A disk holds far more history than its file listing suggests. This course teaches you to read it. You will carve deleted files from unallocated space, interpret slack space, and work with recovery when metadata is gone. Windows artefacts are covered in depth: the registry hives that record devices and program execution, prefetch, shellbags, LNK files, jump lists, the USN journal, and the event logs that timestamp it all. Linux gets equivalent treatment through logs, bash history, systemd journals, and timestamps. You will build a timeline that merges these sources into a single sequence of events, then practise anti-forensics detection: timestomping, wiping, and the traces both leave. Autopsy and The Sleuth Kit are used throughout.