Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | Ramblings

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password

X-Ways Forensics Practitioner's Guide

Subscribe to this list via RSS
DEC
21
0

Reminder for the last discount for the X-Ways Forensics Practitioner’s Guide Online and On demand course.

Posted by Brett Shavers
in  Digital Forensics Books

If you were thinking of doing it, this is the best time since the $599 online course will only be at a discount of 60% for less than two weeks (until Dec 31, 2016) for only $235.  PLUS, registering before December 31, 2016 gets you a print copy of the book, the X-Ways Forensics Practitioner’s Guide shipped to you. Unfortunately, the book is only included for US/Canada registrants since shipping a book outside the USA or Canada costs more than the book.  Shipping to some countries costs more than the entire X-Ways online course costs.  I’m happy to ship a copy, but the shipping fees must be added.  Best bet is to order a book online that delivers locally without extreme duty fees.

Register with the 60% discount using this URL: http://bit.ly/xwfpromo 

Just a few notes on the online XWF course based on emails I have received:

Time limit:  You have a year to view the course as often as you want.

Software: Not included.  You don’t need it for the course, but I think you’ll want to have a license.  If you want to know how XWF compares to other tools, you can get 12 hours of instruction showing how it works and much of what it can do.  Once you start using XWF, you’ll begin to see that it can do a lot more than what the manual or any course can teach. 

About forensics: The online course doesn’t teach forensics, except to demonstrate features of XWF.  Don't expect to learn 'what is the registry' in this course.  It's all about X-Ways Forensics, to get you up and running right away.

Competence: If you go through this course (and you have a foundation of digital forensics knowledge), you’ll have enough knowledge to use XWF on a real case.

Students: If your school uses XWF, you’ll be much better off learning XWF online away from class to get the full benefit of using XWF.   School programs can only teach so much with software in courses where they must teach everything.

The book:  Through Dec 31, 2016 the X-Ways Forensics Practitioner’s Guide book (print copy) is included with your tuition (USA/Canada shipping only).   There is no other book on X-Ways Forensics available.  The next edition may not be for another year or two.  Get your copy as part of the course.  The cost savings of a book + 12 hours of X-Ways Forensics training at $235 is the best deal you can find anywhere.

Course updates: The course may be updated throughout the year when XWF has enough smaller updates to add up to a new course or updated lessons.  You get that as part of your registration.  Revisit the course throughout the year, anytime you want, from anywhere online.

XWF as a primary or other forensic tool:  If you currently use or plan to use XWF in your work, get some training.  Either this course or a course from X-Ways AG, or somewhere.  XWF is not a tool for self-learning when you need it for casework tomorrow.  Especially for a primary tool, get some training.  This course gives you the information to use it either as your primary tool or secondary tool.

If you have any questions, hit me up J

This email address is being protected from spambots. You need JavaScript enabled to view it.

 

0
  4375 Hits
Tags:
X-Ways Forensics Practitioner's Guide X-Ways Forensics
Tweet
Share on Pinterest
4375 Hits
OCT
25
2

X-Ways Forensics Sucks….

Posted by Brett Shavers
in  Digital Forensics

…only with decryption, and even at that, it does everything else superbly.

I probably caught your attention if you are an X-Ways Forensics user.  The only thing that sucks about X-Ways Forensics is that it doesn’t do encryption.  By “doing encryption”, I mean that it doesn’t decrypt encrypted files or systems.  Besides that one aspect of forensic work, X-Ways Forensics rules.

**UPDATED X-WAYS FORENSICS PRACTITIONER’S GUIDE ONLINE COURSE**

I completely updated and extended an online course based on my book, the “X-Ways Forensics Practitioner’s Guide”.  It has taken some time to create a course that has 95% of what you need to use X-Ways Forensics without being an overly long instruction of the software.  The remaining 5% changes every week or so with new features and updates added by X-Ways.  This course covers X-Ways Forensics up to version 19, but know that X-Ways will be adding new features every week that aren’t included in this course yet.  After enough ‘little’ features and improvements have been added, more content to the course will be added as well.

Here is the gist of this post

Register before November 8, 2016 to get both 50% off tuition and a printed copy of the X-Ways Forensics Practitioner’s Guide.  Use this link for the discount: http://courses.dfironlinetraining.com/x-ways-forensics-practitioners-guide-online-and-on-demand-course?pc=blog

Personal anecdote: While sitting in BCERT at FLETC years ago, I brought my trust X-Ways Forensics v13 to class.  FLETC issued FTK and Encase as the forensic suites during this time, and also issued a license for WinHex. The Winhex instruction was probably 30 minutes long.

I had already been using X-Ways Forensics and the FLETC instructors allowed me to use my license alongside their issued tools.  With a FLETC provided image that was given to every student in the course, X-Ways data carved hundreds of pornography pictures from my image while both FTK and Encase did not.  The instructors thought I had been surfing porn in class until I carved from someone else’s image.  Encase and FTK, for some reason, did not carve up the pictures that X-Ways did.  In about 5 minutes after seeing that X-Ways carved up porn that other tools missed, every image was collected from class by the instructors….

I emailed Stefan Fleischmann of X-Ways during lunch to let him know that his X-Ways Forensics program works pretty good.

My personal experience with X-Ways Forensics started because I was a curious about a ‘new’ forensic program based off of Winhex. I only tried X-Ways Forensics because (1) it was cheaper than anything else, (2) looked kinda cool, (3) and got deep into the actual files like a hex editor.  However, I tried to figure it out and the best way to do that was to host a course.  The only reason I gave X-Ways Forensics a chance was because X-Ways agreed to give a training course in Seattle if I would arrange it, their first course ever.  After seeing how X-Ways worked in that one course, I was hooked using X-Ways Forensics as my primary forensic tool for well over a decade.

I have met many examiners who have tried to use X-Ways Forensics and have nearly always gone back to their other tools, like Encase or FTK.  Mostly, I see this to be because of fear of change and lack of information to use X-Ways Forensics.  There were no books about X-Ways Forensics.  The manual was (is) clearly lacking in giving instruction in using X-Ways, the courses were (are) expensive and not typically where you’d like them to be.  Compared to Encase, as one example, books on using Encase have been around for some time, Encase has been taught in government forensic courses for well over a decade, and courses have been planted everywhere around the world for so long that it seems strange to not have a course local to you every year or so.  Plus, the other tools throw parties, like huge beer fests poolside in Vegas or somewhere neat.  X-Ways? No parties.  No beer fests.  It’s all down and dirty with hex, which is just the way I like it.

The manner in which this online course works is similar to the book that Eric Zimmerman and I wrote on X-Ways Forensics.  We wrote, and titled, the book for practitioners.  The manual is not for practitioners.  Do not start reading the manual hoping to find the ‘how to use X-Ways’.  Do read the X-Ways Forensics Practitioner’s Guide to find out.  Unfortunately, books and manuals simply do not fill the remaining gap of instruction and demonstration.  Short videos on Youtube won’t do it either.  You need a course to learn what you need to learn as fast as you can learn it in order for you to be able to use it right away.

If you cannot attend the official X-Ways Forensics course due to time/money, or maybe you want a refresher to the course you took five years ago, or maybe you are in a forensic course in college that uses X-Ways, this online course is the least expensive you can find (the only one currently in the world) that fills that need.

I can promise that after you complete the course, you will have a different perspective of X-Ways.  You most likely will use X-Ways Forensics as a secondary or validation tool.  Many of you will move completely over to X-Ways Forensics and turn your other tools into secondary tools.  Some of you will turn your entire lab into an X-Ways Forensics lab that uses the “other tools” as validation.

One thing the online course does not do is teach forensics.  You might learn a little something since the course uses publicly available forensic images and gives suggestions on workflows (based on case types, such as picture intensive or user document intensive cases), but don’t expect this course to teach everything about forensics.  For that, you need to take a digital forensics course to show what a “lnk” file is, or how to examine the registry.  The X-Ways Forensics Practitioner’s Guide course teaches you how to plug the X-Ways Forensics dongle into your machine and push all the buttons you need to push to get what you are looking for.  That’s more than half the battle for any forensic software: what button do I push to get forensic artifact “x”, “y” and “z”?

Watch the introductory video (free) to get a handle on why you should take this course.  Whether you have been using X-Ways Forensics for more than a day, new to X-Ways Forensics, or thinking about trying it out, this course is the fastest, least expensive, and easiest method to learn. Bar none.

 

0
  8141 Hits
Tags:
X-Ways Forensics X-Ways Forensics Practitioner's Guide
Tweet
Recent Comments
Guest — karl obayi
Thanks for this course. Please, can I get a promo code so I can eroll. Will greatly appreciate the assistance. I already have the ... Read More
Saturday, 02 September 2017 03:22
Brett Shavers
Sorry, but the promo expired.
Saturday, 02 September 2017 09:04
8141 Hits
APR
03
0

Vote for your favorite book

Posted by Brett Shavers
in  Digital Forensics

Don’t forget to vote for the XWF Guide at http://forensic4cast.com/2014/04/2014-forensic-4cast-awards-meet-the-nominees/.  But of course, only vote if you liked it :)

And if you didn’t like it (which means you don’t have XWF…), vote for my other book, Placing the Suspect Behind the Keyboard.  But again, only vote if you liked it :)

And if you didn’t like that book either…give me your phone number.  We need to talk…

0
  2813 Hits
Tags:
X-Ways Forensics Practitioner's Guide Placing the Suspect Behind the Keyboard book
Tweet
2813 Hits
    Previous     Next
1 2 3 4 5 6

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

© 2022 Brett Shavers