Membership

New Technology File System (NTFS) Forensics (W40)

Investigate evidence stored in the New Technology File System. Explore NTFS structures and the forensic meaning of file-system artifacts.

Instructor · Divya Lakshmanan

Modules:
5
Lessons:
159

eForensics learning

Practical skills.
Verified progress.

What you'll learn

  • Examine the structure of NTFS.
  • Interpret hexadecimal file-system data.
  • Apply file-carving techniques to recovery and investigation.

Prerequisites

Basics of Digital Forensics: Forensic Imaging Hashing File Naming Conventions Equipment and software: Forensic Images of NT File system will be provided to you. A computer running Ubuntu 16 LTS is required to forensically analyse the file system images. If you wish to take your own forensic images, then a computer running Windows is also required. Good internet connection to download tools as we go.

Module 2

Module 1

Assessments

Quiz Required

(W40Q01) Hello NTFS! - Assignment 1

Module 3

Module 2

Assessments

Quiz Required

(W40Q02) NTFS Surgery - Assignment 2

Module 4

Module 3

Assessments

Quiz Required

(W40Q03) You seem special NTFS! - Assignment 3

Module 5

Module 4

Assessments

Quiz Required

(W40Q04) I am NTFS and I know it! - Assignment 4

Module 6

Final Exam

Lessons will appear here after course content is added.

Assessments

Quiz Required

(W40Q05) Final Exam

Course access

Unlock New Technology File System (NTFS) Forensics (W40).

Enter your email. We’ll send a sign-in code here without taking you away from this course.