Media Summary: Official Training Courses from 13Cubed! If you are looking for an online, on-demand, comprehensive, and affordable TryHackMe recently released a room dedicated to I talk about conducting triage image. Artifacts: Registry HIVES (SAM, SYS, DEFAULT, USERCLASS, NTUSER), .evtx, .lnk, .pf, ...

Windows Forensics Analysis Part1 Identify - Detailed Analysis & Overview

Official Training Courses from 13Cubed! If you are looking for an online, on-demand, comprehensive, and affordable TryHackMe recently released a room dedicated to I talk about conducting triage image. Artifacts: Registry HIVES (SAM, SYS, DEFAULT, USERCLASS, NTUSER), .evtx, .lnk, .pf, ... In this DFIR exercise on Lets Defend, we are supplied an AD1 file to mount with FTK Imager and use Eric Zimmerman's tools to ... Choose your training here: Advance your career and develop skills to better protect your organization. Part 2 ///Part 3 Coming Soon Every month it seems there are seemingly more

Photo Gallery

Windows Forensics Analysis- Part1, Identify Exploit- Exfiltration, Diwali GiveAway
044 File forensics part1 : Windows Forensics
Windows Artifacts Basic Digital Forensic Analysis
Introduction to Windows Forensics
Intro to Windows Forensics: Windows Registry Artifacts - TryHackMe Walkthrough
Windows Forensics Analysis- Part2, Identify Recon- Delivery- Persistence
Windows Forensics Analysis: Triage Image
DFIR - Windows Forensics - Part 1
FOR500: Windows Forensics Analysis
Part 1-Five Windows Forensic Artifacts for Every Incident Response | Jake Williams
Windows Forensics 1 | Beginner DFIR Walkthrough | TryHackMe | SOC Level 1
FA2025 Purple: Windows Forensics (2025-10-16)
View Detailed Profile
Windows Forensics Analysis- Part1, Identify Exploit- Exfiltration, Diwali GiveAway

Windows Forensics Analysis- Part1, Identify Exploit- Exfiltration, Diwali GiveAway

This Episode is focused on

044 File forensics part1 : Windows Forensics

044 File forensics part1 : Windows Forensics

Windows Forensics

Windows Artifacts Basic Digital Forensic Analysis

Windows Artifacts Basic Digital Forensic Analysis

Module 2-

Introduction to Windows Forensics

Introduction to Windows Forensics

Official Training Courses from 13Cubed! If you are looking for an online, on-demand, comprehensive, and affordable

Intro to Windows Forensics: Windows Registry Artifacts - TryHackMe Walkthrough

Intro to Windows Forensics: Windows Registry Artifacts - TryHackMe Walkthrough

TryHackMe recently released a room dedicated to

Windows Forensics Analysis- Part2, Identify Recon- Delivery- Persistence

Windows Forensics Analysis- Part2, Identify Recon- Delivery- Persistence

This Episode is focused on

Windows Forensics Analysis: Triage Image

Windows Forensics Analysis: Triage Image

I talk about conducting triage image. Artifacts: Registry HIVES (SAM, SYS, DEFAULT, USERCLASS, NTUSER), .evtx, .lnk, .pf, ...

DFIR - Windows Forensics - Part 1

DFIR - Windows Forensics - Part 1

In this DFIR exercise on Lets Defend, we are supplied an AD1 file to mount with FTK Imager and use Eric Zimmerman's tools to ...

FOR500: Windows Forensics Analysis

FOR500: Windows Forensics Analysis

Choose your training here: http://www.sans.org/u/wXD Advance your career and develop skills to better protect your organization.

Part 1-Five Windows Forensic Artifacts for Every Incident Response | Jake Williams

Part 1-Five Windows Forensic Artifacts for Every Incident Response | Jake Williams

Part 2 https://youtu.be/TggbtBxz2nQ ///Part 3 Coming Soon Every month it seems there are seemingly more

Windows Forensics 1 | Beginner DFIR Walkthrough | TryHackMe | SOC Level 1

Windows Forensics 1 | Beginner DFIR Walkthrough | TryHackMe | SOC Level 1

In this walkthrough of the TryHackMe

FA2025 Purple: Windows Forensics (2025-10-16)

FA2025 Purple: Windows Forensics (2025-10-16)

This Purple Team meeting covers

Windows Forensics 04 - Windows Forensics Basics

Windows Forensics 04 - Windows Forensics Basics

What can we have to do the