FSIS 644 Windows Forensic Examinations

3 credits

Computer forensic investigators must be proficient in each of the system platform environments. This course provides information essential to the performance of a forensic examination on a computer running the Microsoft Windows Operating System. Exercises focus on disk level forensic tools and techniques. This course focuses on the underlying operation of automated forensic tools, identifying the most appropriate forensic tool to be used in specific circumstances, and defending their use of forensic tools in the courtroom under cross examination. The course will use leading edge tools from X-Ways, Helix, and EnCase.

Prerequisite(s): FSIS 642 File System Forensic Analysis AND FSIS 643 Incident Response and Evidence Collection