Windows Forensic Analysis
Windows forensics training in Toronto has to cover the operating system people actually use, so this course runs through Windows 11. You learn artifacts first and tools second, which means your findings never depend on one vendor's parser.
Ten weeks leaves room to go deep: registry hives, evidence of execution, shell items, removable device history, email, event logs and browsers, closing with a full capstone investigation you report on.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Parse registry hives directly and explain what each key proves
- Reconstruct program execution from prefetch, SRUM, amcache and shimcache
- Trace file and folder access through LNK files, jump lists and shellbags
- Profile removable device use down to serial number and first connection
- Recover browser history, downloads, cache and session data across Chrome, Edge and Firefox
- Read Windows event logs for authentication, service and account changes
- Build a defensible timeline of user activity from several artifact sources
- Write an investigation report a non-technical reviewer can follow
Course outline
6 modules
- NTFS metadata: master file table, USN journal and logfile
- File system timestamps and what changes them
- Volume shadow copies as historical evidence
- Recycle bin, deleted files and slack space
- Mounting and processing images without altering them
What you need before you start
- Everyday Windows administration or power user familiarity
- Evidence handling experience is helpful but not required
- A machine with 16 GB of RAM, 200 GB free and virtualisation enabled
- A few hours each week for lab work between sessions
Who this course is for
- Analysts moving from IT support into forensics
- SOC and incident response staff who need artifact level detail
- Corporate investigators handling fraud, misuse and departing employee cases
- eDiscovery and legal technology staff who assess forensic findings
- Examiners refreshing technique that does not depend on one product
Where this leads
Prepares you for
CHFI
Awarded by EC-Council
This course lines up closely with the Windows analysis portions of the Computer Hacking Forensic Investigator syllabus. Examination and issuing of the CHFI credential are handled entirely by EC-Council. The academy supplies the training and the lab time, not the certificate.
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



