Examining File Operations
In this hands-on lab, you will learn about file operations as a source of evidence in the context of a forensic investigation. You will practice you examining traces of actions performed involving files, such as files being created, modified, moved, opened, etc.

Course Content
Upon completing this lab, learners should be able to:
- Define "file operations" in the context of digital forensics.
- Identify common types of file operations.
- Identify the dates, times, and nature of specific file operations using file system metadata, file system journals and Registry artifacts.
- Associate files with user accounts based upon file system metadata.
- Correlate multiple data sources to increase confidence in findings regarding file operations.