Free
DFIR Operator Series: Windows Forensics 101
Created for learners to analyze and triage Windows systems (including artifacts and indicators of compromise) and review Operating Systems at a detailed level. Allows learners to apply critical thinking to various steps of forensics investigations (of Windows based systems) and communicate those findings to stakeholders and executive leadership.

4
H
6
M
Time
intermediate
difficulty
4
ceu/cpe
Course Content
DFIR Overview: Analysis (Video)
Analysis
Windows NTFS & FAT Filesystem (Video)
Windows Artifacts
DFIR: Reporting & Wrapping Up
Capstone
DFIR Operator Program Outline
What is DFIR?
Windows NTFS & FAT Filesystem (Video)
Windows Artifacts
DFIR: Examination Phase (Video)
Examination
Overview of Data Collection (Video)
Data Collection
Overview of DFIR (Video)
Digital Forensics Incident Response: Overview
Artifact Overview (Video)
Analysis
Windows NTFS: $MFT (Video)
Windows Artifacts
Final Capstone Lab
Capstone
Lab #8: Memory Forensics
Memory
Capstone Lab Activity
Capstone
Working with Powershell (Text)
Analysis
Disk Analysis Process (Video)
Analysis
Examination Phase (Text)
Examination
Collecting the Data: Chain of Custody (Text)
Data Collection
Ways We Connect and Support You
What is DFIR?
People, Process, and Technology (Text)
Digital Forensics Incident Response: Overview
Lab #3: $MFT Parsing (Overview Video)
Windows Artifacts
Lab #2: Artifact Collection
Examination
Capstone Summary Video
Capstone
NTFS Examination Lab (Video)
Windows Artifacts
Course Description
Created for learners to be able to analyze and triage Windows systems (including specific artifacts and indicators of compromise) and review Operating Systems at a detailed level. This course allows learners a chance to applying critical thinking to various steps of forensics investigations (of Windows based systems) and communicate those findings to stakeholders and executive leadership.