- 08:00 bis 17:00 Uhr
Hotel Belvoir Rüschlikon, Säumerstrasse 37, 8803 Rüschlikon, Switzerland
- Learn to use various applications and utilities to successfully identify, understand and document numerous Windows® artifacts that are vitally important to forensic investigations.
- Learn how to process core system artifacts including SQLite Database analysis, and other new Windows®11 specific applications.
- Gain in-depth knowledge of Windows OneDrive synchronization and how data is shared between trusted devices.
- Attendees will use a variety of open-source and leading forensic applications to examine key artifacts through multiple hands-on labs and student exercises.
The course will follow adult learning principles through training aids such as presentations, diagrams, and practical instructor lead examples. Each artifact covered will be presented in either one or two 50-minute sessions followed by review questions. Students will be given the opportunity throughout the course to ask questions and discuss objectives covered in more detail. Throughout each day students will have practical exercises to work on to reinforce the topics.
Who should attend?
This course is targeted at examiners who have at least 6 months of experience in digital forensics.