Skip to main content

DF310 Advanced Digital Forensic Analysis: Windows

Attention

Due to a federal government shutdown, content updates are temporarily on hold. Content updates and responses to inquiries will resume when normal operations continue.

Questions?

This course covers the identification and extraction of artifacts associated with the Microsoft Windows operating system. Topics include the Change Journal, BitLocker, and a detailed examination of the various artifacts found in each of the Registry hive files. Students also examine Event Logs, Volume Shadow Copies, link files, and thumbnails. This course uses a mixture of lecture, discussion, demonstration, and hands-on exercises.

Cost Information
Amount
0.00
Event Date
-