What's inside?

  • How to review common Windows file systems, and which file system features might be useful in a DFIR investigation

  • How to examine Windows applications, such as chats, browsers, and mail clients

  • How to inspect media files and documents, and utilize media-specific analysis options such as text recognition and keyframe extraction

  • How to identify and analyze forensically important Windows system files, such as registry files, event logs, LNK files

  • How to get more evidence from a Windows data source by using carving, RAM analysis, and other advanced forensic techniques

Course curriculum

    1. Course Participation Agreement

    1. 1.1. Welcome and introduction

    2. 1.1.1. Course glossary

    3. 1.1.2. Tips and tricks

    4. 1.2. Download the course data

    5. 1.3. Belkasoft Evidence Center X: update or request a trial version

    6. 1.3.1. Installation guide

    7. 1.3.2. Add Belkasoft X to the list of antivirus and Windows Defender exceptions

    8. 1.3.2. Troubleshooting

    9. 1.4. Getting started with Belkasoft X

    10. 1.5. Course data

    11. 1.6. Open or create a case

    12. 1.7. Open the pre-configured case

    13. 1.8. (Alternative) Create a new case

    14. 1.8.1. (Alternative) Add and analyze the data sources

    1. 2.1. Overview

    2. 2.2. Data storage organization

    3. 2.3. FAT file systems

    4. 2.4. FAT forensics

    5. 2.5. BelkaQUIZ (4 questions)

    6. 2.6. NTFS file system

    7. 2.7. MFT

    8. 2.8. Alternate data streams

    9. 2.9. Data recovery in NTFS

    10. 2.10. BelkaQUIZ (6 questions)

    11. 2.11. Belkasoft File System window

    12. 2.12. Device properties

    13. 2.13. Filtering data in the File System

    14. 2.14. Advanced filters in the File System

    15. 2.15. BelkaLAB: advanced filters (3 tasks)

    16. 2.16. Hashset analysis in Belkasoft X

    17. 2.17. BelkaQUIZ (4 questions)

    18. 2.18. BelkaLAB: file system (4 tasks)

    1. 3.1. Introduction

    2. 3.2 Artifacts in Belkasoft X (video)

    3. 3.3. Artifacts in Belkasoft X (text)

    4. 3.4. Learn to use mini-timeline, global, and local filters (video)

    5. 3.5. How to search in Belkasoft X

    6. 3.5.1. Search tips

    7. 3.6. BelkaQUIZ (5 questions)

    1. 4.1. Introduction

    2. 4.2. Browsing apps

    3. 4.3. Chrome browser forensics

    4. 4.4. BelkaQUIZ: browsing history (4 questions)

    5. 4.5. BelkaLAB: browsing history (3 tasks)

    6. 4.6. Email forensics

    7. 4.7. BelkaQUIZ: email forensics (3 questions)

    8. 4.8. BelkaLAB: email forensic (3 tasks)

    1. 5.1. Introduction

    2. 5.2. Audio forensics

    3. 5.3. Picture forensics

    4. 5.4. Video forensics

    5. 5.5. Analyzing videos with multiple video streams

    6. 5.6. BelkaLAB: media (4 tasks)

    7. 5.7. BelkaQUIZ: media forensics (6 questions)

About this course

  • $999.00
  • 94 lessons

Social proof: reviews

5 star rating

Windows Forensic Course

Ty Fannon

This was an amazing course, full of valuable content related to forensic artifacts. I have been doing Windows Investigations for about 14 years and I found value in the content. Thank you Belkasoft for the great opportunity to Preview the Window...

Read More

This was an amazing course, full of valuable content related to forensic artifacts. I have been doing Windows Investigations for about 14 years and I found value in the content. Thank you Belkasoft for the great opportunity to Preview the Windows Forensics course and use the Belkasoft X software. Excellence is in the name.

Read Less
5 star rating

Very interesting course

Pietro Cavaliere

I found the course offered by Belkasoft very interesting and comprehensive. It was my first time interacting with their product, and thanks to this course, I discovered a very useful and, above all, complete software. Thank you very much!

I found the course offered by Belkasoft very interesting and comprehensive. It was my first time interacting with their product, and thanks to this course, I discovered a very useful and, above all, complete software. Thank you very much!

Read Less
5 star rating

Excellent Learning Experience in Windows Forensics

Mahmudur Rahman

The Windows Forensics with Belkasoft course provides an in-depth and practical approach to digital forensics, focusing specifically on Windows operating systems. The course materials are well-structured and cover a wide range of topics such as Mas...

Read More

The Windows Forensics with Belkasoft course provides an in-depth and practical approach to digital forensics, focusing specifically on Windows operating systems. The course materials are well-structured and cover a wide range of topics such as Master File Table (MFT), Alternate Data Streams (ADS), and timeline analysis. The real-life case studies offer valuable hands-on experience that is highly applicable to forensic investigations. The user interface of the Belkasoft software is intuitive, making the process of learning and applying forensic techniques seamless. It’s a must-take course for anyone pursuing digital forensics or IT security.

Read Less
5 star rating

Windows Forensics with Belkasoft

Ioannis Loutsis

It covers the most important parts in Digital forensics for WIndows

It covers the most important parts in Digital forensics for WIndows

Read Less
5 star rating

Course Review

Umut KARACALARLI

The training has been very useful both in revisiting the information about the windows operating system and also applying forensics techniques with Belkasoft X application. In the beginning it looked easier than it really is. Later I have noticed ...

Read More

The training has been very useful both in revisiting the information about the windows operating system and also applying forensics techniques with Belkasoft X application. In the beginning it looked easier than it really is. Later I have noticed that I needed to pay more attention to details. Belkasoft X is really a powerful tool and easy to use. Thank you for this valuable course and also for the product that you have built.

Read Less
5 star rating

Great 101 level Course

Jason Stanley

Just finished this course to help me prepare for SANS. This is a great intro to Windows forensics. The concepts were explained clearly and the exercises not only gives you a decent tour of the tool but how to navigate in the Windows file system no...

Read More

Just finished this course to help me prepare for SANS. This is a great intro to Windows forensics. The concepts were explained clearly and the exercises not only gives you a decent tour of the tool but how to navigate in the Windows file system no matter the tool. Highly recommend the course if you're starting your forensics career path.

Read Less
5 star rating

Sunanjay Narain

Sunanjay Narain

Despite being marketed as a basic course, the Windows Forensics training with Belkasoft went well beyond foundational concepts. It offered a deep dive into advanced forensic techniques, providing thorough, hands-on learning that significantly enha...

Read More

Despite being marketed as a basic course, the Windows Forensics training with Belkasoft went well beyond foundational concepts. It offered a deep dive into advanced forensic techniques, providing thorough, hands-on learning that significantly enhanced my skills and understanding of the complexities involved in digital forensics.

Read Less
5 star rating

A Comprehensive Tool

Jermaine Blake

Belkasoft X is a easy forensic tool to operate and provide a great analytical experience.

Belkasoft X is a easy forensic tool to operate and provide a great analytical experience.

Read Less
5 star rating

Windows Forensics with Belkasoft

Shauton Tindley

This is a great Windows forensics course that teaches tool agnostic principles in addition to the best ways to use Belkasoft X to successfully investigate Windows images. As such, I recommend this course to current and aspiring digital forensics p...

Read More

This is a great Windows forensics course that teaches tool agnostic principles in addition to the best ways to use Belkasoft X to successfully investigate Windows images. As such, I recommend this course to current and aspiring digital forensics professionals.

Read Less
5 star rating

Course review

M'paka Kossi NAPO

One word, amazing, I enjoy learning it. Thank you very much

One word, amazing, I enjoy learning it. Thank you very much

Read Less
5 star rating

Review: Windows Forensics with Belkasoft

Shubham Avhad

I recently completed the Windows Forensics with Belkasoft course, and I highly recommend it to anyone working in digital forensics and incident response (DFIR). The course provides a comprehensive and hands-on approach to analyzing Windows artifac...

Read More

I recently completed the Windows Forensics with Belkasoft course, and I highly recommend it to anyone working in digital forensics and incident response (DFIR). The course provides a comprehensive and hands-on approach to analyzing Windows artifacts, making it an excellent learning opportunity for both beginners and experienced investigators. The course was informative, practical, and well-paced. I particularly appreciated the deep dive into Windows system files and application analysis, which provided valuable insights into chat applications, web browsers, and media files. The section on advanced forensic techniques like data carving and embedded data analysis was especially useful for uncovering hidden evidence.

Read Less
5 star rating

course - Windows Forensics with Belkasoft

Emiliano Olivi

Thank you to Belkasoft for the opportunity granted for Windows Forensics course. the course was very interesting and covered topics in a specific and in-depth manner, allowing me to increase my skills

Thank you to Belkasoft for the opportunity granted for Windows Forensics course. the course was very interesting and covered topics in a specific and in-depth manner, allowing me to increase my skills

Read Less

Improve your skills in computer forensics

Grow with Belkasoft