Passware Certified Examiner Training
Become a certified decryption expert in just a week
Passware Certified Examiner (PCE) training is the most prominent online course designed specifically for computer forensic professionals.
It provides world-class knowledge and skills to analyze and decrypt encrypted electronic evidence in an easy to follow format.
Session 1: Detecting Encrypted Files
- Types of files and encryption able to be detected
- Identifying types of files to decrypt
- Saving and loading Encryption Analyzer search results
Session 2: File Password Recovery
- Types of files supported
- Predefined settings / Wizard
Session 3: Custom Dictionary and Keyword Lists
- Creating custom dictionary and keyword lists
- Importing those lists to recover passwords
- Password Exchange
Session 4: Types of Attacks Available in Passware Kit Forensic
- Overview of the various types of attacks and how they work
- Applying attacks and customizing attack settings
Session 5: System and GPU Recommendations
- Supported hardware: GPU Nvidia and AMD cards
- Supported file types
Distributed Password Recovery
- Network setup
- Windows Agent
- Linux Agent
- Hardware acceleration
Sessions 6 and 7: Memory Analysis
- Types of encryption-related evidence that can be extracted from a memory image
- How to create a memory image
- How to use hibernation files
- Loading a memory image into Passware Kit Forensic for analysis
Sessions 8 and 9: Mobile Forensics
- Recover a password for an encrypted backup
- Recover passwords from iOS keychain
- Recover a password for an Android image
Session 10: Cloud Forensics
- Obtaining an iCloud backup
- Obtaining a OneDrive cloud account
Session 11: Resetting a Windows Admin Password
- Creating a bootable USB / CD
- Booting the machine and resetting the password
Session 12: Standalone System
- Recovering passwords from registry files
- Identifying files required to do the analysis
- How to obtain the registry files
Sessions 13 and 14: Full Disk Encryption
- Types of Full Disk Encryption
- Choosing between memory analysis and password recovery
- Decrypting various different volumes
Session 15: Completing the Analysis
- A review of best practice procedures
- Exporting the results and saving the details for a report
Session 16: Batch Recovery & Dictionary Manager
- Why use batch recovery
- Adding files and creating groups for batch recovery
- Sorting by complexity
- Attack and timeout settings for batch recovery
- Adding, merging and sorting dictionaries
- Compiling dictionary from a memory image
Passware Certified Examiner (PCE) Online Training
This online, self-paced course provides forensic examiners with a start-to-finish education on the use of Passware Kit Forensic. During the course, students learn how to detect encrypted evidence, recover passwords for all common file types, analyze memory images, recover passwords for mobile backups, decrypt hard drives, and more.
The course consists of 16 video sessions, varying from 15 to 30 minutes each. At the end of each session, attendees take a “knowledge check” — a simple 3 to 5 question quiz. Participants in this training course may take the exam to receive a Passware Certified Examiner (PCE) designation. Prior knowledge or use of Passware Kit Forensic is not required to take this course.
- Gain extensive knowledge on encrypted electronic evidence
- Know how to locate, process, and decrypt encrypted files and disks
- Obtain required knowledge to set up password recovery attacks and to create and use custom dictionaries
- Discover how to maximize password recovery performance: hardware acceleration and distributed password recovery
- Understand what encryption artifacts can be extracted from memory images
Frequently Asked Questions
- Is this an online course, or is it in a classroom?
- This is an online, self-paced video course, so you can learn at your own speed.
- What software/hardware do I need for this course?
- You need Passware Kit Forensic installed on your computer, Internet access, and speakers or headphones.
- Do I need a working license of Passware Kit Forensic to use this course?
- Yes. Your license of Passware Kit Forensic must be up to date.
- Will I get a certificate at the end of this course?
- Yes. After completing the course, students can take the exam to receive the Passware Certified Examiner (PCE) designation.
- What do I need to pass?
- The passing score is 80%, with 75 questions in total for the test.
- How long is the certificate valid?
- The certificate is valid for two years.