Call Us 0800 540 161
Call Us 0800 540 161
This course is presented as Live Virtual Training. Click for more details.

Presented in association with Cyber Digital Forensics Services (CDFS)


This course is focused on the systematic and efficient examination of computer media using the integrated computer forensics software X-Ways Forensics.

It provides a complete and systematic coverage of all computer forensics features in WinHex and X-Ways Forensics. Hands-on exercises, simulating most aspects of the complete computer forensics process. Attendees are encouraged to immediately try newly gained insights as provided by the instructor, with sample image files. Many topics are explained along with their theoretical background (slack: beyond the usual, how hash databases are internally structured, how deleted partitions are found automatically, with what methods X-Ways Forensics finds deleted files). Other topics are forensically sound disk imaging and cloning, data recovery, search functions, dynamic filtering, report creation. Emphasis can be put on any aspect suggested by the participants. You will receive reference training material for later repetition.

Prerequisite: basic knowledge of computer forensics.

Learning outcomes

Participants will learn how to get the most thorough overview conceivable of existing and deleted files on computer media, how to scan for child pornography in the most efficient way, or how to manually recover deleted files compressed by NTFS which would not even be found by conventional file carving techniques.

Who should attend

This course is intended for anyone who needs to master X-Ways Forensics.

Course contents

  • Slack: beyond the usual
  • Hash databases
  • Deleted partitions
  • Forensically sound disk imaging
  • Cloning
  • Data recovery
  • Search functions
  • Dynamic filtering
  • Report creation

Course fees

The fee for the course is:

  • $4,120 + GST