Investigate Windows systems using forensic techniques that recover evidence of user activity, malware execution, and data theft. Covers registry analysis, browser artifacts, deleted file recovery, prefetch, shimcache, and timeline reconstruction for investigations that stand up to legal scrutiny.
Investigate Windows systems using forensic techniques that recover evidence of user activity, malware execution, and data theft. Build cases that stand up to legal scrutiny.
Windows dominates enterprise environments - and therefore dominates forensic investigations. FOR500 teaches the artifacts, tools, and techniques required to investigate incidents on Windows systems.
Extract evidence from Windows systems:
User Activity Analysis
Reconstruct user actions through registry artifacts
Analyze browser history and downloads
Recover deleted files and slack space
Track application execution and data access
System and Malware Artifacts
Identify persistence mechanisms
Analyze prefetch and shimcache
Examine scheduled tasks and services
Recover evidence of malware execution
Timeline and Reporting
Build comprehensive event timelines
Correlate artifacts across systems
Present findings clearly for legal review
Document chain of custody
Hands-on labs investigate realistic Windows systems with actual evidence to recover.
Earn GIAC GCFE certification (exam sold separately). 36 CPE credits across 6 intensive days.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing option: a single-user license for the FOR500: Windows Forensic Analysis course. You buy access for one person, and pricing is set per user with no tiers or size choices. To cover more people, you add more units under this same dimension. The course is a digital forensics and incident response offering that includes hands-on labs and maps to a related certification. Billing follows a contract model. There are no usage-based charges or add-on dimensions to select here.
Top-of-mind questions for buyers
What does one FOR500 single-user license cover for the person using it?
One license gives a single named person access to the FOR500: Windows Forensic Analysis course. The course runs 6 days instructor-led or 36 hours self-paced, with 22 hands-on labs. It maps to the related digital forensics examiner certification. Each additional person needs their own license unit.
How does cost change when I need to train more than one person?
Pricing is set per user with no tiers. To cover more people, you add more units under this same single-user dimension. Each unit stays priced the same regardless of how many you buy. The cost scales in direct proportion to the number of users licensed.
How long does my access to the FOR500 course content last after purchase?
Self-paced OnDemand access typically runs for a 4-month period, and you can request an extension if you cannot finish in time. Digital course materials and progress tracking are available during this window. For details on your specific access period, confirm with the vendor.
www.sans.org+1
Helpful?
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Get 24x7 access to our world-renowned Digital Forensics & Incident Response (DFIR) team with a DFIR Retainer. We provide unmatched industry knowledge, understanding of your local threat landscape and deep expertise across all stages of the breach response lifecycle.
Harness local Large Language Models for DFIR investigations without exposing sensitive data to third-party services. Learn to deploy self-hosted AI, build custom forensic agents, and analyze logs and artifacts using natural language queries.
Investigate cybercrime from initial indicators through attribution. Covers threat actor tracking, dark web investigations, cryptocurrency tracing, criminal community monitoring, and evidence collection for law enforcement support.
Master tactical, operational, and strategic cyber threat intelligence skills. Learn to collect, analyze, and operationalize threat data to improve detection and response capabilities. Build intelligence products that inform security decisions across your organization. 36 CPEs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.