DF410 - NTFS Examinations with EnCase

Have questions about training?   Contact us

Duration: 4 Days

This hands-on course involves technical information and practical exercises about the NT File System (NTFS). The class addresses the technical aspects of NTFS, including an in-depth analysis of the Master File Table ($MFT) and its components. Students will locate and recover valuable NTFS artifacts and understand their evidentiary value. The structure of the NTFS directory will be examined and parsed. Students will recover encrypted passwords, identify alternate data streams, identify security permissions for users, and determine if other storage media was connected to an NTFS volume through reparse points. In addition, students will examine a partially wiped drive and recover files from the partially wiped NTFS volume using their new knowledge and skills.

Delivery method: Group-Live. NASBA defined level: advanced

CPE Credits - 32


This course is intended for law enforcement officers, computer forensic examiners, corporate and private investigators, and network security personnel. A basic understanding of the concepts of computer forensics and Internet-related access is required. The class curriculum builds upon the foundation of the EnCase® Computer Forensics II course, continuing with a focus on NTFS file system examinations.


DF210 - Building an Investigation with EnCase or EnCE Certification. Advance preparation for this course is not required.


The meaning and relevance of the artifacts that administratively document NTFS are emphasized.

The course provides in-depth coverage on artifacts, including:

  • Components of the NTFS Volume Boot Record and the Master File Table
  • Definitions and purpose of NTFS internal system files
  • Characteristics and storage of NTFS resident and non-resident attributes
  • Storage of alternate data streams and reparse points
  • Addressing NTFS user account information, encryption and file system security
  • Resolving Windows® Vista operating system symbolic links
  • Linking media to a NTFS volume
  • Addressing technical issues associated with NTFS
  • Advanced NTFS data recovery

 Course Syllabus


Format Currency Price
Per Student at OpenText Site €  2,395.47 
Per Student at OpenText Site GBP  2,030.60 
Per Student at OpenText Site USD  2,750.00 

Taxes: All prices exclude VAT or other taxes where applicable (all currencies).

Extra expenses: Customer site course prices do not include instructor travel expenses, which are billed separately.

Reservations: Please provide a minimum of 3 weeks advance notice when arranging courses at customer sites.

Course & Workshop Calendar

Below is a listing of all the currently available dates and locations for this course or workshop from OpenText.

To register, please select the course you want to attend by clicking the "Add to cart" button.

Date Course type Course name Language Location Price Add
Oct 01, 2019  On-site  DF410 - NTFS Examinations  English  Virtual Classroom - Europe GSI UK Time 2,030.60  Add to cart
Oct 01, 2019  On-site  DF410 - NTFS Examinations  English  GSI-Reading, UK 2,030.60  Add to cart
Oct 15, 2019  On-site  DF410 - NTFS Examinations  English  GSI-Pasadena, CA 2,750.00  Add to cart