Event Type:
Tuesday Jul 17, 2018 - 12:00pm UTC to Friday Jul 20, 2018 - 04:00pm UTC
Event Description:
This course covers the identification and extraction of artifacts associated with the current versions of Microsoft Windows operating systems (Vista through Windows 10) and the NT file system. Topics include the change journal, BitLocker, and a detailed examination of the various artifacts found in each of the registry hive files. Students examine event logs, volume shadow copies, link files, and thumbnails. This course uses a mixture of lecture, discussion, demonstration, and hands-on exercises.
Location:
537 Bayne Avenue
2nd Floor, Council Chambers
Pittsburgh, PA
15202
United States
See map: Google Maps
Event URL:
Amount | Description |
---|---|
$0.00 | Free |
Space Available:
Yes
Category:
Program Areas: