0%

Explore Courses Defend What Matters

Your Bag

Computer & Disk Forensics

04 Digital Forensics

Computer & Disk Forensics

Recover deleted files and reconstruct user activity from Windows and Linux artefacts that most people never know exist.

Levels
04
Skill Range
Beginner Expert
Track
Digital Forensics
Lifetime Access
Computer & Disk Forensics
From 244CREDS

A disk holds far more history than its file listing suggests. This course teaches you to read it. You will carve deleted files from unallocated space, interpret slack space, and work with recovery when metadata is gone. Windows artefacts are covered in depth: the registry hives that record devices and program execution, prefetch, shellbags, LNK files, jump lists, the USN journal, and the event logs that timestamp it all. Linux gets equivalent treatment through logs, bash history, systemd journals, and timestamps. You will build a timeline that merges these sources into a single sequence of events, then practise anti-forensics detection: timestomping, wiping, and the traces both leave. Autopsy and The Sleuth Kit are used throughout.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    244 CREDS

    Purpose

    Carve deleted files from a disk that holds more history than its file listing shows.

    Outcome

    You can recover files a normal listing does not show.

    What You'll Learn
    • Carve files from unallocated space by signature.
    • Interpret slack space and what it can retain.
    • Recover data when the metadata is gone.
  2. Level 02

    Intermediate

    487 CREDS

    Purpose

    Read Windows artefacts that record activity most users never know exists.

    Outcome

    You can reconstruct user activity from Windows artefacts.

    What You'll Learn
    • Analyse registry hives for devices and program execution.
    • Interpret prefetch, shellbags, LNK files, and jump lists.
    • Read the USN journal and event logs for timestamps.
  3. Level 03

    Advanced

    700 CREDS

    Purpose

    Cover Linux artefacts and build a unified timeline.

    Outcome

    You can build a single timeline across multiple systems.

    What You'll Learn
    • Analyse logs, bash history, and systemd journals on Linux.
    • Merge Windows and Linux sources into one sequence of events.
    • Resolve conflicting timestamps into a coherent order.
  4. Level 04

    Expert

    1,073 CREDS

    Purpose

    Detect anti-forensics, since a capable adversary tries to erase the trail.

    Outcome

    You can detect attempts to hide or falsify evidence.

    What You'll Learn
    • Detect timestomping by cross-referencing timestamp sources.
    • Identify wiping and the traces it leaves behind.
    • Work through a case in Autopsy and The Sleuth Kit and report it.