Windows Endpoint Investigation
Learn to Investigate Windows Systems Like a Professional Investigator
Answer the questions that matter: What ran? Who was here? How did the attacker move? What persistence did they install? What data left the network? What did they try to hide? Work through real forensic artifacts, build timelines across multiple hosts, detect anti-forensics, and complete two full capstone investigations.
What you'll be able to do
Course Syllabus
Every module and every lesson. Open a module to see its lessons.
Download the full syllabus (PDF)
Phase 1: Foundations
What Windows Endpoint Investigation teaches: how to reconstruct an attack from the evidence a Windows system leaves behind.
6 lessonsHide lessons
- WF0.1 What Forensic Analysis IsPreview
- WF0.2 How This Course Is StructuredPreview
- WF0.3 The Forensic ToolstackPreview
- WF0.4 What Windows Records Without Being AskedPreview
- WF0.5 Best PracticesPreview
- WF0 Module SummaryPreview
How to collect and preserve Windows forensic evidence in the correct order, with the correct tools, producing an analysis-ready evidence package.
12 lessonsHide lessons
- WF1.1 Order of Volatility and Collection Decisions
- WF1.2 Encryption Before You Image
- WF1.3 Memory Acquisition and Extraction
- WF1.4 KAPE Triage and Processing
- WF1.5 Velociraptor for Remote Collection
- WF1.6 Full Disk Imaging and Verification
- WF1.7 Processing Collected Evidence
- WF1.8 Fleet-Wide Collection at Scale
- WF1.9 Proving the Collection Is Complete
- WF1.10 The Collection You Cannot Repeat
- WF1.11 See It Done: A Soldered Laptop, Four Hundred Hosts, and a Ticket Nobody Mentioned
- WF1 Check My Knowledge
Phase 2: Investigation Questions
Finding execution evidence from Prefetch, Amcache, Shimcache, BAM, SRUM, and event logs.
12 lessonsHide lessons
- WF2.1 The Execution Evidence Hierarchy
- WF2.2 Prefetch
- WF2.3 Amcache
- WF2.4 BAM, DAM and SRUM
- WF2.5 Process Creation Events
- WF2.6 PowerShell Execution
- WF2.7 Credential Tool Identification
- WF2.8 C2 and Lateral Movement Tools
- WF2.9 Anti-Forensics and Execution Evidence
- WF2.10 Building a Cross-Source Execution Timeline
- WF2.11 See It Done: Seventy-One Minutes, Found Nine Days Later
- Check My Knowledge
Account forensics, authentication analysis, folder and file access artifacts, application usage, search history, geolocation, document tracking, and user attribution.
10 lessonsHide lessons
Patient zero and retention horizons, origin markings and what removes them, delivery chains that carry no file, following an account across a boundary, the one technique whose evidence sits on the source, and the...
12 lessonsHide lessons
- WF4.1 Initial Access and Patient Zero
- WF4.2 Mark of the Web
- WF4.3 The Delivery Chain
- WF4.4 Following the Account Across the Boundary
- WF4.5 Remote Desktop and What It Records
- WF4.6 What Each Technique Leaves, and Where
- WF4.7 Stolen Credentials and What They Do to Attribution
- WF4.8 Choosing the Next Host
- WF4.9 Collecting While the Estate Is Running
- WF4.10 A Chain With a Gap, and When to Stop
- WF4.11 See It Done: The Contractor's Second Tuesday
- WF4 Check My Knowledge
Persistence mechanism forensics: registry Run keys, services, scheduled tasks, WMI subscriptions, COM hijacking, PowerShell-based persistence, user-level persistence, Autoruns triage, multi-layer patterns, and...
11 lessonsHide lessons
- WF5.1 The Persistence Landscape
- WF5.2 Registry Persistence Across Hives
- WF5.3 Scheduled Tasks and Services From Event Logs
- WF5.4 WMI Subscriptions and the Mechanisms Most Analysts Miss
- WF5.5 PowerShell and Script-Based Persistence
- WF5.6 NTUSER.DAT and User-Level Persistence
- WF5.7 The Autoruns Triage Workflow
- WF5.8 Multi-Layer Persistence
- WF5.9 Reconstructing the Persistence Timeline
- WF5.10 See It Done: Six Mechanisms, Two Rebuilds, One Account
- WF5 Check My Knowledge
Data exfiltration forensics: SRUM application network usage, USB device history, browser uploads and downloads, cloud storage sync evidence, email artifacts, staging and compression patterns, and quantifying the...
9 lessonsHide lessons
- WF6.1 SRUM and the Volume Question
- WF6.2 USB Devices and Removable Media
- WF6.3 Browser Downloads, and the Uploads Nobody Logged
- WF6.4 Cloud Storage on the Endpoint
- WF6.5 Email Artifacts and the Export That Was a Decision
- WF6.6 Staging and Compression
- WF6.7 Quantifying What Left
- WF6.8 See It Done: Six Routes, One Employee, Two Reports
- WF6 Check My Knowledge
NTFS filesystem forensics: MFT architecture, MFTECmd parsing, USN Journal analysis, ransomware pattern detection, $LogFile transactions, deleted file recovery, timestomping detection, Alternate Data Streams, document...
13 lessonsHide lessons
- WF7.1 NTFS Architecture for Investigators
- WF7.2 Reading a Parsed MFT
- WF7.3 The Change Journal
- WF7.4 Mass Operations and Ransomware
- WF7.5 The Transaction Log
- WF7.6 Deleted File Recovery
- WF7.7 Timestomping Detection
- WF7.8 Alternate Data Streams
- WF7.9 File and Document Metadata
- WF7.10 Directory Index Analysis
- WF7.11 Building the Filesystem Timeline
- WF7.12 See It Done: Eleven Days Later
- WF7 Check My Knowledge
Anti-forensic detection and evidence recovery: anti-forensics threat model, Volume Shadow Copy recovery, event log clearing detection, secure deletion tool artifacts, data hiding techniques, pagefile and hibernation...
9 lessonsHide lessons
- WF8.1 The Anti-Forensics Threat Model
- WF8.2 Volume Shadow Copies
- WF8.3 Event Log Clearing and Recovery
- WF8.4 Secure Deletion and Wiping Tool Detection
- WF8.5 Data Hiding
- WF8.6 Memory, Pagefile and Hibernation File Analysis
- WF8.7 Evidence Integrity and Admissibility
- WF8.8 See It Done: Forty-Five Minutes of Cleanup
- Check My Knowledge
Phase 3: Integration
Constructing super timelines with Plaso, analyzing with Timeline Explorer, correlating across multiple hosts, assessing confidence levels, and producing defensible findings and reports.
8 lessonsHide lessons
What browsers and communication applications leave behind: Chromium and Firefox artifacts, cross-browser analysis, private browsing recovery, and the messaging and email application traces that place a user at a...
9 lessonsHide lessons
- WF10.1 Chromium Browser Forensics
- WF10.2 Firefox and Cross-Browser Analysis
- WF10.3 Private Browsing and Artifact Recovery
- WF10.4 Electron and WebView2 Application Forensics
- WF10.5 The Windows Search Database
- WF10.6 Email Forensics
- WF10.7 Cloud Application Artifacts on the Endpoint
- Module Summary
- Knowledge Check
Phase 4: Capstone Investigations
A full insider threat investigation worked end to end: case briefing and evidence inventory, account and session analysis, execution evidence, and the findings package somebody else reads.
10 lessonsHide lessons
- INV1.01 Case Briefing and Evidence Inventory
- INV1.02 Account and Session Analysis
- INV1.03 Execution Evidence
- INV1.04 Data Staging and USB Transfer
- INV1.05 Cloud and Browser Evidence
- INV1.06 Anti-Forensic Cleanup
- INV1.07 Timeline Construction
- INV1.08 Findings and Report
- Module Summary
- Knowledge Check
A full ransomware investigation worked end to end: initial triage, the phishing vector, credential theft and escalation, and a classification that separates the encrypted hosts from the compromised ones.
Phase 0: Course Resources
The lookup layer: every command the course teaches, grouped by what you are trying to establish.
1 lessonsHide lessons
Procedures: what you do, in what order, and what each step must produce.
1 lessonsHide lessons
Build the environment that produces the evidence this course analyzes.
1 lessonsHide lessons
Complete investigations worked end to end, including the wrong turns.
Artifact generation and analysis procedures.
Resources for practicing endpoint investigation and using it at work: the forensic lab, an open-source DFIR toolkit, the detection library, guided investigations, and response playbooks.
External sources this course draws on: tooling documentation, research, standards and community Windows forensics material.
Course Completion
Windows Endpoint Investigation end-of-course exam: a simulation-based assessment testing your ability to reconstruct attacker activity from forensic evidence across multiple hosts.
1 lessonsHide lessons
Course overview
The Windows Endpoint Investigation course gives you the practical, hands-on expertise to forensically collect, analyze, and interpret data from Windows systems - turning raw artifacts into clear evidence for incident response and internal investigations.
Learn how to:
By the end, you'll have the complete skillset of a confident Windows forensics investigator - ready to support breach response, internal probes, and proactive defense.
How this course works
This course is organized around the questions an investigation actually asks, rather than around the artifacts that happen to answer them. Each module is a question and the loop inside it is the same.
1. Ask the question before choosing the artifact. What ran, who was here, how did they get in, what did they install. Starting from the question stops an investigation becoming a tour of a forensic toolkit.
2. Collect once, correctly. Acquisition and triage decide everything downstream, and a host that has been rebuilt cannot be re-collected.
3. Corroborate across at least two artifacts. Execution evidence in Prefetch alone is a lead. The same execution in Prefetch, Amcache and an event log, with times that agree, is a finding.
4. Notice what is missing. Cleared logs, wiped artifacts and timestamps that disagree are evidence in themselves, and an absence with a mechanism named is a finding rather than a gap.
5. Assemble the picture last. The timeline is built from artifacts already understood. Building it first inherits every parsing error into the narrative.
The course closes with two full investigations, an insider case and a ransomware case, worked end to end.
What this course assumes
No minimum experience and no prerequisite course. Every artifact is introduced with what it records, why Windows writes it and what it cannot tell you.
What makes it go faster: a Windows machine to examine and the tooling installed. Neither is required, and every artifact in the course is shown parsed with its output.
What this course does not cover: memory forensics, network investigation and malware reverse engineering. Each is a separate course, and this one is the disk and the operating system.
Who this course is for
You're a SOC analyst, incident responder, security engineer, or IT professional with a sharp investigative mindset and you're ready to specialize in Windows forensics.
This course is designed for you if you want to:
In short: if you want to become the go-to expert who can track user activity, uncover hidden evidence, and deliver clear findings across Windows systems, this course is for you.
What you'll learn
By the end of this Windows Endpoint Investigation course you will be able to:
Key course takeaways
Lab Pack - build the evidence, then work it
Two investigation scenarios: Insider exfiltration (INC-NE-2026-0915) where a departing employee stages 6.7 GB across USB and cloud storage over 9 days. Ransomware (INC-NE-2026-1022) tracing a phishing email through credential theft, lateral movement across 3 hosts, persistence installation, and encryption of 173K files.
The pack exists so you practice on evidence whose answer you already know. The generators build a case on a machine you own, so every artifact you go on to read was produced by something you did, and you can check your finding against what actually happened. That is the one condition under which being wrong teaches you something. Walkthroughs, exercises, verification scripts and report templates come with it, and every tool it uses is free: KAPE, the EZ Tools suite, Velociraptor, Plaso, RegRipper and Timeline Explorer.
WFIR, a PowerShell module for practice and testing. Eleven functions, one per investigative question the course asks: collect a triage image and hash it, correlate execution across Prefetch, Amcache and Shimcache, decode logon activity and flag an account authenticating from somewhere it never has, enumerate persistence sorted by what each mechanism survives, reconcile USB history across the four sources that each hold part of it, quantify outbound data per application against its own baseline, detect timestomping and cleared logs, and merge the lot into one host-tagged timeline.
It reads the CSV output KAPE and the EZ Tools already produce rather than reimplementing a parser, so what it shows you is what the artifacts hold. It reports what it could not establish alongside what it could: it will tell you a handle was opened against the credential store and refuse to call that credential theft, because only the first of those is recorded. Reading its output next to your own conclusion is a good deal of the practice.
Test before using in your environment. WFIR is written against the command lines this course teaches and is built for the lab: run it against evidence whose answer you already know, satisfy yourself it reports what you expect, and validate it under your own change process before it goes anywhere near live work.
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Study Guide - Windows Endpoint Investigation
The course as a book. Eleven chapters following the modules, every section of the course inside them, and under each one what it teaches, the commands that do the work and the figures that show it. 205 pages.
It is generated from the published course rather than written alongside it, so it cannot drift from what you are being taught. Yours to print, annotate and keep.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites for this course. The techniques and tools used in the course will equip you with the skills to analyze cyber incidents and crimes involving Windows systems.
What are the device requirements?
A device with approximately 16 GB of RAM or more. A device with adequate storage, preferably with 10 GB of free storage space on an external storage device (USB).
How will the course benefit your career?
Windows forensic capabilities will enhance your career and equip you with the required skills to investigate cyber incidents. Cyber threats to organizations are evolving at a rapid pace; therefore, there is an increase in the demand for individuals who can analyze systems, detect breaches, and recover critical evidence.
This course teaches how to investigate key artifacts (registry, logs, memory, and file system), detect malware, trace unauthorized access, and recover lost data. These skills are valuable for career growth in cybersecurity.
Forensics is a demanding skill required in roles such as forensic analyst, cybercrime investigator, SOC analyst, and security consultant, among many others.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Forensic evidence: All lab evidence files are fictional constructs. Validate forensic procedures against your jurisdiction's legal requirements before use in legal proceedings.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
Version and changelog
Current version: 1.2 | Last updated: September 2026 | Built to: Course Specification v4
September 2026 - v1.2: Both capstone investigations rebuilt end to end. Every sub now opens on prose, carries a worked artifact, and states what it could not establish as well as what it could.
June 2026 - v1.1: Course renamed to Windows Endpoint Investigation.
2026 - v1.0: Course launch. 11 content modules organized by investigation question, 2 capstone investigations (insider threat and ransomware), a procedure cookbook, and a lab pack with artifact generators and walkthroughs.
This course is actively maintained.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.