AWFE · Windows 11 forensics training

Advanced Windows 11 Forensic Exploitation (AWFE)

Expert-level Windows 11 forensics over five days: BitLocker, WSL and Sandbox, Registry and user activity, Helium apps, OneDrive, Chromium browsers and SQLite exploitation.

Dates
22–26 Feb 2027
Duration
5 days, 08:00–17:00
Level
Advanced
Seats
Limited number of seats
Windows 11 forensics training – Advanced Windows 11 Forensic Exploitation (AWFE)

Course overview

The Advanced Windows® Forensic Exploitation course offers expert-level training over the span of 5 days, tailored for digital examiners already well-versed in the fundamentals of digital forensics. This intensive program delves into advanced forensic techniques using an array of third-party tools, specifically honing in on the latest features of Microsoft’s operating system.

Throughout the course, participants will master the utilization of various applications and utilities crucial for the identification, processing, comprehension, and documentation of the latest Windows® 11 artifacts essential for comprehensive digital investigations. Topics covered include navigating the intricacies of chromium-based browsers, decrypting BitLocker encryption, analyzing newly-introduced Helium based apps, dissecting obscured application data, leveraging the Windows Subsystem for Linux and Sandbox environments, and scrutinizing other Windows® 11 specific artifacts. Additionally, students will explore methodologies for reviewing data distributed across multiple locations.

This comprehensive curriculum extends beyond surface-level understanding, offering deep insights into Windows 11 virtualized security measures, alongside comprehensive exploration of new Registry file functionalities and transaction logging. Core Windows artifacts will undergo thorough examination and analysis. The course culminates with an extensive exploration of OneDrive offline storage and synchronization processes across authenticated devices, shedding light on critical aspects of data management.

Of particular importance is the emphasis on SQLite forensics, which is pivotal in data analysis. Students will acquire proficiency in scripting and data exploitation, enhancing their investigative capabilities. By the end of the course, participants will have acquired advanced skills and a nuanced understanding of Windows® 11 forensic exploitation, empowering them to tackle complex digital investigations with confidence and precision.

Students will use a variety of open source and leading forensic applications to examine key artifacts through multiple hands-on labs and student exercises.

Who should attend

Digital examiners already well-versed in the fundamentals of digital forensics (at least 12 months of forensic examination experience).

Course modules (8)

Windows® Operating Systems Overview

This module introduces students to the key changes and enhancements found in modern Microsoft operating systems, with a primary focus on Windows 11. Students will examine newly introduced features, default security mechanisms, and system behaviors that directly impact incident response and forensic examinations. Through a guided walkthrough of Windows 11 from an end-user perspective, the module highlights updates to Windows Explorer, visual and interface changes, and how these differences affect evidence discovery and system navigation. Special attention is given to first responder considerations, including operating system access methods, shutdown behaviors, and the handling of mounted encrypted volumes such as BitLocker-protected drives and OneDrive Personal Vault data. By the end of the module, students will be better prepared to safely interact with live Windows 11 systems while preserving evidentiary integrity.

Handling BitLocker Encryption

This module provides an in-depth examination of Microsoft BitLocker encryption as implemented on both system partitions and removable media. Students will learn how BitLocker operates at a technical level, including its integration with modern Windows security features and its impact on data accessibility during forensic examinations.

The module guides students through identifying and interpreting BitLocker metadata stored within encrypted volumes, with a dedicated focus on BitLocker To Go and its use on removable storage devices. Recovery mechanisms are reviewed in scenarios where BitLocker protection has failed or access credentials are unavailable. The module concludes with structured workflows for the forensic analysis of BitLocker-protected volumes, emphasizing best practices, decision points, and evidence-handling considerations to support defensible and repeatable analysis.

Windows 11 Subsystem Analysis

This module examines modern Microsoft sub-systems and their role within contemporary Windows operating systems, with a focus on features that introduce additional execution environments and associated forensic artifacts. Students will explore what is new in Microsoft sub-system technologies and how these components extend system functionality while simultaneously increasing investigative complexity.

Specific emphasis is placed on Windows Sandbox and Windows Subsystem for Linux (WSL). Students will examine how Sandbox environments are deployed, used, and destroyed, along with the artifacts they may leave behind on the host system. The module also explores the practical and adversarial uses of Linux sub-systems on Windows operating systems and guides students through the identification and analysis of host-based WSL artifacts, enabling investigators to recognize and interpret sub-system activity during forensic examinations.

Registry Analysis on Windows 11 Systems

This module provides a foundational and investigative-focused overview of the Windows Registry and its significance in forensic examinations. Students will define the structure and purpose of the Windows Registry and examine the many forensic benefits it provides as a centralized repository of system and user activity. The module explores Windows 11 account types and recent updates that affect authentication, authorization, and user profiling. Students will learn how to track removable hardware usage across a Windows® 11 system using Registry-based artifacts and correlate these findings with other system data. The module concludes by examining Registry evidence of user interactions with the operating system, enabling investigators to reconstruct system usage patterns and support timeline-based analysis.

User Activity Analysis

This module focuses on Windows Shell artifacts that record user interaction with files, applications, and search functionality, with an emphasis on changes introduced in Windows 11. Students will review the structure and forensic value of Windows Shell Links (LNK files) and examine the updated Jump List functionality used by modern applications.

The module provides a detailed comparison of Automatic and Custom Jump Lists, including how cloud-based and synchronized files are referenced and tracked within Jump List artifacts. Students will conduct an in-depth analysis of Jump List databases, exploring backend storage formats and techniques for reconstructing timelines of user activity. The module also examines the Windows 11 Search function, including the extraction and interpretation of data from the new SQLite-based search databases. The module concludes with an introduction to Microsoft Copilot interactions and emerging considerations for forensic analysis of AI-assisted user activity.

Handling Helium Based Immersive Applications

This module examines helium-based applications introduced in modern Windows operating systems and the forensic artifacts they generate as a result of user interaction. Students will review the function and purpose of helium-based applications and how they differ architecturally from traditional Windows applications.

The module explores backend folder structures and newly introduced Registry files that store user activity and application state information. Particular attention is given to the new tab functionality and the associated backend binary files used to persist session data. Students will also explore the extensive use of SQLite databases within helium-based applications, with a focused examination of SQLite tables of forensic interest associated with the Windows Photos app. The module concludes with practical techniques for exploiting stored data using SQLite scripts and complementary analysis methods to support timeline reconstruction and user behavior analysis.

OneDrive Forensic Analysis

This module provides a comprehensive examination of the Microsoft OneDrive solution with a focus on forensic analysis of synchronized and cloud-resident data. Students will begin with an overview of the OneDrive architecture and review the various implementation options available across modern Windows operating systems, including personal, business, and device-based configurations.

The module examines the OneDrive encrypted Vault and the implications it presents during live response and post-acquisition analysis. Students will learn how to process offline files at the file system level and identify artifacts associated with file hydration and availability states. Additional topics include locating and interpreting synchronization log files, reviewing account owner and client configuration settings, and analyzing stored settings files. The module concludes with techniques for exploiting SQLite databases to identify and reconstruct recent file interactions and user activity within OneDrive.

Working with Chromium Based Browser Artifacts

This module focuses on the forensic examination of modern Chromium-based browser applications and associated communication artifacts within Windows operating systems. Students will review the architecture and behavior of Chromium-based browsers and examine how user activity is recorded across multiple backend data stores.

The module guides students through the extraction and analysis of browsing artifacts contained within various SQLite databases and JSON-encoded files, including history, downloads, cookies, and session data. Special attention is given to tab recovery and session restore data files, enabling reconstruction of browser usage following crashes or system shutdowns. The module also introduces LevelDB storage formats and basic analysis techniques commonly encountered in modern browser implementations. The module concludes with a review of Windows Mail artifacts and examination techniques, allowing students to correlate browser activity with email usage and communication timelines.

Prerequisites

To get the most out of this class, you should:

  • Have 12 months experience in forensic examinations
  • Attended Spyder Forensics Foundations training or similar program
  • Be familiar with Windows Operating systems.

Tools and techniques

  • Open-source and leading commercial forensic applications
  • SQLite scripts

Class materials and software

You will receive a student manual, lab exercises and other class-related material.

The course will adhere to adult learning principles, employing training aids such as presentations, diagrams, and practical instructor-led examples. Each covered artifact will be presented in either one or two 50-minute sessions, followed by review questions. Students will have opportunities throughout the course to ask questions and delve into covered objectives in greater detail. Practical exercises will be assigned each day to reinforce the topics.

Certificate

Official e-DiFTA certificate

Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Instructor

Zach Neeman

Zach Neeman

Senior Trainer / Developer, Spyder Forensics

Zach Neeman is a digital forensics leader, educator and subject matter expert in Windows forensic artefacts with extensive experience in DFIR operations, team development and professional training. Throughout his career, Zach has combined deep…

Full profile →

Frequently asked questions

What experience do I need for AWFE?

At least 12 months of experience in forensic examinations, Spyder Forensics Foundations training or a similar programme, and familiarity with Windows operating systems.

Who can attend this course?

Attendance is intended exclusively for law enforcement personnel, military personnel engaged in digital forensic activities and private-sector investigators.

What is included in the €2,500 fee?

Five days of hands-on training (08:00–17:00), an official certificate of successful completion recognising the training hours, a buffet lunch and morning and afternoon coffee breaks every day.

How are seats allocated?

Seats are limited and allocated on a “first paid – first confirmed” basis. Your registration is confirmed once payment is received; the payment deadline is 25 December 2026.

Do I receive a certificate?

Yes. Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.

Is VAT charged?

Invoices are issued from France. Private individuals and organisations in France pay French VAT (20%). Organisations outside France are invoiced without French VAT when they provide a valid VAT number, TIN or EIN. Full VAT rules.

Related courses

All 8 courses →
€2,500AWFE · 22–26 Feb 2027
Register →