The Advanced Windows® Forensic Exploitation course offers expert-level training over the span of 5 days, tailored for digital examiners already well-versed in the fundamentals of digital forensics. This intensive program delves into advanced forensic techniques using an array of third-party tools, specifically honing in on the latest features of Microsoft’s operating system.
Throughout the course, participants will master the utilization of various applications and utilities crucial for the identification, processing, comprehension, and documentation of the latest Windows® 11 artifacts essential for comprehensive digital investigations. Topics covered include navigating the intricacies of chromium-based browsers, decrypting BitLocker encryption, analyzing newly-introduced Helium based apps, dissecting obscured application data, leveraging the Windows Subsystem for Linux and Sandbox environments, and scrutinizing other Windows® 11 specific artifacts. Additionally, students will explore methodologies for reviewing data distributed across multiple locations.
This comprehensive curriculum extends beyond surface-level understanding, offering deep insights into Windows 11 virtualized security measures, alongside comprehensive exploration of new Registry file functionalities and transaction logging. Core Windows artifacts will undergo thorough examination and analysis. The course culminates with an extensive exploration of OneDrive offline storage and synchronization processes across authenticated devices, shedding light on critical aspects of data management.
Of particular importance is the emphasis on SQLite forensics, which is pivotal in data analysis. Students will acquire proficiency in scripting and data exploitation, enhancing their investigative capabilities. By the end of the course, participants will have acquired advanced skills and a nuanced understanding of Windows® 11 forensic exploitation, empowering them to tackle complex digital investigations with confidence and precision.
Students will use a variety of open source and leading forensic applications to examine key artifacts through multiple hands-on labs and student exercises.