Windows Digital Forensics – 5 Days

Build your digital forensics expertise by learning from a simulated real-life cyber targeted attack incident. Practice reconstructing the incident, using time stamps, finding traces of intrusion in Windows OS components and also analyzing browser and email history.

Course Outline

Through a simulated real-life targeted cyberattack, the course covers the following topics:
• Introduction to digital forensics
• Live response and evidence acquisition
• Post-mortem analysis of Windows machines
• MS Windows registry internals
• MS Windows events
• MS Windows artifacts analysis
• Browsers artifacts forensics
• Email analysis
• Forensics challenges with SSD disks
• Recommendations for building a digital forensics lab
• Testing the newly gained skills with a practical challenge using different windows artifacts

• How to acquire various digital evidence and deal with it in a forensically sound environment
• Find traces of incident-related malicious activities from
• MS Windows artifacts
• Utilize time stamps from different Windows artifacts to reconstruct an incident scenario
• Find and analyze browser and email history
• Be able be apply the tools and instruments of digital forensics
• Understand the process of creating a digital forensics lab


Mid-level: system administration skills required


Below is a Course Schedule for this:



Duration: 5 Days

