Membership

Windows Registry and Log Analysis (W31)

Investigate Windows Registry artifacts and logs. Develop a practical approach to interpreting records of system configuration and user activity. This is an earlier course edition; examples reflect the tools and versions used when it was recorded.

Instructor · Luca Cadonici

Modules:
6
Lessons:
44

eForensics learning

Practical skills.
Verified progress.

What you'll learn

  • Extract investigative information from the Windows Registry.
  • Collect and analyze logs with PowerShell and Log Parser.
  • Connect Registry and log artifacts with system activity.

Prerequisites

Intermediate use of the Windows operating system Intermediate understanding of the Windows operating system Basic concepts of Computer Forensics (imaging, hashing) Basic understanding of networking (TCP/IP, IP addressing, routing, DNS, DHCP) Basic concepts of IT security Equipment and software: A Workstation running Windows 7, 8 or 10. FTK Imager 4.1.1 http://accessdata.com/product-download/ftk-imager-version-4.1.1 Log Parser 2.2 https://www.microsoft.com/en-us/download/details.aspx?id=24659 Registry Viewer 1.8.1.3 (demo version) http://accessdata.com/product-download/registry-viewer-1.8.1.3 PowerShell 5.0 https://docs.microsoft.com/en-us/powershell/wmf/5.1/install-configure

Module 3

Module 1

Assessments

Assignment Required

(W31A01) Exercise: Tracking system boot and shutdown phases

Assignment Required

(W31A02) Exercise: Reconstructing recent activity on the computer

Module 4

Module 2

Assessments

Assignment Required

(W31A03) Exercise: Registry Key Cell analysis with FTK Imager

Assignment Required

(W31A04) Exercise: Retrieving information with PowerShell

Module 5

Module 3

Assessments

Assignment Required

(W31A05) Exercise: Investigating through Registry Analysis

Assignment Required

(W31A06) Exercise: Parsing Registry Keys to collect network information

Module 6

Module 4

Assessments

Assignment Required

(W31M31A07) Exercise: Reconstructing a Remote Desktop Session

Assignment Required

(W31M31A08) Exercise: Putting it all together - simulation of a real forensics expertise in a Windows Environment

Quiz Required

(W31Q01) Windows Registry and Log Analysis Final Exam

Course access

Unlock Windows Registry and Log Analysis (W31).

Enter your email. We’ll send a sign-in code here without taking you away from this course.