Skip to main content

DF310 Advanced Digital Forensic Analysis: Windows

Attention

This website is under construction. Please send questions or comments to bjanttac@usdoj.gov.

Questions?

This course covers the identification and extraction of artifacts associated with the Microsoft Windows operating system. Topics include the Change Journal, BitLocker, and a detailed examination of the various artifacts found in each of the Registry hive files. Students also examine Event Logs, Volume Shadow Copies, link files, and thumbnails. This course uses a mixture of lecture, discussion, demonstration, and hands-on exercises.

Cost Information
Amount
0.00
Event Date
-