Learning Outcomes
What You'll Learn
βEstablish legal authority before any examination β consent, warrants, and corporate authorization
βPerform forensically sound dead-box and live acquisitions with write blockers and hash verification
βAnalyze Windows NTFS artifacts β MFT, $UsnJrnl, MACE timestamps, and deleted file recovery
βExtract and interpret browser history, email artifacts, and user activity from Windows and macOS
βIdentify USB connection artifacts and connect device usage to specific users via registry and LNK files
βBuild defensible event timelines from multiple artifact sources without timestamp interpretation errors
βOperate Autopsy, FTK, and X-Ways workflows and cross-validate critical findings across tools
βWrite court-ready forensic reports that separate findings from opinions and withstand cross-examination