The Windows Forensic Analysis and Advanced NTFS Investigation Course develops the practical skills required to investigate Windows systems, reconstruct user activity, and support incident response. Participants examine Windows forensic evidence from the Registry, Event Logs, Prefetch, AmCache, Shimcache, UserAssist, ShellBags, LNK files, Jump Lists, SRUM, browsers, email, USB devices, and cloud applications.
The course strengthens standard Windows Forensics Training with dedicated NTFS Forensics, including Master File Table Analysis, USN Journal Analysis, $LogFile, deleted-file examination, timestamps, and Windows Timeline Analysis. Participants learn how to correlate multiple artifacts rather than depend on a single source.
Realistic investigation scenarios cover insider threats, data leakage, malware activity, unauthorized access, renamed files, deleted evidence, removable media, and anti-forensic behavior. The NIST data-leakage case demonstrates how email, browsers, Windows Search, cloud storage, NTFS, and USB evidence can be combined into one investigative timeline.
By the end of this course, participants will be able to:
The course combines instructor-led sessions, practical demonstrations, guided investigations, group exercises, and case-study analysis. Participants learn the purpose, location, forensic value, and limitations of each Windows artifact.
Exercises focus on NTFS Forensic Analysis, Registry examination, program execution, Event Logs, Browser Forensics, Email Forensics, USB activity, and Windows Timeline Analysis. The NIST data-leakage case provides a realistic scenario involving confidential files, cloud uploads, removable media, renamed extensions, deleted evidence, and anti-forensic activity.
Participants work individually and in groups to identify evidence, test investigative hypotheses, reconstruct events, and present findings. Tool examples are introduced where relevant, but the course remains focused on investigative methods rather than one software platform.
Tool clarification: Software and licensed forensic tools are not provided. Participants receive insights, demonstrations, and examples of tools relevant to the course.
Participants should understand Windows operating systems, file structures, user accounts, networking, and basic cybersecurity concepts. Previous experience in incident response, system administration, SOC operations, or digital forensics is beneficial.
Each day's session is generally structured to last around 4–5 hours, with breaks and interactive activities included. The total course duration spans five days, approximately 20–25 hours of instruction.
Usually not. Investigators should correlate several artifacts, such as Prefetch, UserAssist, SRUM, Event Logs, AmCache, Shimcache, and Registry data. Some artifacts indicate only that a file existed, while others provide stronger evidence of execution.
This course gives NTFS Forensics a central role rather than treating it as a brief file-system overview. Participants examine $MFT, USN Journal, $LogFile, timestamps, deleted records, and alternate data streams in detail.
It also connects NTFS evidence with Windows Registry Forensics, Event Logs, Prefetch, AmCache, Shimcache, UserAssist, SRUM, ShellBags, Browser Forensics, Email Forensics, and USB activity.
The course is tool-independent and focuses on evidence interpretation, artifact correlation, timeline reconstruction, and defensible conclusions. A realistic data-leakage case connects technical analysis to corporate risks such as insider threats, intellectual-property theft, unauthorized cloud transfers, and removable-media misuse
credits: 5 credit per day
Course Mode: full-time
Provider: Agile Leaders Training Center
London 05 - 09 Oct 2026
London 14 - 18 Sep 2027
Course Overview:The Windows Forensic Analysis and Advanced NTFS Investigation Course develops the practical skills required to investigate Windows systems, reconstruct user activity, and support incident response. Participants examine Windows forensic evidence from the Registry, Event Logs, Prefetch, AmCache, Shimcache, UserAssist, ShellBags, LNK files, J…
Yes. Available dates and destinations are listed in the course dates section on this page.
Choose an available date on this page and complete the registration form, or send a programme enquiry.
Yes. Use the brochure download link provided on this page.