Surviving Digital Forensics: Volume Shadow Copy

Learn how to tap into this amazing source of historical user information. It's easier than you think!
4.5 (12 ratings)
Instead of using a simple lifetime average, Udemy calculates a
course's star rating by considering a number of different factors
such as the number of ratings, the age of ratings, and the
likelihood of fraudulent ratings.
257 students enrolled
Take This Course
  • Lectures 5
  • Length 34 mins
  • Skill Level Expert Level
  • Languages English
  • Includes Lifetime access
    30 day money back guarantee!
    Available on iOS and Android
    Certificate of Completion
Wishlisted Wishlist

How taking a course works


Find online courses made by experts from around the world.


Take your courses with you and learn anywhere, anytime.


Learn and practice real-world skills and achieve your goals.

About This Course

Published 3/2014 English

Course Description

All SDF courses may now be found at SUMURI.COM. This course will remain live in UDEMY for existing students.

Time travel anyone? Well, sort of... By creating computer forensic images from volume shadow copies you are able to capture the system in different points in time- going back days, weeks, months or even years. Drop these images into your favorite computer forensic tool and suddenly your pulling up previous versions of documents and deleted files and folders. I have used this technique to overcome the effects of computer "wiping" and "cleaning" utilities. This class teaches you how to identify and create these images in a few quick steps- no high cost computer forensic tools needed. In fact, you will be amazed how easy it is to do. If you are a computer forensic analyst then this is one of the top skills you need to have.

What are the requirements?

  • Computer forensic analysis experience
  • IT Experience

What am I going to get from this course?

  • Identifying volume shadow copies
  • Imaging volume shadow copies
  • Processing volume shadow copies
  • Understanding volume shadow copies

Who is the target audience?

  • Computer Forensic Analysts
  • IT Professionals
  • Students

What you get with this course?

Not for you? No problem.
30 day money back guarantee.

Forever yours.
Lifetime access.

Learn on the go.
Desktop, iOS and Android.

Get rewarded.
Certificate of completion.


Section 1: Survive Volume Shadow Copy

Welcome to the SDF series. In this class we are going to learn how to convert a shadow copy into a DD image file you can forensically process. First, however, let's learn a little about more about volume shadow copies.


Now that we have the fundamentals out of the way let's go hands on. The first thing we need to do is examine out target drive to see what shadow copy files exist and to get the information we will need for the imaging process. Next, we create our DD image using FAU. You will be amazed at how easy this is to do.


Let's check out the results and see the differences between some shadow copies.

1 page

Just a quick update about Windows 8.


Thanks for joining me and don't forget to download the cheat sheet.

Check out other classes of the SDF series at

Follow me on Twitter @LeclairDF to get the latest happenings of the SDF series.

Check out our Blog at

Check out our Youtube channel

Students Who Viewed This Course Also Viewed

  • Loading
  • Loading
  • Loading

Instructor Biography

Michael Leclair, Computer Forensic Analyst

Over twelve years of experience as a Computer Forensic Analyst, author and developer of computer forensic training and analysis tools. Specialties include: Windows forensics, Mac forensics, iOS forensics, Mac Server forensics & mobile device forensics. Creator of the "Surviving Digital Forensics" series and part of SUMURI's RECON for Mac OS X development team.

Certifications include: CFCE, CISSP, CCE, EnCE, A+, Network+

Regularly instruct law enforcement, government and corporate investigators both nationally and internationally in computer forensics.

Ready to start learning?
Take This Course