Windows Forensics
Forensic Data Examination
The Data Examination Process Overview

Resources:
Mounting a disk image using Arsenal Image Mounter
Arsenal Image Mounter Tutorial - Opens in new tab

















Guide on Windows files and forensic artifacts






The FTK Imager Tool - Opens in new tab



Creating a triage data collection with KAPE
Download The Kroll Artifact Parser And Extractor (KAPE) - Opens in new tab














Windows Forensics Navigation
Data Collection Process Overview
4.3 Disk Acquisition
Forensic Data Examination This Page