top of page

Related Courses

Practical Windows Forensics 11+ Hours Course

Price: 6.00 USD | Size: 2.00 GB  | Duration :  11+ Hours  | 83 Video Lessons | ⭐️⭐️⭐️⭐️⭐️ 4.9

BRAND : Expert TRAINING | ENGLISH |  Bonus :  Bundle of Forensics PDF Guides | INSTANT DOWNLOAD 

 

HOW TO DOWNLOAD THIS COURSE?

You can Instant Download a PDF file After successful payment, This PDF File Contains Course Download links

You can Download This Course immediately from the click that Links

 

Practical Windows Forensics 11+ Hours Course & PDF Guides

 

 

The objective of the Practical Windows Forensics (PWF) course is to show students how to perform a full digital forensic investigation of a Windows system in a complete do-it-yourself setup.

 

  • 11 hours of guided video content
  • 80+ videos on-demand
  • Using freely available and industry-recognized forensic tools
  • 100% hands-on and in do-it-yourself format

 

 

Course Description

The course covers a full digital forensic investigation of a Windows system. It begins with the simple preparation of our lab, which consists of setting up a “victim” VM and a forensic workstation. We’ll then run an attack simulation script (open-source PWF Attack script) on the victim VM that simulates attack patterns as commonly observed by threat actors in the industry to create a realistic setting for our investigation. From there, we’ll kick off the forensic process, beginning with the data collection, examination and extraction before diving deeper into the analysis of the information at hand.

The data analysis section consists of a comprehensive investigation, including various tools and many different forensic artifacts with which every analyst should be familiar. We will not only analyze artifacts, but also discuss their behavior to learn when, why and how to interpret the data contained within these artifacts. The analysis begins with Windows disk and memory artifacts and ends with the analysis of the timelines generated from both.

This course also covers many important artifacts and concepts relating to Windows forensic analysis. We’ll use several freely available tools for the analysis that are well known and recognized in the industry. The student will leave the course with a comprehensive understanding of the forensic process, important Windows artifacts and forensic tools and a forensic workstation available and ready to go for future investigations.

 

 

 

Course Outline:

 

  • Virtual lab set up
  • Forensic workstation set up
  • Setup and attack of the target VM
  • Acquisition of virtual memory and disk images
  • Disk analysis
    • Registry
    • Users, SIDs and Profiles
    • User behavior
    • NTFS / MFT / USNJrnl
    • Execution Artifacts
    • Persistence Artifacts
    • Event Log Analysis

 

  • Memory Analysis
    • Processes
    • DLLs
    • SIDs
    • Registry

 

  • Super Timeline Analysis

Practical Windows Forensics 11+ Hours Course

SKU: ETRA 172
$6.00Price
    bottom of page