A forensic guide for linking USB activity to Windows computer systems
Learn Windows memory forensics
Learn how an analyze Windows Shimcache evidence
Learn how to prove file use & knowledge with evidence from Windows Explorer
Learn how an analyze Windows prefetch evidence
A computer forensic guide for understanding LINK file evidence on Windows computer systems
Build core computer forensic skills and learn how to interpret & validate Mac OS X dates & times
Computer forensic evidence to help prove file use & knowledge
Learn weblog forensics
Learn how to apply RAM extraction basics and get hands on experience using RAM capture tools - including Inception
Learn how to build a virtual SIFT Workstation
Learn how to tap into this amazing source of historical user information. It's easier than you think!