Header-Banner

* Basic course
** Intermediate course
*** Advanced course

Coming soon… all labs and lectures will be ranked according to skill level as basic, intermediate, and advanced.
Tentative agenda — all tracks subject to change

SUNDAY | MONDAY | TUESDAY | WEDNESDAY  Printable View

 
Enterprise Lab
Forensics Lab
General Lab I
General Lab II
General Lab III
Fundamentals Lab
eDiscovery Track
Most Popular Lab Track
Lecture
Sunday, 4/27/08
3:00pm -
4:30pm

**
Detecting Malicious Code: The Next Generation of Physical Memory Analysis
- Rich Cummings, Jim Butterworth

VIEW DETAILS

**
How to Forensically Acquire Data Using Software and Hardware Write-block Solutions
- Chris Hapsas

VIEW DETAILS

*/**
MySpace® Investigations
- Frank Zellers

VIEW DETAILS

**
EnCE® Workshop
- Kirk Hunter

VIEW DETAILS

*
The Analysis-powered Internal Investigation: How Analytics Can Find the Smoking Gun
- Jason Reeve

VIEW DETAILS

*
Basic Investigator Skills: How to Not Spend Your Life Sorting Through Search Hits
- Matt McFadden

VIEW DETAILS

*
Introduction to EnCase eDiscovery Suite v3
- Brent Botta, Frank Lin

VIEW DETAILS

**
Essential Macintosh® Forensics - David York

VIEW DETAILS

*
The Etiquette of Being Deposed
- Andy Spruill

VIEW DETAILS

4:45pm - 6:00pm

**
Lose the GeekSpeak: Creating Client Friendly Forensic Reports
- Jerry Hatchett

VIEW DETAILS

*
Taking the Pain & Expense Out of In-House eDiscovery
- Cyndie Zikmund

VIEW DETAILS

*
Search Engine and Indexing
- Dominik Weber

VIEW DETAILS

**
Lessons Learned in E-Discovery and Corporate Investigations: A Panel Discussion

VIEW DETAILS

*
Forensic Investigation 101: Where to Start Looking -
Chris Hapsas

VIEW DETAILS

All Skill Levels
Developing an Effective Collection Strategy and Ensuring Your ESI is Admissible in Court
- Scott A. Carlson, Patrick E. Zeller

VIEW DETAILS

**
Email Investigations
- James Habben

VIEW DETAILS

*
Corporate Investigations in the 21st Century
- James Doyle

VIEW DETAILS

Monday, 4/28/08
7:30am - 8:50am

**
Mastering Conditions Enterprise
- Jon Stewart

VIEW DETAILS

***
How to Create and Perform Effective Keyword Searches (Advanced Searching)
- Daniel Smyth

VIEW DETAILS

**
Foreign Language Challenges
- Dominik Weber

VIEW DETAILS

* / **
First Looks at Windows® 2008 Server
- John Marsh

VIEW DETAILS

*
The Analysis-powered Internal Investigation: How Analytics Can Find the Smoking Gun
- Jason Reeve

VIEW DETAILS

**
Basic RAID Acquisition and Analysis
- Simon Key

VIEW DETAILS

**
Planning for eDiscovery: Requirements for a Successful Project
- Geoff Black, Brent Botta

VIEW DETAILS

*
iPhone® Forensics, New Handheld Devices, New Issues
- Amber Shroader

VIEW DETAILS

**
The Next Generation of Incident Response: Convergence of the Forensic Analyst and Incident Responder
- Jim Butterworth

VIEW DETAILS

9:00am - 10:00am
KEYNOTE - JIM LOVELL, COMMANDER OF THE APOLLO 13 MISSION
10:00am - 10:30am
EXHIBIT HALL REFRESHMENT BREAK
10:30am - 11:30am

**
Pre-incident Response Planning
- Benjamin Denkers

VIEW DETAILS

**
Using EnCase® Field Intelligence Model (FIM) Live Forensic Examinations
- Larry Sewell

VIEW DETAILS

**
CyberChild Exploitation - Part I: Investigations in the Workplace IT Focus (Lecure)
- Robert Monsour

VIEW DETAILS

***
How to Create and Perform Effective Keyword Searches (Advanced Searching)
- Daniel Smyth

VIEW DETAILS

** / ***
Best Practices Using the Clearwell® eDiscovery Platform
- Jason Reeve

VIEW DETAILS

*
Digital Forensic Triage
- Jennifer Hicks

VIEW DETAILS

All Skill Levels
Building a Successful Corporate Team and Partnership with IT & Legal
- Jack Halprin

VIEW DETAILS

***
Advanced Tips and Tricks of Forensics
- Chris Paven, Nick Ringold

VIEW DETAILS

***
Unpublished NTFS Forensic Artifacts
- Dominik Weber

VIEW DETAILS

11:45am - 12:45pm

* / **
Malware Analysis Workshop
- Yogesh Khatri

VIEW DETAILS

*
Super Basic Stuff: What you could do with EnScript
- James Habben

VIEW DETAILS

*
CyberChild Exploitation - Part II: Computer Forensics and Child Rescue, Law Enforcement Focus
- Matt McFadden

VIEW DETAILS

**
EnCE® Workshop
- Kirk Hunter

VIEW DETAILS

**
Lessons Learned in E-Discovery and Corporate Investigations -A Panel Discussion

VIEW DETAILS

*/**
MySpace® Investigations - Frank Zellers

VIEW DETAILS

All Skill Levels
The EDRM: Electronic Discovery Reference Model and the Future of eDiscovery
- George Socha, Tom Gelbman

VIEW DETAILS

*
Vista® Deep Dive I: Basic Investigations of Windows® Vista®
- Mike Fowler

VIEW DETAILS

*
What's Lurking in Your Enterprise
- Chet Hosmer

VIEW DETAILS

12:45pm - 2:00pm
LUNCH BREAK
Technology Forum-EnCase
2:00pm - 3:30pm

**
Covert Remote Examinations
- Walker Johnson

VIEW DETAILS

**
Mastering Conditions Forensics
- Jon Stewart

VIEW DETAILS

*
Network Forensics Techniques: How it Differs from Host Level Forensics
- MJ Staggs

VIEW DETAILS

*
Outsourcing Your Case: Real World Handling
- David Shin

VIEW DETAILS

**
Guidance EnCase eDiscovery® & the Clearwell® eDiscovery Platform: Real Cases from Identification to Review
- Jason Reeve

VIEW DETAILS

*
Introduction to Common File Systems and their Structure
- Larry Sewell

VIEW DETAILS

*
Condition Series, Part I: Understanding Conditions and How They Lead You to Success
- Brent Botta, Daniel Smyth

VIEW DETAILS

**
Vista® Deep Dive II: Bitlocker - Details and Forensic Considerations of Full Volume Encryption in Vista
- Mike Fowler

VIEW DETAILS

**
Forensic and Digital Investigations in EMEA
- Dr. Professor John Walker

VIEW DETAILS

3:30pm - 4:00pm
EXHIBIT HALL REFRESHMENT BREAK
4:00pm - 5:30pm

** / ***
Hacking Malware
- Yogesh Khatri

VIEW DETAILS

**
EnCase® Lab Edition
- Jason Frederickson

VIEW DETAILS

*
Imaging Macs® Without Macs
- Nicole Donnelly

VIEW DETAILS

**
File Identification and Recovery Using Block-Based Hash Analysis - Simon Key

VIEW DETAILS

** / ***
Best Practices Using the Clearwell® eDiscovery Platform
- Jason Reeve

VIEW DETAILS

* / **
LECTURE: "Policing the Internet" Making Online Investigations an Everyday Law Enforcement Task
- Todd Shipley, Bill Siebert

VIEW DETAILS

**
Condition Series, Part II: Advance Condition Utilization
- Brent Botta, Daniel Smyth

VIEW DETAILS

***
File and Registry Virtualization: A Look at how Vista's use of Virtualization may Impact your Investigation
- John Marsh

VIEW DETAILS

*
GPS Forensics
- Amber Schroader

VIEW DETAILS

Tuesday, 4/29/08
7:00am - 8:30am

*
EnCase® Data Audit and Policy Enforcement
- Gus Quiroga

VIEW DETAILS

***
Learning to Love the Records Pane
- Jon Stewart

VIEW DETAILS

All Skill Levels
What to Do When All Hope is Gone: Acquiring Data Off a Dead Drive
- John Weichman, Eddie Weichman

VIEW DETAILS

**
Defeating Advanced Hiding Techniques
- Dave Shaver

VIEW DETAILS

**
Guidance EnCase eDiscovery® & the Clearwell® eDiscovery Platform: Real Cases from Identification to Review
- Jason Reeve

VIEW DETAILS

*
Case Study Firefox® Artifacts and Unallocated Space
- Brent Duckworth, Salvatore Montemarano

VIEW DETAILS

***
LAB: Strategy for Creation of Filtering Criteria for Collection and Processing of ESI
- Brent Botta, Geoff Black

VIEW DETAILS

**
Examining the Windows® Registry
- Dan Purcell

VIEW DETAILS

**
Case Studies of Botnet Infection, Propagation and Control
- MJ Staggs

VIEW DETAILS

8:45am - 10:00am

User Traffic Analysis: How to Look at a Live Environment - Jim Butterworth

VIEW DETAILS

**
Timeline Analysis
- Kirk Hunter

VIEW DETAILS

** / ***
Hacking Malware - Yogesh Khatri

VIEW DETAILS

*
EDS/Encryption
- Dominik Weber

VIEW DETAILS

**
File Identification and Recovery Using Block-Based Hash Analysis - Simon Key

VIEW DETAILS

**
Information Gathering and Data Correlation
- Chris Pavan & Nick Ringoldd

VIEW DETAILS

**
Building an In-house eDiscovery Process: How to Approach the Challenges of eDiscovery
- Scott Steiner

VIEW DETAILS

*
Condition Series, Part I: Understanding conditions and how they lead you to Success
- Brent Botta, Daniel Smyth

VIEW DETAILS

**
Creating Total Visibility by Linking Network and Host Forensics
- Edward Schwartz

VIEW DETAILS

10:00am - 10:30am
EXHIBIT HALL REFRESHMENT BREAK
10:30am - 11:30am

**
Large-scale EnCase® Enterprise Development Best Practices
- Daniel Smyth

VIEW DETAILS

**
Essential Macintosh® Forensics
- David York

VIEW DETAILS

***
Automating Event Log Forensics
- Dr. Rich Murphey

VIEW DETAILS

***
How to Spot Packet Forgeries and Spoofing
- MJ Staggs

VIEW DETAILS

**
Cell Phone Forensics
- Brad Montgomery

VIEW DETAILS

**
Email Lab: What you Can Do With Gmail
- James Habben

VIEW DETAILS

All Skill Levels
International eDiscovery/ eDisclosure: The Asia-Pacific, European Union and United Kingdom Comparative
- Seamus Byrne

VIEW DETAILS

**
Defeating Advanced Hiding Techniques
- Dave Shaver

VIEW DETAILS

*
e-Admissibility: The Intersection of Technology and Pretrial Civil Litigation
- Joshua Gilliland

VIEW DETAILS

11:45am - 12:45pm

*
Conducting Enterprise Investigations
- Scott Steiner

VIEW DETAILS

***
Advanced Tips and Tricks of Forensics
- Chris Pavan & Nick Ringold

VIEW DETAILS

Authenticated Whitelisting and Software Reputation: Information Assurance and Desktop Lockdown - Doug Cahill

VIEW DETAILS

*
Vista® Deep Dive I: Basic Investigations of Windows® Vista®
- Mike Fowler

VIEW DETAILS

***
EnScript Part I: Using Projects and the DeBugger
- Shawn McCreight

VIEW DETAILS

*
What Every Investigator Needs to Know About Creating a Forensic Report
- Dan Purcell

VIEW DETAILS

All Skill Levels
A Review of the Rules, Cases & Regulations for eDiscovery - 17 Months after the Federal Rules Updates
- Patrick E. Zeller

VIEW DETAILS

***
Anti (Computer) Forensics: Is There Such a Thing?
- Scott Mann

VIEW DETAILS

***
Mystery Slot: Never Before Released Material
- Dominik Weber

VIEW DETAILS

12:45pm - 2:00pm
LUNCH
2:00pm - 3:30pm

**
Detecting Malicious Code: The Next Generation of Physical Memory Analysis
- Rich Cummings, Jim Butterworth

VIEW DETAILS

***
Advanced RAID Analysis
- Howard Williamson

VIEW DETAILS

***
Technical Profiling for Law Enforcement and Intelligence
- Christopher Jones

VIEW DETAILS

**
Vista® Deep Dive II: Bitlocker-Details and Forensic Considerations of Full Volume Encryption in Vista®
- Mike Fowler

VIEW DETAILS

***
Anti (Computer) Forensics: Is There Such a Thing?
- Scott Mann

VIEW DETAILS

**
The Process of Peer Review
- Chris Pavan, Nick Ringold

VIEW DETAILS

**
LAB: Processing and Reporting of ESI After Collection Utilizing Filtering Criteria to Produce Deliverables
- Daniel Smyth

VIEW DETAILS

*
Network Forensics Techniques - How it Differs from Host Level Forensics
- MJ Staggs

VIEW DETAILS

*
eCrime and Steganography
- Chet Hosmer

VIEW DETAILS

3:30pm - 4:00pm
EXHIBIT HALL REFRESHMENT BREAK
4:00pm - 5:30pm

**
The Use of Forensics in eDiscovery
- Greg Kelley

VIEW DETAILS

*
State of the Art Forensics Lab
- Keith Foggon

VIEW DETAILS

***
Vista® Deep Dive III: File and Registry Virtualization: A Look at how Vista's use of Virtualization may Impact your Investigation
- John Marsh

VIEW DETAILS

***
EnScript Part II: Creating Plugins
- Shawn McCreight

VIEW DETAILS

**
Email Investigations
- James Habben

VIEW DETAILS

**
eDiscovery Workshop: Collection and Processing Strategies for Email
- Geoff Black

VIEW DETAILS

* / **
Malware Analysis Workshop
- Yogesh Khatri

VIEW DETAIL

**
Hardware Write Blocking Best Practices
- Greg Dominguez

VIEW DETAILS

Wednesday, 4/30/08
8:00am - 9:30am

*
EnCase® Information Assurance
- Gus Quiroga

VIEW DETAILS

**
Examining the Windows® Registry
- Dan Purcell

VIEW DETAILS

*
iPhone® Forensics, New Handheld Devices, New Issues
- Amber Shroader

VIEW DETAILS

*
Social Hacking
- Dr. William Figg

VIEW DETAILS

***
Advanced EnScript® Programming Techniques
- Howard Williamson

VIEW DETAILS

**
Malicious Artifact Identification and Analysis
- Jim Butterworth

VIEW DETAILS

All Skill Levels
A Strategic Business Approach to eDiscovery: The Convergence of Technology, Law and Information Security
- John Patzakis

VIEW DETAILS

 

**
Accelerating Incident Response With Network Forensics Techniques
- Edward Schwartz

VIEW DETAILS

9:45am - 11:00am

*
EnCase® Lab Edition
- Jason Frederickson

VIEW DETAILS

*
Roundtable Discussion: Digital Forensics in the Classroom
- Andy Spruill

VIEW DETAILS

**
Redacting Information from Digital Devices
- Dr. Gavin Manes

VIEW DETAILS

"Live" Malware Analysis for the Incident Responder and Corporate Information Security Professional - Rich Cummings

VIEW DETAILS

***
EnScript Part III: Creating Packages and Licenses
- Shawn McCreight

VIEW DETAILS

***
Advanced Remote Forensics: Full Speed Imaging and Analysis of remote systems without a Corporate LAN
- Andrew Sheldon

VIEW DETAILS

All Skill Levels
EnCase eDiscovery Roadmap & The Future of eDiscovery
- Jack Halprin

VIEW DETAILS

 

*
The Future of EnCase Software
- Gary Ulaner

VIEW DETAILS