Windows Endpoint Investigation

Learn to Investigate Windows Systems Like a Professional Investigator

Answer the questions that matter: What ran? Who was here? How did the attacker move? What persistence did they install? What data left the network? What did they try to hide? Work through real forensic artifacts, build timelines across multiple hosts, detect anti-forensics, and complete two full capstone investigations.

Included with Specialist, from $29/month, or $289/year and save 25%. Preview the first module free, no account needed.
Practice included: forensic cases, plus the Practice Hub.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

Build forensic capabilities, allowing you to reconstruct the critical activities carried out by the adversary
Demonstrate knowledge and expertise to help solve data breaches
Manage incident cases and support stakeholders throughout the investigative process
Defend and validate the case management and investigative process
Develop reporting capabilities and presentation of forensic findings
FOR501 | Specialist tier | 13 modules across 4 phases | 36–40 hours at your own pace | 40 CPE credits | All tools free | No prerequisite | Updated September 2026

Course Syllabus

Every module and every lesson. Open a module to see its lessons.

Download the full syllabus (PDF)

Phase 2: Investigation Questions

WF8
What Did They Try to Hide?

Anti-forensic detection and evidence recovery: anti-forensics threat model, Volume Shadow Copy recovery, event log clearing detection, secure deletion tool artifacts, data hiding techniques, pagefile and hibernation...

9 lessonsHide lessons
  1. WF8.1 The Anti-Forensics Threat Model
  2. WF8.2 Volume Shadow Copies
  3. WF8.3 Event Log Clearing and Recovery
  4. WF8.4 Secure Deletion and Wiping Tool Detection
  5. WF8.5 Data Hiding
  6. WF8.6 Memory, Pagefile and Hibernation File Analysis
  7. WF8.7 Evidence Integrity and Admissibility
  8. WF8.8 See It Done: Forty-Five Minutes of Cleanup
  9. Check My Knowledge

Phase 3: Integration

WF9
Building the Complete Picture

Constructing super timelines with Plaso, analyzing with Timeline Explorer, correlating across multiple hosts, assessing confidence levels, and producing defensible findings and reports.

8 lessonsHide lessons
  1. WF9.1 Why Timelines Change Everything
  2. WF9.2 Building Targeted Timelines With Plaso
  3. WF9.3 Timeline Explorer for Analysis
  4. WF9.4 Multi-Host Timeline Correlation
  5. WF9.5 Confidence Assessment and Writing Findings
  6. WF9.6 Reporting and Testimony Preparation
  7. WF9 Module Summary
  8. Check My Knowledge
WF10
Communication & Application Forensics

What browsers and communication applications leave behind: Chromium and Firefox artifacts, cross-browser analysis, private browsing recovery, and the messaging and email application traces that place a user at a...

9 lessonsHide lessons
  1. WF10.1 Chromium Browser Forensics
  2. WF10.2 Firefox and Cross-Browser Analysis
  3. WF10.3 Private Browsing and Artifact Recovery
  4. WF10.4 Electron and WebView2 Application Forensics
  5. WF10.5 The Windows Search Database
  6. WF10.6 Email Forensics
  7. WF10.7 Cloud Application Artifacts on the Endpoint
  8. Module Summary
  9. Knowledge Check

Phase 4: Capstone Investigations

Investigation: Insider Threat

A full insider threat investigation worked end to end: case briefing and evidence inventory, account and session analysis, execution evidence, and the findings package somebody else reads.

10 lessonsHide lessons
  1. INV1.01 Case Briefing and Evidence Inventory
  2. INV1.02 Account and Session Analysis
  3. INV1.03 Execution Evidence
  4. INV1.04 Data Staging and USB Transfer
  5. INV1.05 Cloud and Browser Evidence
  6. INV1.06 Anti-Forensic Cleanup
  7. INV1.07 Timeline Construction
  8. INV1.08 Findings and Report
  9. Module Summary
  10. Knowledge Check
Investigation: Ransomware

A full ransomware investigation worked end to end: initial triage, the phishing vector, credential theft and escalation, and a classification that separates the encrypted hosts from the compromised ones.

10 lessonsHide lessons
  1. INV2.01 Case Briefing and Initial Triage
  2. INV2.02 The Phishing Vector
  3. INV2.03 Credential Theft
  4. INV2.04 Lateral Movement
  5. INV2.05 Persistence
  6. INV2.06 Defense Evasion
  7. INV2.07 Encryption Timeline
  8. INV2.08 Blast Radius
  9. Module Summary
  10. Knowledge Check

Phase 0: Course Resources

WF90
Cheatsheets

The lookup layer: every command the course teaches, grouped by what you are trying to establish.

1 lessonsHide lessons
  1. Cheatsheet
WF91
Cookbooks

Procedures: what you do, in what order, and what each step must produce.

1 lessonsHide lessons
  1. Cookbook
WF92
Lab Setup

Build the environment that produces the evidence this course analyzes.

1 lessonsHide lessons
  1. Lab Setup
WF95
Playground

Resources for practicing endpoint investigation and using it at work: the forensic lab, an open-source DFIR toolkit, the detection library, guided investigations, and response playbooks.

WF96
References

External sources this course draws on: tooling documentation, research, standards and community Windows forensics material.

Course Completion

Course Exam

Windows Endpoint Investigation end-of-course exam: a simulation-based assessment testing your ability to reconstruct attacker activity from forensic evidence across multiple hosts.

1 lessonsHide lessons
  1. Course Completion. Windows Endpoint Investigation

Course overview

The Windows Endpoint Investigation course gives you the practical, hands-on expertise to forensically collect, analyze, and interpret data from Windows systems - turning raw artifacts into clear evidence for incident response and internal investigations.

Learn how to:

Track user activity across networks and endpoints with precision
Organize and present findings that stand up in real investigations
Validate security tools, strengthen vulnerability assessments, and uncover insider threats
Hunt down hackers and close critical gaps in your security policies

By the end, you'll have the complete skillset of a confident Windows forensics investigator - ready to support breach response, internal probes, and proactive defense.

How this course works

This course is organized around the questions an investigation actually asks, rather than around the artifacts that happen to answer them. Each module is a question and the loop inside it is the same.

1. Ask the question before choosing the artifact. What ran, who was here, how did they get in, what did they install. Starting from the question stops an investigation becoming a tour of a forensic toolkit.

2. Collect once, correctly. Acquisition and triage decide everything downstream, and a host that has been rebuilt cannot be re-collected.

3. Corroborate across at least two artifacts. Execution evidence in Prefetch alone is a lead. The same execution in Prefetch, Amcache and an event log, with times that agree, is a finding.

4. Notice what is missing. Cleared logs, wiped artifacts and timestamps that disagree are evidence in themselves, and an absence with a mechanism named is a finding rather than a gap.

5. Assemble the picture last. The timeline is built from artifacts already understood. Building it first inherits every parsing error into the narrative.

The course closes with two full investigations, an insider case and a ransomware case, worked end to end.

What this course assumes

No minimum experience and no prerequisite course. Every artifact is introduced with what it records, why Windows writes it and what it cannot tell you.

What makes it go faster: a Windows machine to examine and the tooling installed. Neither is required, and every artifact in the course is shown parsed with its output.

What this course does not cover: memory forensics, network investigation and malware reverse engineering. Each is a separate course, and this one is the disk and the operating system.

Who this course is for

You're a SOC analyst, incident responder, security engineer, or IT professional with a sharp investigative mindset and you're ready to specialize in Windows forensics.

This course is designed for you if you want to:

Gain deep, practical mastery of Windows artifacts and how attackers leave traces
Learn to forensically capture, analyze, secure, and present digital evidence that stands up in real investigations
Move from basic log review to conducting full-scope Windows-based cyber investigations
Support incident response, internal probes, insider threat hunts, and proactive defense

In short: if you want to become the go-to expert who can track user activity, uncover hidden evidence, and deliver clear findings across Windows systems, this course is for you.

What you'll learn

By the end of this Windows Endpoint Investigation course you will be able to:

Master Windows artifacts and perform full-scope digital forensics on Microsoft Windows systems
Forensically capture, analyze, secure, and present digital evidence that stands up in real investigations
Conduct deep forensic analysis of Windows systems, media, and endpoints
Rapidly locate critical artifacts and evidence to answer key investigation questions
Apply structured processes and repeatable analytical techniques to build advanced on-the-job forensic capability
Extract actionable findings and turn them into clear, investigative reports or incident response deliverables

Key course takeaways

Build production-ready forensic capabilities that let you rapidly answer critical questions and lead full cyber incident investigations
Develop the real-world expertise to investigate and resolve data breaches and insider threats with confidence
Master the most important Windows artifacts and evidence locations across endpoints, systems, and media
Quickly locate, extract, and present the exact evidence needed to support investigations, legal matters, and business decisions
Set up a complete, ready-to-use forensics lab using free, open-source, and commercial tools
Create repeatable, process-driven investigative workflows that make you highly effective and consistent on the job

Lab Pack - build the evidence, then work it

Two investigation scenarios: Insider exfiltration (INC-NE-2026-0915) where a departing employee stages 6.7 GB across USB and cloud storage over 9 days. Ransomware (INC-NE-2026-1022) tracing a phishing email through credential theft, lateral movement across 3 hosts, persistence installation, and encryption of 173K files.

The pack exists so you practice on evidence whose answer you already know. The generators build a case on a machine you own, so every artifact you go on to read was produced by something you did, and you can check your finding against what actually happened. That is the one condition under which being wrong teaches you something. Walkthroughs, exercises, verification scripts and report templates come with it, and every tool it uses is free: KAPE, the EZ Tools suite, Velociraptor, Plaso, RegRipper and Timeline Explorer.

WFIR, a PowerShell module for practice and testing. Eleven functions, one per investigative question the course asks: collect a triage image and hash it, correlate execution across Prefetch, Amcache and Shimcache, decode logon activity and flag an account authenticating from somewhere it never has, enumerate persistence sorted by what each mechanism survives, reconcile USB history across the four sources that each hold part of it, quantify outbound data per application against its own baseline, detect timestomping and cleared logs, and merge the lot into one host-tagged timeline.

It reads the CSV output KAPE and the EZ Tools already produce rather than reimplementing a parser, so what it shows you is what the artifacts hold. It reports what it could not establish alongside what it could: it will tell you a handle was opened against the credential store and refuse to call that credential theft, because only the first of those is recorded. Reading its output next to your own conclusion is a good deal of the practice.

Test before using in your environment. WFIR is written against the command lines this course teaches and is built for the lab: run it against evidence whose answer you already know, satisfy yourself it reports what you expect, and validate it under your own change process before it goes anywhere near live work.

Windows Endpoint Investigation Lab Pack
2 scenarios · walkthroughs · exercises · report templates · the WFIR PowerShell module
Download Lab Pack (.zip)

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

Walkthroughs take a single investigative problem from acquisition to finding with no theory in the way: a binary that is no longer on disk, an account that was not the person, files that left on a USB stick, persistence nobody installed deliberately, timestamps that disagree, evidence somebody tried to remove, a disk image with no context, and an artifact that was not there.
Playbooks take one artifact class each and show you how to generate it on a machine you control so you know the ground truth, then how to read it, how to verify it, and where it misleads.
A cookbook organized by investigative task rather than by artifact, so it starts where a real case starts rather than where the evidence would tidy up.
A command cheatsheet grouped by the question each command answers, for the point at which you know what you are doing and need the exact switch.
A lab setup guide for building the environment the course assumes, on hardware you already have.
A references module for the research behind the claims, because most of this was reverse-engineered rather than published.
A playground that tells you where to practice: the Forensic Lab with investigation cases against real artifact sets, the SOC Simulator with a Prefetch and MFT timeline reconstruction written for this course, and the Playbook Suite for what happens once an investigation reaches a conclusion. Each one says why it is worth working rather than only linking to it.
VanGuard and the Detection Library are free, open source, and yours permanently whether you subscribe or not: a single-binary DFIR toolkit that triages a live machine or runs from a USB stick, and production detections across KQL, Sigma, Splunk, Velociraptor and YARA, each with its false positives, tuning notes and validation steps.

Study Guide - Windows Endpoint Investigation

The course as a book. Eleven chapters following the modules, every section of the course inside them, and under each one what it teaches, the commands that do the work and the figures that show it. 205 pages.

It is generated from the published course rather than written alongside it, so it cannot drift from what you are being taught. Yours to print, annotate and keep.

FOR501 Study Guide
205 pages · 11 chapters · 98 sections · 919 topics · 92 figures
Download Study Guide (.pdf)

Things you need to know

What are the prerequisites for this course?

There are no prerequisites for this course. The techniques and tools used in the course will equip you with the skills to analyze cyber incidents and crimes involving Windows systems.

What are the device requirements?

A device with approximately 16 GB of RAM or more. A device with adequate storage, preferably with 10 GB of free storage space on an external storage device (USB).

How will the course benefit your career?

Windows forensic capabilities will enhance your career and equip you with the required skills to investigate cyber incidents. Cyber threats to organizations are evolving at a rapid pace; therefore, there is an increase in the demand for individuals who can analyze systems, detect breaches, and recover critical evidence.

This course teaches how to investigate key artifacts (registry, logs, memory, and file system), detect malware, trace unauthorized access, and recover lost data. These skills are valuable for career growth in cybersecurity.

Forensics is a demanding skill required in roles such as forensic analyst, cybercrime investigator, SOC analyst, and security consultant, among many others.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Forensic evidence: All lab evidence files are fictional constructs. Validate forensic procedures against your jurisdiction's legal requirements before use in legal proceedings.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.2  |  Last updated: September 2026  |  Built to: Course Specification v4

September 2026 - v1.2: Both capstone investigations rebuilt end to end. Every sub now opens on prose, carries a worked artifact, and states what it could not establish as well as what it could.

June 2026 - v1.1: Course renamed to Windows Endpoint Investigation.

2026 - v1.0: Course launch. 11 content modules organized by investigation question, 2 capstone investigations (insider threat and ransomware), a procedure cookbook, and a lab pack with artifact generators and walkthroughs.

This course is actively maintained.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.