Practical Windows Forensics

Current Status

Not Enrolled

Price

Closed

Get Started

This course is included in the Analyst I – PWFA Training Track and Hero Bundle Training. Enroll to access the course.

> View Course Syllabus

 

Support & FAQs

Please use our Support & FAQ page to find more information and reach out to us and join our Discord community for general conversation topics and networking.

 

Important: Virtual Labs

  • Your labs are real virtual machines in the cloud. This means it may take a few minutes until they are started up and available.
  • Whenever you have less than 15 minutes remaining, you will have the option to extend your lab by 1 hour.
  • When a VM shuts down, it will not store your files and data.
  • For the best experience, it’s recommended to use Google Chrome where you will have copy and paste functionality.
Tools Used

Arsenal Image Mounter, Kroll Artifact Browser (KAPE), Eric Zimmerman Tools (Timeline Explorer, Registry Explorer, MFTECmd, AppCompatCacheParser, AmcacheParser, PECmd, EvtxECmd), Event Log Explorer, RegRipper, Sysinternals Autoruns, Sysmon, Volatility3, QEMU, Plaso Tools, Log2Timeline

Certificate of Completion

Once you finish the course you will receive your Certificate of Completion!

 

 

Average Review Score:
★★★★★
Excellent Learning Resource
★★★★★

It is essential to learn about cybersecurity continuously. The PWF course is an invaluable resource for this purpose. Markus shares his expertise and always responds on Discord when you contact him. Throughout the course, you will be guided through an investigation and learn various techniques. Markus presents his framework for a Digital Forensics and Incident Response (DFIR) investigation. I highly recommend this course.

You must log in and have started this course to submit a review.

Course Content

Lesson Content
0% Complete 0/2 Steps
2) Online Lab Instructions 1 Topic
Lesson Content
0% Complete 0/1 Steps
3) Data Collection Process 3 Topics
5) Disk Analysis Introduction 2 Topics
5.2) User Behavior Analysis 4 Topics
5.3) Overview of Disk Structures, Partitions and File Systems 2 Topics
8) Reporting 1 Topic
Lesson Content
0% Complete 0/1 Steps
9) Final! 1 Topic
Lesson Content
0% Complete 0/1 Steps
Scroll to Top

Training Waitlist

Join our waitlist and get notified when training becomes available.

Contact Information
Professional Experience
I'm interested in

*By submitting this form, you’re agreeing that we will contact you and to receive our free email newsletter. (You’ll never be spammed and you can unsubscribe at any time.) We do not share your information with third-parties.