WINDOWS FORENSICS AND TOOLS The Windows Forensics and Tools course focuses on building digital forensics knowledge of Microsoft Windows operating systems, as well as some compatible software or tools that can be used to obtain or process information in such systems. TIME 4 hours 15 minutes DIFFICULTY Beginner CEU/CPE 4 Course Content Module 1 : Is Windows Forensics Easy? • 1.1 Course Introduction 7m • 1.2 Common Myths 9m • 1.3 Forensic Investigation Methodology 7m Module 2 : Windows Imaging • 2.1Physical Drive Nomenclature in Windows 4m • 2.2Logical Drive Nomenclature in Windows 9m • 2.3Summary of Windows Device Names 4m Module 3 : Imaging with DD • 3.1Basic dd.exe Operation 10m • 3.2dd.exe Logical Drive Example 5m • 3.3Physical Memory 7m • 3.4Looking at Memory 4m Module 4 : Memory Analysis Tools • 4.1Memparser 10m • 4.2Volatility 4m • 4.3Other Tools 10m Module 5 : Windows Essentials - SID • 5.1SID (Security Identifier) 7m Module 6 : System Registry • 6.1Registry Hives 9m • 6.2New...