Hover a category to view courses…
Topics:
NTFS, FAT32, EXT4 structures
MFT records, timestamps, metadata
Slack space & unallocated space
Shellbags, LNK files, prefetch
Physical vs logical imaging
Recovering deleted files
Carving techniques
Journal analysis
Multi-artifact correlation
Timeline creation using file system + registry + logs
Detecting user activity patterns
Reconstructing intrusion behavior
Evidence interpretation
Professional reporting
Visualizing timelines
Reporting inaccuracies to avoid