Investigate Windows systems using forensic techniques that recover evidence of user activity, malware execution, and data theft. Covers registry analysis, browser artifacts, deleted file recovery, prefetch, shimcache, and timeline reconstruction for investigations that stand up to legal scrutiny.
Investigate Windows systems using forensic techniques that recover evidence of user activity, malware execution, and data theft. Build cases that stand up to legal scrutiny.
Windows dominates enterprise environments - and therefore dominates forensic investigations. FOR500 teaches the artifacts, tools, and techniques required to investigate incidents on Windows systems.
Extract evidence from Windows systems:
User Activity Analysis
Reconstruct user actions through registry artifacts
Analyze browser history and downloads
Recover deleted files and slack space
Track application execution and data access
System and Malware Artifacts
Identify persistence mechanisms
Analyze prefetch and shimcache
Examine scheduled tasks and services
Recover evidence of malware execution
Timeline and Reporting
Build comprehensive event timelines
Correlate artifacts across systems
Present findings clearly for legal review
Document chain of custody
Hands-on labs investigate realistic Windows systems with actual evidence to recover.
Earn GIAC GCFE certification (exam sold separately). 36 CPE credits across 6 intensive days.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing option: a single-user license for the FOR500: Windows Forensic Analysis course. You buy access for one person, and pricing is set per user with no tiers or size choices. To cover more people, you add more units under this same dimension. The course is a digital forensics and incident response offering that includes hands-on labs and maps to a related certification. Billing follows a contract model. There are no usage-based charges or add-on dimensions to select here.
Top-of-mind questions for buyers
What does one FOR500 single-user license cover for the person using it?
One license gives a single named person access to the FOR500: Windows Forensic Analysis course. The course runs 6 days instructor-led or 36 hours self-paced, with 22 hands-on labs. It maps to the related digital forensics examiner certification. Each additional person needs their own license unit.
How does cost change when I need to train more than one person?
Pricing is set per user with no tiers. To cover more people, you add more units under this same single-user dimension. Each unit stays priced the same regardless of how many you buy. The cost scales in direct proportion to the number of users licensed.
How long does my access to the FOR500 course content last after purchase?
Self-paced OnDemand access typically runs for a 4-month period, and you can request an extension if you cannot finish in time. Digital course materials and progress tracking are available during this window. For details on your specific access period, confirm with the vendor.
www.sans.org+1
Helpful?
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Conduct detailed, in-depth forensic analysis on raw data from Mac and iOS cases. Learn APFS file system examination, log analysis, metadata extraction, and investigation of Apple-specific technologies like Time Machine, FileVault, AirTags, and FindMy. Build confidence in handling Mac and iOS incident response investigations.
Investigate cloud compromises across AWS, Azure, and GCP using forensic techniques designed for cloud-native evidence. Covers CloudTrail analysis, Azure AD investigation, container forensics, serverless examination, and Kubernetes incident response.
Learn to hunt for and respond to advanced persistent threats through deep forensic analysis. Covers memory forensics, malware analysis, lateral movement detection, and enterprise-scale incident response techniques for identifying sophisticated adversaries who evade standard defenses.
Extract and analyze evidence from smartphones and mobile devices. Covers logical and physical acquisition, lock bypass, app analysis, deleted data recovery, location artifacts, and cloud-synced data. Learn to validate findings and produce court-ready reports.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.