Course outlinePractice: (W52Q04T12)
Your course
PowerShell in Digital Forensics (W52)
Module 1
Before the course
Module 2
Module 1
- 1.(W52M01) The NET Framework
- 2.(W52M02) Powershell Terminology
- 3.(W52M03) Using PowerShell
- 4.(W52M04) PowerShell Gallery Demonstration
- 5.(W52M05) PSGallery - Simulation Exercise
- 6.(W52M06) Services and Processes - Simulation Exercise
- 7.(W52M07) Services and Processes - Simulation Exercise
- 8.(W52M08) Forensic cases suited for using PowerShell
- 9.(W52M09) Cmdlets to Scripting
- 10.(W52M10) Shares Simulation Exercise
- 11.(W52M11) Shares Simulation Assessment
- 12.(W52M12) Advanced Functions
- 13.(W52M13) Advanced Functions - Simulation Exercise
- 14.(W52M14) Advanced Functions - Simulation Assessment
- 15.(W52M15) Desired State Configuration
- 16.(W52M16) DSC - Simulation Exercise
- 17.(W52M17) DSC - Simuation Assessment
- 18.(W52M18) Integrating with other tools
- 19.(W52M19) Extract Registry Hive - Simulation Exercise
- 20.(W52M20) Extract Regustry Hive Simulation Assessment
- 21.(W52M21) EvidenceOfExecution - Simulation Exercise
- 22.(W52M22) EvidenceOfExecution - Simulation Assessment
- 23.Practice: (W52Q01T08)
- 24.Practice: (W52Q01T12)
Module 3
Module 2
- 1.(W52M23) Installed Software
- 2.(W52M24) Installed Software - Simulation
- 3.(W52M25) Running Applications
- 4.(W52M26) Running Applications - Simulation
- 5.(W52M27) Services
- 6.(W52M28) Services - Simulation
- 7.(W52M29) User Accounts Details
- 8.(W52M30) User Accounts Details - Simulation
- 9.(W52M31) Network Activity
- 10.(W52M32) Network Activity - Simulation
- 11.(W52M33) Running Processes
- 12.(W52M34) Processes - Simulation
- 13.(W52M35) Hashing
- 14.(W52M36) Get Flash - Demonstration
- 15.(W52M37) PowerShell Imaging
- 16.(W52M38) New VHDX
- 17.(W52M39) New VHD
- 18.(W52M40) WIM - Simulation
- 19.(W52M41) Other scripting languages
- 20.(W52M42) VBScript - Simulation
- 21.(W52M43) JavaScript Simulation
- 22.(W52M44) PowerShell on a network
- 23.(W52M45) Calling functions
- 24.(W52M46) Importing
- 25.(W52M47) Network information - Simulation
Module 4
Module 3
Module 5
Module 4
- 1.(W52M52) Testing and Validation
- 2.(W52M53) Preserving Data in PowerShell
- 3.(W52M54) Keeping Data Unaltered
- 4.(W52M55) Imaging and Hashing Confirmation
- 5.(W52M56) Script to Executable - Demonstration
- 6.(W52M57) Certifying PowerShell and Scripting
- 7.(W52M58) Module Design - Demonstration
- 8.(W52M59) Real World Relevant Case Example
Module 6
Final Exam
Module 6Lesson 2
Practice: (W52Q04T12)
Course lessonLocked
Member lesson
Unlock the full lesson
Sign in to read and unlock the course materials.
Course access
Unlock PowerShell in Digital Forensics (W52).
Enter your email. We’ll send a sign-in code here without taking you away from this course.