Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Entry-level

Windows Forensic Analysis

Windows forensics training in Toronto has to cover the operating system people actually use, so this course runs through Windows 11. You learn artifacts first and tools second, which means your findings never depend on one vendor's parser.

Ten weeks leaves room to go deep: registry hives, evidence of execution, shell items, removable device history, email, event logs and browsers, closing with a full capstone investigation you report on.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
Windows Forensic Analysis

What you will be able to do

  • Parse registry hives directly and explain what each key proves
  • Reconstruct program execution from prefetch, SRUM, amcache and shimcache
  • Trace file and folder access through LNK files, jump lists and shellbags
  • Profile removable device use down to serial number and first connection
  • Recover browser history, downloads, cache and session data across Chrome, Edge and Firefox
  • Read Windows event logs for authentication, service and account changes
  • Build a defensible timeline of user activity from several artifact sources
  • Write an investigation report a non-technical reviewer can follow

Course outline

6 modules

  • NTFS metadata: master file table, USN journal and logfile
  • File system timestamps and what changes them
  • Volume shadow copies as historical evidence
  • Recycle bin, deleted files and slack space
  • Mounting and processing images without altering them

What you need before you start

  • Everyday Windows administration or power user familiarity
  • Evidence handling experience is helpful but not required
  • A machine with 16 GB of RAM, 200 GB free and virtualisation enabled
  • A few hours each week for lab work between sessions

Who this course is for

  • Analysts moving from IT support into forensics
  • SOC and incident response staff who need artifact level detail
  • Corporate investigators handling fraud, misuse and departing employee cases
  • eDiscovery and legal technology staff who assess forensic findings
  • Examiners refreshing technique that does not depend on one product

Where this leads

Prepares you for

CHFI

Awarded by EC-Council

This course lines up closely with the Windows analysis portions of the Computer Hacking Forensic Investigator syllabus. Examination and issuing of the CHFI credential are handled entirely by EC-Council. The academy supplies the training and the lab time, not the certificate.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.