Back to Windows OS Forensics
Infosec

Windows OS Forensics

The Windows OS Forensics course covers windows file systems, Fat32, ExFat, and NTFS. You will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. You will also learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable you to validate the information from multiple forensic tools properly.

Status: Data Storage
Status: Data Validation
IntermediateCourse8 hours

Featured reviews

JB

Reviewed Dec 25, 2022

It is a well written course for those starting out in Digital Forensics such as myself. Highly recommended for those who wish to understand the importance of file systems in Forensics

MY

Reviewed Nov 8, 2021

A very good course. But need improvement, since it called Windows OS Forensics, it should cover more about Windows artifacts. But overall, great content. Thanks a lot.

AA

Reviewed Sep 16, 2021

Excellent Course with very clear cut explanations. Thank you !!!

AT

Reviewed Sep 21, 2021

there are some mistakes (questions 4 and 45) in the final quiz.

AR

Reviewed Sep 23, 2022

v​ery intresting course that helped to me analyze the window deeply. Also helpful to the real life.

All reviews

Showing: 20 of 27

Ashish
Reviewed Sep 23, 2022
Apoorva
Reviewed Sep 17, 2021
Ian
Reviewed Jan 5, 2024
Amb
Reviewed May 25, 2025
Jomel
Reviewed Dec 25, 2022
mr
Reviewed Nov 8, 2021
Alejandro
Reviewed Mar 14, 2024
Anh
Reviewed Sep 22, 2021
Sean
Reviewed Aug 5, 2022
Mohammad
Reviewed Sep 11, 2021
Muhammad
Reviewed Dec 2, 2023
pasan
Reviewed Jun 14, 2022
ISAAC
Reviewed Jun 29, 2026
JALIL
Reviewed Feb 22, 2022
José
Reviewed Jul 21, 2021
Severino
Reviewed Nov 26, 2024
DIYA
Reviewed Jun 29, 2026
ابوبكر
Reviewed Oct 19, 2025
Ali
Reviewed Dec 23, 2021
kommareddy
Reviewed Apr 8, 2026