Free
DFIR Operator Series: Windows Forensics 101
Created for learners to analyze and triage Windows systems (including artifacts and indicators of compromise) and review Operating Systems at a detailed level. Allows learners to apply critical thinking to various steps of forensics investigations (of Windows based systems) and communicate those findings to stakeholders and executive leadership.
4
H
6
M
Time
intermediate
difficulty
4
ceu/cpe
Course Content
Windows EVTX Logs (Lab)
Windows Artifacts
Post Lab Takeaways & Closing Thoughts
Windows Artifacts
Windows Registry, Shellbags & Amcache (Text)
Windows Artifacts
Windows Security Identifiers (Text)
Windows Artifacts
Windows EVTX Overview (Video)
Windows Artifacts
Windows EVTX Overview (Text)
Windows Artifacts
Course Description
Created for learners to be able to analyze and triage Windows systems (including specific artifacts and indicators of compromise) and review Operating Systems at a detailed level. This course allows learners a chance to applying critical thinking to various steps of forensics investigations (of Windows based systems) and communicate those findings to stakeholders and executive leadership.