Windows Forensics
Forensic Data Examination
The Data Examination Process Overview
Resources:
Mounting a disk image using Arsenal Image Mounter
Arsenal Image Mounter Tutorial - Opens in new tab
Guide on Windows files and forensic artifacts
The FTK Imager Tool - Opens in new tab
Creating a triage data collection with KAPE
Download The Kroll Artifact Parser And Extractor (KAPE) - Opens in new tab
Windows Forensics Navigation
Data Collection Process Overview
4.3 Disk Acquisition
Forensic Data Examination This Page