The "Cybercop (CC) 315 Windows Artifacts" (WinArt) course covers the identification and extraction of artifacts associated with the current versions of Microsoft Windows operating systems (Vista through Windows 10) and the New Technology file system. Topics include the change journal, BitLocker, and a detailed examination of the various artifacts found in each of the registry hive files. Students examine event logs, volume shadow copies, link files, and thumbnails. This course uses a mixture of lecture, discussion, demonstration, and hands-on exercises.
WinArt is a four-day classroom course.
Prerequisite: CC 201 – Digital Evidence Examination and Processing classroom course. Equivalent training and/or experience may substitute for the prerequisite.
Amount | Description |
---|---|
$0.00 | No Cost $0 |