
Explore practical Windows forensics for beginners by learning basic concepts, Windows architecture, memory and disk forensics, and analyzing event logs and artifacts to preserve evidence.
Discover the Windows registry as the central repository for system, software, hardware, and user settings. Learn how to navigate root keys, keys, and values with Regedit to extract forensic clues.
Demonstrate how to import and export registry subkeys with Regedit, including selecting export range and saving changes, and warn that merging registry files can cause conflicts and instability.
Analyze the Windows registry manually to uncover forensic evidence, including OS version, time zone, installed software, USB devices, network SSIDs, printer drivers, and recent activity.
explore windows registry with regedit.exe, examining uninstall, run, recent files, and mounted devices to practice manual analysis and identify software, driver, and USB entries.
analyze rdp cache files to uncover attacker activity, including screenshots of accessed files, by parsing bitmap artifacts in the rdp cache located under user appdata folders.
Analyze the windows recycle bin by examining dollar i metadata and dollar r data files, then use Rafferty and dollar i parse tools to extract deletion times and original paths.
Learn to analyze Windows LNK shortcut files to uncover original file paths, sizes, serial numbers, network shares, and MAC addresses; using exiftool and command-line tools for forensic investigations.
Analyze Windows jump lists, including automatic and custom destinations, to trace user activity and file access for incident response and malware analysis.
Analyze user assist artifacts in the Windows registry to reconstruct a user's program execution history, focus time, and execution counts using Ntuser.dat and the user assist key.
This course is aimed at individuals with little or no experience in Windows forensics who want to develop a foundation in this area. It provides an overview of the basic techniques and tools used for investigating Windows systems.
Throughout the course, students will learn about the importance of forensic analysis in investigating security incidents. They will also gain an understanding of the Windows operating system and its components, including the registry, file systems, event logs, and other key artifacts.
The course covers a range of forensic tools and how to use them effectively for investigations. Students will learn about data acquisition, analysis, and reporting techniques commonly used in Windows forensics.
By the end of the course, students will have a basic understanding of Windows forensics and be able to apply their knowledge to identify, collect, and analyze digital evidence in Windows systems. They will also understand the legal and ethical considerations that need to be taken into account when conducting investigations.
All course materials are provided in a zip file, and students will have access to practical exercises and quizzes to reinforce their learning. This course is an excellent starting point for individuals interested in pursuing a career in digital forensics or incident response.