- This event has passed.
Windows 10 Forensic Artifacts
July 7 @ 12:00pm - 1:00pm CDTFree
This session will explore the digital forensic artifacts found in Windows 10 that can be used in post-incident analysis or computer investigation. It will include where the artifacts are located on disk, as well as analysis techniques, and suggestions for preservation. Highlights will be sync data, Cortana, System Resource Usage Monitor (SRUM), Timeline, Windows Registry, and common logs.
What attendees will learn
- Know which artifacts might be present
- How to locate and analyze artifacts
- Learn how to preserve artifacts when extracting them
Information Security Officer,
University of Wisconsin–Stevens Point