Overview
Investigate Windows systems using forensic techniques that recover evidence of user activity, malware execution, and data theft. Build cases that stand up to legal scrutiny.
Windows dominates enterprise environments - and therefore dominates forensic investigations. FOR500 teaches the artifacts, tools, and techniques required to investigate incidents on Windows systems.
Extract evidence from Windows systems:
User Activity Analysis
- Reconstruct user actions through registry artifacts
- Analyze browser history and downloads
- Recover deleted files and slack space
- Track application execution and data access
System and Malware Artifacts
- Identify persistence mechanisms
- Analyze prefetch and shimcache
- Examine scheduled tasks and services
- Recover evidence of malware execution
Timeline and Reporting
- Build comprehensive event timelines
- Correlate artifacts across systems
- Present findings clearly for legal review
- Document chain of custody
Hands-on labs investigate realistic Windows systems with actual evidence to recover.
Earn GIAC GCFE certification (exam sold separately). 36 CPE credits across 6 intensive days.
Highlights
- Master Windows forensic artifacts: Registry analysis, browser history, deleted file recovery, prefetch, shimcache, scheduled tasks, and persistence mechanisms. Build tool-agnostic analysis skills.
- 22 hands-on labs: Carve files from free space, analyze application execution, examine USB device history, search email attachments, parse crash recovery files, and build comprehensive timelines.
- Prepares for GIAC GCFE certification. Built for forensic analysts and incident responders investigating Windows systems. 6 days, 36 CPEs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
FOR500 - Single User | Single user license for DFIR - FOR500: Windows Forensic Analysis | $8,780.00 |
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.