An advanced specialist programme for interpreting Windows forensic artefacts, correlating user activity with system evidence, and supporting investigations and incident response through accurate, defensible findings.
Duration: 5 Days
Level: Advanced
Modern enterprise environments generate extensive Windows artefacts capable of revealing user activity, programme execution, file access, removable-media usage, cloud interaction, and web behaviour. This course develops advanced knowledge of Windows forensic analysis across multiple operating-system generations and demonstrates how distinct artefacts can be correlated to support incident response, internal investigations, cybercrime inquiries, and defensible reporting. It covers forensic triage, NTFS, Registry analysis, event records, email, cloud storage, and browser evidence, while remaining focused on advanced analysis rather than introductory evidence handling, chain-of-custody procedures, or basic drive acquisition..