Learning Path

Windows OS Forensics

    Syllabus

  • The FAT File System Course — 02:04:44
    • This course covers the structure and layout of the Fat file system.

  • The NTFS File System Course — 01:22:25
    • NTFS is a crucial component of forensic examinations.

  • The ex-fat File System Course — 01:11:03
    • In this course, the student learns the structure and layout of the ex-FAT file system.

  • Windows Registry Forensics Course — 01:05:56
    • This course covers the history and function of the registry.

  • Incident Response Project
  • Windows OS Forensics Project
  • Bits, Bytes, Endienness Course — 00:23:37
    • This course explains the various numbering schemas used throughout computer forensics.

  • Disk Partition Schemas Course — 01:15:17
    • This course demonstrates the difference between the master boot record and the GUID partition table.

  • SCADA Cyber Range — 03:14:00
  • Windows OS Forensics Skill Assessment Assessment — 00:23:30

Syllabus

What you will learn

The student will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. The student will learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable students to validate the information from multiple forensic tools properly.

Wistia video thumbnail

Meet the author

In addition to being an Infosec instructor, Denise Duffy teaches computer forensics worldwide to European law enforcement through the European Anti-Fraud Office. During her 25-year career at the Middletown Police Department, Denise underwent extensive training in specialized computer and mobile device forensics, including widespread access data courses, multiple IACIS trainings, U.S. Secret Service Training at the National Computer Forensics Institute, BlackBag Technologies Training, many National White Collar Crime (NW3C) courses, an X-Ways online course and considerable Internet Crimes Against Children Training (ICAC) courses.

Denise currently holds the following certifications: CFCE (Certified Forensic Computer Examiner), CCFE (Certified Computer Forensics Examiner), CMFE (Certified Mobile Forensics Examiner) and CEH (Certified Ethical Hacker). She is most proud of her two sons who joined the U.S. Military, as Denise is a Desert Shield/Desert Storm veteran herself.

The details

Learning path insights

How to claim CPEs

Should you complete this learning path, you’ll be able to download a certificate of completion. Use this to claim your CPEs or CPUs.

No software. No set up. Unlimited access.

Skip the server racks and spin up a realistic environment with one click. lnfosec Skills cyber ranges require no additional software, hardware or server space so your team can spend less time configuring environments and more time learning. Unlimited cyber range access is included in every lnfosec Skills subscription so your team can skill up however they learn best.

Plans & pricing

  • Infosec Skills Personal

    $299 / year

    • 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
    • 100s of hands-on labs in cloud-hosted cyber ranges
    • Custom certification practice exams (e.g., CISSP, Security+)
    • Skill assessments
    • Infosec peer community support
  • Infosec Skills Teams

    $799 per license / year

    • Team administration and reporting
    • Dedicated client success manager
    • Single sign-on (SSO)
      Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
    • Integrations via API
      Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
    • 190+ role-guided learning paths and assessments (e.g., Incident Response)
    • 100s of hands-on labs in cloud-hosted cyber ranges
    • Create and assign custom learning paths
    • Custom certification practice exams (e.g., CISSP, CISA)
    • Optional upgrade: Guarantee team certification with live boot camps

Unlock 7 days of free training

  • 1,400+ hands-on courses and labs
  • Certification practice exams
  • Skill assessments

You're in good company

AH

My instructor knew his stuff! His ability to explain heavy concepts in a (quickly) digestible manner is the only reason I am certified today!

Aaron Hahn

AK

The instructor was very well versed in the material presented during the course and delivered it in an effective manner. The training environment was conducive to learning. The material provided for this course was adequate for accomplishing course objectives.

Abram Kauk

AW

The whole experience was great. Very well done. Great lecturing, examples/stories and knowledge of the material.

Adam Wojcicki