Catalogue · MOD-DEF-08

Windows Forensics

When a Windows host is compromised, the investigator reconstructs what happened. This module trains you in forensic investigation: evidence acquisition, artefacts, memory, timeline and admissible report.

Defence (Blue) Praticien 6 bricks 10 labs 18.5 h 5 real cases

Objectives

• Acquire evidence while preserving its integrity • Reconstruct execution and persistence • Analyse memory (Volatility) • Build a timeline and an admissible report

Module bricks