SECURITY 508SECURITY 508


GIAC Certification Available
CCE Bootcamp Logo

Course PDF

Investigations involving Windows-based operating systems occur frequently. As a result, it is essential to make an in-depth study and examination of the forensic evidence left on Windows-based operating systems. This hands-on forensic course will arm you with methods and techniques to respond and investigate complex events for your organization. It covers Windows methods that will ensure maximum evidence capture without poisoning key evidence that might reside on the system and in memory.

You will learn how to use freely available Windows tools and methods to secure a system without disturbing it, discover hidden malware, and find hidden clues that may still reside on the system. Each student will also learn how to examine restore point snapshots in Windows XP and examine Shadow Copy volumes on Windows Vista and Windows 7.

This course covers Microsoft Windows 2000, Windows XP, Windows 2003, Windows Vista, and Windows 7. Even though they all use NTFS or FAT for the file system, each one is different and there are some variations on the type of forensic data that might be found on each operating system.




  • Key Windows File System Analysis Concepts
    • How to Mount/Examine Windows Forensic Images
    • Difference in Vista/XP Forensics
    • Detecting Malware Easily
    • Restore Points, Shadow Copy, and Registry Data
    • Recovering Deleted Windows Key Files
  • Windows Incident Response Methodology
    • Collecting Volatile Data Automatically
    • Recovering Passwords
    • Getting Around Locked Computer (Screensaver)
    • Proper Way to Execute Command Prompts
  • Windows Registry Analysis for Forensic Analysts
    • Registry Hive Basics
    • Timeline of Registry Last Write Times
    • Registry Slack
    • Deleted Registry Artifacts
  • Restore Point and Shadow Copy Forensics
    • Acquiring Shadow Copy Volume Image
    • Shadow Copy Data Analysis
    • XP Restore Point Data Analysis
    • Looking at Registry Files in XP Restore Point
  • Day 4 Exercises
    • Examine System Registry For User and Application Forensic Data
    • Using Automated Toolkits to Collect Information from Windows-Based Systems
    • Using Autopsy, Foremost, and The Sleuth Kit to Examine NTFS/FAT Image
    • Recover Files from a USB Key Used in a Crime
    • Utilize Prefetch, Registry Forensics, Restore Points, and More in a Real Case
SECURITY 508 Upcoming Events
Event Location Dates Delivery Method
SANS SelfStudyBooks & MP3s OnlyAnytimeSelf Paced
SANS OnDemandOnlineAnytimeSelf Paced
SANS London 2009London, United KingdomNov 28, 2009 - Dec 06, 2009Live Event
Community SANS Tucson 2009Tucson, AZNov 30, 2009 - Dec 05, 2009Community SANS
Community SANS Colorado Springs 2009Colorado Springs, CONov 30, 2009 - Dec 05, 2009Community SANS
Mentor Session - SEC508Atlanta, GADec 02, 2009 - Feb 17, 2010Mentor
Mentor Session - SEC508Medellín, ColombiaDec 02, 2009 - Dec 04, 2009Mentor
SANS CDI East 2009Washington DCDec 11, 2009 - Dec 18, 2009Live Event
Mentor Session - Security 508Charlotte, NCJan 14, 2010 - Mar 18, 2010Mentor
Mentor Session - Security 508Denver, COJan 19, 2010 - Mar 23, 2010Mentor
Community SANS Lake Tahoe 2010Lake Tahoe, CAJan 25, 2010 - Jan 30, 2010Community SANS
SANS Phoenix 2010Phoenix, AZFeb 14, 2010 - Feb 20, 2010Live Event
SANS India 2010Bangalore, IndiaFeb 22, 2010 - Feb 27, 2010Live Event
SANS 2010Orlando, FLMar 06, 2010 - Mar 15, 2010Live Event
Mentor Session - SEC508Greeley, COMar 11, 2010 - May 13, 2010Mentor
Community SANS Boston 2010Boston, MAMar 15, 2010 - Mar 20, 2010Community SANS
SANS vLive! - SEC 508 - Rob LeeSANS vLive! SEC508 - 201003, VAMar 23, 2010 - Apr 29, 2010
SANS Northern Virginia Bootcamp 2010Reston, VAApr 06, 2010 - Apr 13, 2010Live Event
Mentor Session - SEC508Boise, IDSep 28, 2010 - Nov 30, 2010Mentor
"This is awsome! We're seeing details that most people don't even know exist" - John Wright, Info Tech, Inc.
"The class provided in-depth, real world, hands-on information" - Robert Dale Drollinger, General Dynamics
SANS Institute