Workshops

Get hands-on experience with Windows Forensics tutorials and walk-throughs.

Windows Forensics 101

This workshop covers the fundamentals of Windows Forensics. Get hands-on experience by capturing a triage image of your own computer, and learn about common Windows artifacts.

Start!
Windows Forensics 102

This workshop builds on the foundations covered in Windows Forensics 101. Introducing new concepts and some additional Windows artifacts.

Coming Soon!
Windows Artifact Database

Digital Forensics and Incident Response (DFIR) investigation scenerios often revolve around anwsering a specific question. As a result, SANS, the industry leader for Cyber Security training categorizes forensic artifacts by the specific questions that you're trying to anwser. I referenced SANS Windows Forensic Analysis poster to create this database and added some additional contextual information help jumpstart your analysis.

Query the Database!