Windows OS forensics

Windows forensics education is intended for introduction to forensic analysis of Windows operating system and its characteristics.

Duration of the education is 3 to 5 days with the goal of introducing attenders to basics of Windows operating system, forensic artifacts on Windows, tools and procedures of Windows digital forensics and application of digital forensics tools to that platform. Attenders are getting introduced to applications specific for Windows like MS Office package, document formats, basics of FAT and NTFS file systems, basic elements of security, encryption, visualization etc. Considering frequent change, this education is being constantly perfected and it follows current conditions. Goal of this education is for attender to understand the functioning of Windows operational system and what artifacts and in what way can be found and used in forensically correct way.