Passware Certified Examiner Training

Become a certified decryption expert in just a week

Passware Certified Examiner (PCE) training is the most prominent online course designed specifically for computer forensic professionals.

It provides world-class knowledge and skills to analyze and decrypt encrypted electronic evidence in an easy to follow format.

Course Outline:

  • Session 1: Detecting Encrypted Files
    • Types of files and encryption able to be detected
    • Identifying types of files to decrypt
    • Saving and loading Encryption Analyzer search results
  • Session 2: File Password Recovery
    • Types of files supported
    • Predefined settings / Wizard
  • Session 3: Custom Dictionary and Keyword Lists
    • Creating custom dictionary and keyword lists
    • Importing those lists to recover passwords
    • Password Exchange
  • Session 4: Types of Attacks Available in Passware Kit Forensic
    • Overview of the various types of attacks and how they work
    • Applying attacks and customizing attack settings
  • Session 5: System and GPU Recommendations
    • Hardware acceleration
      • Supported hardware: GPU Nvidia and AMD cards
      • Supported file types
    • Distributed Password Recovery
      • Network setup
      • Windows Agent
      • Linux Agent
  • Sessions 6 and 7: Memory Analysis
    • Types of encryption-related evidence that can be extracted from a memory image
    • How to create a memory image
    • How to use hibernation files
    • Loading a memory image into Passware Kit Forensic for analysis
  • Sessions 8 and 9: Mobile Forensics
    • Recover a password for an encrypted backup
    • Recover passwords from iOS keychain
    • Recover a password for an Android image
  • Session 10: Cloud Forensics
    • Obtaining an iCloud backup
    • Obtaining a OneDrive cloud account
  • Session 11: Resetting a Windows Admin Password
    • Creating a bootable USB / CD
    • Booting the machine and resetting the password
  • Session 12: Standalone System
    • Recovering passwords from registry files
    • Identifying files required to do the analysis
    • How to obtain the registry files
  • Sessions 13 and 14: Full Disk Encryption
    • Types of Full Disk Encryption
    • Choosing between memory analysis and password recovery
    • Decrypting various different volumes
  • Session 15: Completing the Analysis
    • A review of best practice procedures
    • Exporting the results and saving the details for a report
  • Session 16: Batch Recovery & Dictionary Manager
    • Why use batch recovery
    • Adding files and creating groups for batch recovery
    • Sorting by complexity
    • Attack and timeout settings for batch recovery
    • Adding, merging and sorting dictionaries
    • Compiling dictionary from a memory image

Passware Certified Examiner (PCE) Online Training

This online, self-paced course provides forensic examiners with a start-to-finish education on the use of Passware Kit Forensic. During the course, students learn how to detect encrypted evidence, recover passwords for all common file types, analyze memory images, recover passwords for mobile backups, decrypt hard drives, and more.

The course consists of 16 video sessions, varying from 15 to 30 minutes each. At the end of each session, attendees take a “knowledge check” — a simple 3 to 5 question quiz. Participants in this training course may take the exam to receive a Passware Certified Examiner (PCE) designation. Prior knowledge or use of Passware Kit Forensic is not required to take this course.

Course Objectives

  • Gain extensive knowledge on encrypted electronic evidence
  • Know how to locate, process, and decrypt encrypted files and disks
  • Obtain required knowledge to set up password recovery attacks and to create and use custom dictionaries
  • Discover how to maximize password recovery performance: hardware acceleration and distributed password recovery
  • Understand what encryption artifacts can be extracted from memory images
Buy Now Download Course Outline PDF
The link to the course, along with your login credentials will be sent to your email immediately after the order is placed.

Frequently Asked Questions

Is this an online course, or is it in a classroom?
This is an online, self-paced video course, so you can learn at your own speed.
What software/hardware do I need for this course?
You need Passware Kit Forensic installed on your computer, Internet access, and speakers or headphones.
Do I need a working license of Passware Kit Forensic to use this course?
Yes. Your license of Passware Kit Forensic must be up to date.
Will I get a certificate at the end of this course?
Yes. After completing the course, students can take the exam to receive the Passware Certified Examiner (PCE) designation.
What do I need to pass?
The passing score is 80%, with 75 questions in total for the test.
How long is the certificate valid?
The certificate is valid for two years.