This course covers the identification and extraction of artifacts associated with the Microsoft® Windows® operating system. Topics include the Change Journal, BitLocker®, and a detailed examination of various artifacts found in each of the Registry hive files. Students also examine event logs, Volume Shadow Copies, link files, and jump lists. This course uses a mixture of lecture, discussion, demonstration, and hands-on exercises.
Excel Office 365 is recommended, versions 2010 and newer will be functional.
Students who complete this course and pass the post-test are eligible for 1.0 point toward the 3CE certification.