Course outline(W31M04V03) Using PowerShell for Log Analysis Video
Your course
Windows Registry and Log Analysis (W31)
Module 1
Course content
Module 2
Before the course
Module 3
Module 1
- 1.(W31M01) An introduction to Windows Logging
- 2.(W31M02) The EVTX files
- 3.(W31M02V01) The EVTX files Video
- 4.(W31M03) Getting started with PowerShell
- 5.(W31M03V02) Getting started with PowerShell Video
- 6.(W31M04) Using PowerShell for Log Analysis
- 7.(W31M05) Useful logs in computer forensics
- 8.(W31M06) Logs from different channels
- 9.(W31M04V03) Using PowerShell for Log Analysis Video
Module 4
Module 2
- 1.(W31M09) An introduction to the Windows Registry
- 2.(W31M10) How the Registry works: Keys and values
- 3.(W31M11) The hives
- 4.(W31M12) Windows Registry extraction with FTK Imager
- 5.(W31M12V04) Windows Registry extraction with FTK Imager Video
- 6.(W31M13) Parsing the Registry with FTK Imager
- 7.(W31M13V05) Parsing the Registry with FTK Imager Video
- 8.(W31M14) Registry parsing with PowerShell: Get-ChildItem and Get-ItemProperty cmdlet
- 9.(W31M14V06) Registry parsing with PowerShell: Get-ChildItem and Get-ItemProperty cmdlet Video
- 10.(W31M17) Appendix to module 2
Module 5
Module 3
- 1.(W31M18) Registry Analysis with Registry Viewer
- 2.(W31M18V07) Registry Analysis with Registry Viewer Video
- 3.(W31M19) Machine and Operating System
- 4.(W31M19V08) Machine and Operating System Video
- 5.(W31M20) USB devices
- 6.(W31M20V09) USB devices Video
- 7.(W31M21) Users
- 8.(W31M21V10) Users Video
- 9.(W31M22) Applications
- 10.(W31M22V11) Applications Video
- 11.(W31M23) Network
- 12.(W31M23V12) Network Video
- 13.(W31M26) Appendix to module 3
Module 6
Module 4
- 1.(W31M27) Combining PowerShell with Log Parser
- 2.(W31M27V13) Combining PowerShell with Log Parser Video
- 3.(W31M28) Tracking Remote Desktop Sessions
- 4.(W31M29) Tracking Network Connections
- 5.(W31M29V14) Tracking Remote Desktop Sessions Video
- 6.(W31M30) A practical example - Unauthorized access from a corporate network
- 7.(W31M30V15) A practical example – Unauthorized access from a corporate network Video
Module 3Lesson 9
(W31M04V03) Using PowerShell for Log Analysis Video
Lesson videoLocked
Member lesson
Unlock the full lesson
Sign in to watch and unlock the course materials.
Course access
Unlock Windows Registry and Log Analysis (W31).
Enter your email. We’ll send a sign-in code here without taking you away from this course.