❗The content presented here is sourced directly from Udemy platform. For comprehensive course details, including enrollment information, simply click on the 'Go to class' link on our website.
Updated in [July 27th, 2023]
This course, Surviving Digital Forensics: Windows Shellbags, is designed to help computer forensic examiners become better at their craft. In this class, participants will learn how to use Windows Shellbag records to prove file use and knowledge. Shellbag records are created by certain user activity and can be used to show where a user has navigated to on a computer system and when they did so.
The class begins with a brief overview of the issue at hand, followed by a hands-on approach to learning. Low cost and no cost computer forensic tools will be used to extract and analyze Windows Shellbag evidence. Expert and novice computer forensic examiners alike will gain from this class.
The course outline includes: Introduction and Welcome to the SDF series; Getting the most out of the class; Windows Shellbags - an overview; Shellbag Deep Dive; Setting up your forensic system; Validation practical 01 - local system activity; Validation practical 02 - attached USBs; Validation practical 03 - networked drives; Student Practical; Student Quiz; Reporting options; Review; Conclusion & thank you.
A PC running Win7 or Win8 is required for this course, with admin rights to the system. The system should be a test system containing no critical data. The forensic tools used are all freely available.
Course Syllabus
Introduction
Understanding Windows Shellbags
Getting Setup for the Practicals
Shellbag Validation Practicals 01 - Local System Activity
Shellbag Validation Practicals 02 - Attached USBs
Shellbags Validation Practical 03 - Networked Drives
Conclusion