What is new in FOR500: Windows Forensics Course? Windows 10 and beyond -
Windows Forensic Analysis is constantly progressing. If you have been doing digital forensics for the past few years and haven't been able to keep your skills up to date, FOR500 Windows Forensic Analysis will bring your skills up to date. Do you know what a shell item is and why it is important to proper windows digital artifact analysis? Have you ever heard of the SRUM database and what it could mean in attempting to track individuals stealing data from your organizations? The latest evidence of execution artifacts such as ShimCache and AmCache registry hive files are critical to proving certain programs are executed. Even more so, Windows operating systems synchronize a lot of the data stored on the OS across multiple devices without you knowing about it. Completely updated through Windows 10 the new FOR500: Windows Forensics course is not an introduction to forensics class but focuses completely on artifacts that will help you solve the most complex investigations. For more information about FOR500 or to see the next course runs visit: sans.org/FOR500 Speaker Bio Rob Lee Rob Lee is the curriculum lead and author for digital forensic and incident response at the SANS Institute. With more than 19 years of experience in computer forensics, vulnerability and exploit discovery, intrusion detection/prevention and incident response, he provides consulting services via HARBINGERS LLC. in the Boston, MA. area. Before directing services at HARBINGERS, Rob worked with government agencies in law enforcement, defense, and intelligence communities as a lead for vulnerability discovery and exploit development teams supporting Title10/50 cyber operations. Following his work in the intel community, he worked at the incident response firm MANDIANT for 5 years. Notably, he co-authored MANDIANT's first detail threat intelligence reports on Chinese APT activity titled "M-Trends: The Advanced Persistent Threat."

SANS DFIR WEBCAST - Network Forensics What Are Your Investigations Missing

How To Manage Security Risks & Threats | Google Cybersecurity Certificate

Introduction to Windows Forensics

Exploring Registry Explorer

DFIR 101: Digital Forensics Essentials | Kathryn Hedley

SANS DFIR Webcast - Detecting Evil on Windows Systems - An In Depth Look at the DFIR Poster
![Beginner to T-SQL [Full Course]](https://i.ytimg.com/vi/cACat4KNncg/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLA4o6xA3UzwmxwP9P-enFU9sgxi6Q)
Beginner to T-SQL [Full Course]

DNS Evidence You Don’t Know What You’re Missing

Windows Memory Forensics

SANS DFIR Webcast - Memory Forensics for Incident Response

BYOB Webinar Building a Strong Foundation Cyber Security Essentials 2026 05 13 15 50 AEST

Windows Autopilot #intunetraining #autopilot #sccm #microsoft #intune
![Power Automate Tutorial ⚡ Beginner To Pro [Full Course]](https://i.ytimg.com/vi/KsgxDz-nY_I/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLA_rx8lyBNlJugWNGyVLp7B46-c0w)
Power Automate Tutorial ⚡ Beginner To Pro [Full Course]

From Seizure to Actionable Intelligence in 90 Minutes or Less

Windows MACB Timestamps (NTFS Forensics)
![Power Apps and Power Automate in Microsoft Teams [Full Course]](https://i.ytimg.com/vi/ynKtu_QZhOQ/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLDcVZRVwAbJJh-p-wCzC70k57WhOA)
Power Apps and Power Automate in Microsoft Teams [Full Course]

Investigating Malware Using Memory Forensics - A Practical Approach

Fast, Scalable Results with EZ Tools and the New Command line poster

Linux Full Course for Beginners | Learn Linux System Administration

