of Full Volume Encryption in Vista
- Mike Fowler
VIEW DETAILS |
**
Forensic and Digital Investigations in EMEA - Dr. Professor John Walker
VIEW DETAILS |
3:30pm - 4:00pm |
EXHIBIT HALL REFRESHMENT BREAK |
4:00pm - 5:30pm |
** / ***
Hacking Malware - Yogesh Khatri
VIEW DETAILS |
**
EnCase® Lab Edition - Jason Frederickson
VIEW DETAILS |
*
Imaging Macs® Without Macs - Nicole Donnelly
VIEW DETAILS |
**
File Identification and Recovery Using Block-Based Hash Analysis - Simon Key
VIEW DETAILS |
** / ***
Best Practices Using the Clearwell® eDiscovery Platform - Jason Reeve
VIEW DETAILS |
* / **
LECTURE: "Policing the Internet" Making Online Investigations an Everyday Law Enforcement Task - Todd Shipley, Bill Siebert
VIEW DETAILS |
**
Condition Series, Part II: Advance Condition Utilization - Brent Botta, Daniel Smyth
VIEW DETAILS |
***
File and Registry Virtualization: A Look at how Vista's use of Virtualization may Impact your Investigation - John Marsh
VIEW DETAILS |
*
GPS Forensics - Amber Schroader
VIEW DETAILS |
|
7:00am - 8:30am |
*
EnCase® Data Audit and Policy Enforcement - Gus Quiroga
VIEW DETAILS |
***
Learning to Love the Records Pane - Jon Stewart
VIEW DETAILS |
All Skill Levels
What to Do When All Hope is Gone: Acquiring Data Off a Dead Drive - John Weichman, Eddie Weichman
VIEW DETAILS |
**
Defeating Advanced Hiding Techniques - Dave Shaver
VIEW DETAILS |
**
Guidance EnCase eDiscovery® & the Clearwell® eDiscovery Platform: Real Cases from Identification to Review - Jason Reeve
VIEW DETAILS |
*
Case Study Firefox® Artifacts and Unallocated Space - Brent Duckworth, Salvatore Montemarano
VIEW DETAILS |
***
LAB: Strategy for Creation of Filtering Criteria for Collection and Processing of ESI - Brent Botta, Geoff Black
VIEW DETAILS |
**
Examining the Windows® Registry - Dan Purcell
VIEW DETAILS |
**
Case Studies of Botnet Infection, Propagation and Control - MJ Staggs
VIEW DETAILS |
8:45am - 10:00am |
User Traffic Analysis: How to Look at a Live Environment - Jim Butterworth
VIEW DETAILS |
**
Timeline Analysis - Kirk Hunter
VIEW DETAILS |
** / ***
Hacking Malware - Yogesh Khatri
VIEW DETAILS |
*
EDS/Encryption - Dominik Weber
VIEW DETAILS |
**
File Identification and Recovery Using Block-Based Hash Analysis - Simon Key
VIEW DETAILS |
**
Information Gathering and Data Correlation - Chris Pavan & Nick Ringoldd
VIEW DETAILS |
**
Building an In-house eDiscovery Process: How to Approach the Challenges of eDiscovery - Scott Steiner
VIEW DETAILS |
*
Condition Series, Part I: Understanding conditions and how they lead you to Success
- Brent Botta, Daniel Smyth
VIEW DETAILS |
**
Creating Total Visibility by Linking Network and Host Forensics - Edward Schwartz
VIEW DETAILS |
10:00am - 10:30am |
EXHIBIT HALL REFRESHMENT BREAK |
10:30am - 11:30am |
**
Large-scale EnCase® Enterprise Development Best Practices - Daniel Smyth
VIEW DETAILS |
**
Essential Macintosh® Forensics - David York
VIEW DETAILS |
***
Automating Event Log Forensics - Dr. Rich Murphey
VIEW DETAILS |
***
How to Spot Packet Forgeries and Spoofing - MJ Staggs
VIEW DETAILS |
**
Cell Phone Forensics - Brad Montgomery
VIEW DETAILS |
**
Email Lab: What you Can Do With Gmail - James Habben
VIEW DETAILS |
All Skill Levels
International eDiscovery/ eDisclosure: The Asia-Pacific, European Union and United Kingdom Comparative - Seamus Byrne
VIEW DETAILS |
**
Defeating Advanced Hiding Techniques
- Dave Shaver
VIEW DETAILS |
*
e-Admissibility: The Intersection of Technology and Pretrial Civil Litigation - Joshua Gilliland
VIEW DETAILS |
11:45am - 12:45pm |
*
Conducting Enterprise Investigations - Scott Steiner
VIEW DETAILS |
***
Advanced Tips and Tricks of Forensics - Chris Pavan & Nick Ringold
VIEW DETAILS |
Authenticated Whitelisting and Software Reputation: Information Assurance and Desktop Lockdown - Doug Cahill
VIEW DETAILS |
*
Vista® Deep Dive I: Basic Investigations of Windows® Vista® - Mike Fowler
VIEW DETAILS |
***
EnScript Part I: Using Projects and the DeBugger - Shawn McCreight
VIEW DETAILS |
*
What Every Investigator Needs to Know About Creating a Forensic Report - Dan Purcell
VIEW DETAILS |
All Skill Levels
A Review of the Rules, Cases & Regulations for eDiscovery - 17 Months after the Federal Rules Updates - Patrick E. Zeller
VIEW DETAILS |
***
Anti (Computer) Forensics: Is There Such a Thing?
- Scott Mann
VIEW DETAILS |
***
Mystery Slot: Never Before Released Material - Dominik Weber
VIEW DETAILS |
12:45pm - 2:00pm |
LUNCH |
2:00pm - 3:30pm |
**
Detecting Malicious Code: The Next Generation of Physical Memory Analysis - Rich Cummings, Jim Butterworth
VIEW DETAILS |
***
Advanced RAID Analysis - Howard Williamson
VIEW DETAILS |
***
Technical Profiling for Law Enforcement and Intelligence - Christopher Jones
VIEW DETAILS |
**
Vista® Deep Dive II: Bitlocker-Details and Forensic Considerations of Full Volume Encryption in Vista® - Mike Fowler
VIEW DETAILS |
***
Anti (Computer) Forensics: Is There Such a Thing? - Scott Mann
VIEW DETAILS |
**
The Process of Peer Review - Chris Pavan, Nick Ringold
VIEW DETAILS |
**
LAB: Processing and Reporting of ESI After Collection Utilizing Filtering Criteria to Produce Deliverables - Daniel Smyth
VIEW DETAILS |
*
Network Forensics Techniques - How it Differs from Host Level Forensics - MJ Staggs
VIEW DETAILS |
*
eCrime and Steganography - Chet Hosmer
VIEW DETAILS |
3:30pm - 4:00pm |
EXHIBIT HALL REFRESHMENT BREAK |
4:00pm - 5:30pm |
**
The Use of Forensics in eDiscovery - Greg Kelley
VIEW DETAILS |
*
State of the Art Forensics Lab - Keith Foggon
VIEW DETAILS |
***
Vista® Deep Dive III: File and Registry Virtualization: A Look at how Vista's use of Virtualization may Impact your Investigation - John Marsh
VIEW DETAILS |
***
EnScript Part II: Creating Plugins - Shawn McCreight
VIEW DETAILS |
**
Email Investigations - James Habben
VIEW DETAILS |
**
eDiscovery Workshop: Collection and Processing Strategies for Email - Geoff Black
VIEW DETAILS |
* / **
Malware Analysis Workshop - Yogesh Khatri
VIEW DETAIL
|
**
Hardware Write Blocking Best Practices - Greg Dominguez
VIEW DETAILS |
|
8:00am - 9:30am |
*
EnCase® Information Assurance - Gus Quiroga
VIEW DETAILS |
**
Examining the Windows® Registry - Dan Purcell
VIEW DETAILS |
*
iPhone® Forensics, New Handheld Devices, New Issues - Amber Shroader
VIEW DETAILS |
*
Social Hacking - Dr. William Figg
VIEW DETAILS |
***
Advanced EnScript® Programming Techniques - Howard Williamson
VIEW DETAILS |
**
Malicious Artifact Identification and Analysis - Jim Butterworth
VIEW DETAILS |
All Skill Levels
A Strategic Business Approach to eDiscovery: The Convergence of Technology, Law and Information Security - John Patzakis
VIEW DETAILS |
|
**
Accelerating Incident Response With Network Forensics Techniques - Edward Schwartz
VIEW DETAILS |
9:45am - 11:00am |
*
EnCase® Lab Edition - Jason Frederickson
VIEW DETAILS |
*
Roundtable Discussion: Digital Forensics in the Classroom - Andy Spruill
VIEW DETAILS |
**
Redacting Information from Digital Devices - Dr. Gavin Manes
VIEW DETAILS |
"Live" Malware Analysis for the Incident Responder and Corporate Information Security Professional - Rich Cummings
VIEW DETAILS |
***
EnScript Part III: Creating Packages and Licenses - Shawn McCreight
VIEW DETAILS |
***
Advanced Remote Forensics: Full Speed Imaging and Analysis of remote systems without a Corporate LAN - Andrew Sheldon
VIEW DETAILS |
All Skill Levels
EnCase eDiscovery Roadmap & The Future of eDiscovery - Jack Halprin
VIEW DETAILS |
|
*
The Future of EnCase Software - Gary Ulaner
VIEW DETAILS |