
Introduction to the course
Discover what digital forensics entails and how investigators identify what happened, where intrusion originated, and the damage using siem tools for file system, memory, and network forensics and incident response.
Acquire data for digital forensics using disk images, memory images, logical disk to disk copies, and sparse copies with autopsy, ensuring admissible data under NIST and chain of custody.
Identify and isolate devices with data, extract and create secure forensic images, analyze recovered data with keyword searches and carving, and document and present findings for legal outcomes.
Explore how to install Autopsy, enable the central repository, set up a forensic workstation, and analyze a virtual machine for evidence.
Use Wireshark and Nmap/Zenmap to scan networks, analyze packets, and identify open ports. Learn to apply firewall rules and isolate compromised devices in a forensic workflow.
Explore how to inspect the Windows registry for hacker activity using regedit, Registry Explorer, and RegRipper; copy the registry with transaction logs and analyze keys, executables, and DLLs.
Develop analytical thinking to break down complex data and identify patterns in digital forensics and incident response, then test hypotheses with evidence and prepare clear reports for executives and courts.
Learn how to conduct an investigation and use the tools needed for incident response in Windows digital forensics.
Professor Robert McMillen has created over 100 IT courses for companies such as LinkedIn Learning, Pluralsight, The InfoSec Institute, and now Udemy.
Intro to Windows Digital Forensics and Incident Response is an introduction course to all the tools, knowledge, and demonstrations needed to get started in a career as a digital forensics investigator and incident responder. View demonstrations using tools built into Windows as well as third party tools downloaded from the internet. Learn data preservation, emergency response preparedness, how to respond to an incident legally and professionally, how to know if you have been hacked by reviewing the registry, antimalware programs, and SIEM log aggregation tools. Included are commands, an incident response document to download, and a quiz to test your knowledge.
Create a case with Autopsy and preserve current processes in RAM using free tools that can produce results produced into courtrooms with proper chain of custody. Learn how to be a white hat hacker using tools such asn Zenmap and Wireshark. You'll see like demonstrations of sending and receiving data packets in a way you'll understand.
Learn to be part of an emergency response team and understand the order of action when malware is discovered on your network. You'll be the IT hero and use forensics skills to locate the attacker as well as properly respond to the incident.