The Windows OS Forensics course covers windows file systems, Fat32, ExFat, and NTFS. You will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. You will also learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable you to validate the information from multiple forensic tools properly.



Windows OS Forensics
This course is part of Computer Forensics Specialization

Instructor: Denise Duffy
Access provided by The National Institute of Engineering
7,298 already enrolled
(80 reviews)
Recommended experience
What you'll learn
- The student will learn about the windows file systems, Fat32, ExFat, and NTFS. 
- Students will learn how these systems store data, what happens when a file gets written to disc, & what happens when a file gets deleted from disc. 
- Students will learn how to recover deleted files. 
Skills you'll gain
Details to know

Add to your LinkedIn profile
1 assignment
See how employees at top companies are mastering in-demand skills

Build your subject-matter expertise
- Learn new concepts from industry experts
- Gain a foundational understanding of a subject or tool
- Develop job-relevant skills with hands-on projects
- Earn a shareable career certificate

There are 6 modules in this course
This module explains the various numbering schemas used throughout computer forensics. In this module, you'll explore the numbering schemas used in computer forensics. This knowledge allows the student to interpret data at the hex and binary levels. This skill is necessary to validate forensic software tools and gives the student an understanding of where to locate the data displayed by their forensic software. This information is notably beneficial for court proceedings.
What's included
4 videos
A look at the master boot record and the GUID partition table. This module demonstrates the difference between the master boot record and the GUID partition table. This information gives the student an understanding of where to locate both partitions and data on the drive. The forensic student learns how to interpret the master boot record and locate the volume boot record for each volume on the drive.
What's included
6 videos
This module explores the structure of the FAT file system. This module covers the structure and layout of the FAT file system. The student develops an understanding of how the FAT file system writes a file to a drive and deletes a file from a drive. With this knowledge, the examiner can recover deleted data or recover data from a reformatted drive.
What's included
6 videos
In this module, you'll explore the details of the NTSF file system. NTSF is a crucial component of forensic examinations. This module explains how the file system organizes information and where data is located on the drive. It also covers where the metadata for the file is stored and the changes that occur at a file system level when someone deletes or creates a file.
What's included
6 videos
Take a closer look at the details of the ex-FAT file system. In this module, the student learns the structure and layout of the ex-FAT file system, how the file system tracks files, where it stores the file metadata and how to recover deleted data.
What's included
5 videos
Explore the complexities and challenges of Windows Registry forensics. This module covers the history and function of the Registry. It includes how to examine the live Registry, the location of the Registry files on the forensic image and how to extract files. After examining the files with forensic tools, the student can locate relevant artifacts such as USB device connection times, recently used documents, program last run times and programs set to run at startup.
What's included
4 videos1 assignment
Earn a career certificate
Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.
Instructor

Offered by
Why people choose Coursera for their career




Learner reviews
80 reviews
- 5 stars72.50% 
- 4 stars23.75% 
- 3 stars2.50% 
- 2 stars0% 
- 1 star1.25% 
Showing 3 of 80
Reviewed on Nov 8, 2021
A very good course. But need improvement, since it called Windows OS Forensics, it should cover more about Windows artifacts. But overall, great content. Thanks a lot.
Reviewed on Sep 21, 2021
there are some mistakes (questions 4 and 45) in the final quiz.
Reviewed on Sep 23, 2022
very intresting course that helped to me analyze the window deeply. Also helpful to the real life.
Explore more from Information Technology
 - Infosec 
 - Infosec 
 - Infosec 
 - Nanyang Technological University, Singapore 

