Page Loader Logo

The International Association of Computer Investigative Specialists

Online WFE : Windows Forensic Examiner

Registration is Open

Event Details

The IACIS Online WFE course is a 36-hour course of instruction; the course is designed to provide students with a detailed study of the Windows Operating System.

Through a variety of lectures, instructor-led and independent hands-on practical exercises students will study the Windows operating system in far greater detail, and with far more specificity regarding critical areas of forensic focus, than what can be accomplished in the more generalized, overview perspective of the BCFE course.

This program will focus on how a variety of Windows Operating Systems work “under the hood”, with a focus on the most current/common versions. At the conclusion of this course, students will have a clearer understanding of various operating system artifacts and why they present as they do, and how knowledge of these artifacts can play a significant role in the forensic and investigative process.

The WFE course champions a forensic tool-independent approach to learning. This approach allows for a deeper exploration of the underlying subject matter than might be afforded in other programs which are designed to complete a particular task or view/extract a particular artifact.

The WFE course is designed to build on and expand the students existing forensic knowledge and skillset and is not an entry level class. Prospective students should reference the “Prerequisites” section elsewhere in this document for additional information about expectations for students.

The WFE course will assist students in preparing for their CAWFE certification, however the training program is not taught to the certification, instead, students are recommended to take notes, participate, and make the most of the classroom environment. The material provided to students will be used as part of certification process, however, reading outside of the provided material is advisable and will benefit the student in obtaining a deeper understanding. As an example, the WFE material includes information about Artifact A, but the trainers focus on Artifacts B, C and D. The certification may include questions on Artifacts A and D.

Online WFE Course topics

  • Virtualization: Concepts, artifacts, and practical usage. We explore the various terminology used to describe virtualization and its associated technologies. This extends to exploring WSL and Hyper-V technologies.
  • Partitioning Schemes: Understanding MBR and GPT partitioning schemes. We explore these common schemes and parse some of the structures at the hex level. Understanding these structures provides a greater level of understanding (and refresher) on these data structures which can help to solidify findings in examiners investigations.
  • File Systems: Overview of the common file-system NTFS and its critical use of metadata files such as $MFT, $Logfile, $Volume, $Bitmap, $Boot, MFT Records, Orphaned files, Alternate Data Streams, Directory Indexing
  • Security Features and Encryption: common to the Windows Operating System, such as BitLocker and EFS
  • Registry: Concepts and structures of common registry files such as SOFTWARE, SAM, SYSTEM, NTUSER.dat. Exploration of Shellbags, Amcache, UserAssist, AppCompatCache / Shimcache,
  • Artifacts: We will review many Windows artifacts, such as: PowerShell, Clipboard, DoH, Access Control Lists, Thumbcache, Iconcache, PhotosApp, Windows Mail, Timeline, Backup, Event Logs, Link Files, Jump Lists, Prefetch, OneDrive, Notifications, Edge, Cortana, Services, Microsoft Defender Logging.
  • RAM and virtual memory management concepts: We use command line tools to analyze a RAM image and determine application usage and user interaction.

 

More Details

PREREQUISITE:

Basic Computer Forensic Examiner [BCFE] course AND completion of the Certified Forensic Computer Examiner [CFCE] certification is highly recommended, but not required.

SYLLABUS:

Online WFE Syllabus coming soon

PAYMENT DETAILS:

PAYMENT MUST BE RECEIVED PRIOR TO THE START OF THE ONLINE TRAINING. All online cycles must be started and completed within the active course cycle completion dates. Students who fail to complete course exercises within the specified timeframe will be removed from the process and he/she will forfeit any fees paid. Under certain circumstances students with an identified hardship may request to be transferred to the following online training cycle. To qualify for this request, the student must notify the course administrator (onlinetraininghelp@iacis.com) a minimum of 30 days before the end of the class cycle. This type of request will be granted on a limited basis and only as a one (1) time transfer. There will be no refunds issued to students who fail to start or complete the online training cycle.

HOW TO REGISTER:

Existing IACIS members, simply log in with your credentials and go to the Products page to purchase and register for the course.

For non-IACIS members, the membership fee is waived with the purchase of the training course; however, to register for the course you must complete a membership application at the time of purchase. Purchase training course here.

Quick Details

WhenVarious Times

Cost$995Payment MUST BE RECEIVED at least 70 days prior to the first day of class.

CertificationCompletion of the online WFE course entitles each member to one attempt at the CAWFE Certification process. The attempt must be completed within the time frame of your online cycle. Each online class cycle is three months; a fourth month is allowed for testing.

IACIS Chair

Ian Donovan

WFE Chairman Instructor

Certifications

CFCE IACIS Certification

CFCE

Certified Forensic Computer Examiner Program

CAWFE IACIS Certification

ICMDE

Certified Mobile Device Examiner

CMDE IACIS Certification

CAWFE

Certified Advanced Windows Forensic Examiner

Courses Offered at This Event

Taught by experienced professionals, these hands-on sessions cover everything from foundational skills to advanced investigative methods. Whether you’re new to the field or a seasoned expert, you’ll gain practical knowledge that directly applies to your work. Explore the course lineup and build your expertise today.

The IACIS Windows Forensic Examiner (“WFE”) course is a 36-hour course of instruction offered over five (5) consecutive days. It is designed to provide students with a detailed study of the Windows Operating System. Through a variety of lectures and instructor-led and independent hands-on practical exercises, students will study the Windows operating system in far greater detail and with far more specificity regarding critical areas of forensic focus than what can be accomplished in the more generalized perspective of the BCFE Training Program.
Skip to content