December 12 - 14, 2005
Download the printable Registration Form in Adobe PDF format.
Course Description:
This course provides basic information to the street-level investigator and search personnel in the proper procedures for seizing computer systems used in the commission of a crime. It explains the special needs of the field examiner or forensic expert and includes some legal issues such as probable cause and evidence preservation peculiar to seizing computer systems. The course is a prelude to forensic instruction on retrieving or recovering data from the system.
| Duration: | 3 days (24 hours) |
| Prerequisites: | See Description |
| Lead Instructor: | Mark M. Pollitt |
Course Objectives:
Upon completion of this course, the officer will be able to explain how computers, the internet and digital storage media can be utilized in criminal activity. The officer will be able to identify a variety of computers, network equipment and digital storage devices which may be encountered in connection with criminal investigations. The officer will be able to correctly draft a search warrant affidavit to seize digital evidence. The officer will be able to correctly plan and execute a search warrant for digital evidence including: a search plan, initial entry, survey, site documentation, interviews, computer system documentation, searches for computer related computer information, photographing computer systems, securing computer systems and storage media, packaging, storage and transportation of digital evidence. The officer will be able to explain the roles, responsibilities and limitations of computer forensic examiners, analysts and investigators.
Course Materials:
| Morning Session | Afternoon Session | |
|---|---|---|
| Dec 12 | Course introduction Introduction to computer forensics Legal Issues Introduction to computers and networks |
Internet and evidence Computer and hardware lab Drafting affidavits |
| Dec 13 | Review of draft affidavits Introduction to Operating Systems Interviewing for computer searches Mock interviews |
Computer search planning Operations orders and checklists Search execution Packing, transporting and Storage of digital evidence |
| Dec 14 | Mock Computer Search Warrant |
Examiner/Investigator relationships Testimony Moot Court Demo Assessment test |