Windows OS Forensics

Coursera MOOC / Non-credit USD 49
Enroll now →
Windows OS Forensics

About this course

The Windows OS Forensics course covers windows file systems, Fat32, ExFat, and NTFS. You will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. You will also learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable you to validate the information from multiple forensic tools properly.

What you'll learn

  • understand Windows file systems
  • learn the processes of file writing and deletion
  • gain skills in recovering deleted files
  • interpret file system data structures

Course objectives

  • provide a thorough understanding of data storage in Windows OS
  • equipped students with skills for file recovery
  • enable interpretation of forensic tool outputs

Skills you'll gain

Related courses

Course details are provided by the platform and may change — always confirm on the provider's site. Links may be affiliate links.