Windows OS Forensics (Coursera)

Offered by Infosec,
Windows OS Forensics (Coursera)

The Windows OS Forensics course covers windows file systems, Fat32, ExFat, and NTFS. You will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. You will also learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable you to validate the information from multiple forensic tools properly.

Class Deals by MOOC List - Click here and see Coursera's Active Discounts, Deals, and Promo Codes.

What You Will Learn

  • The student will learn about the windows file systems, Fat32, ExFat, and NTFS.
  • Students will learn how these systems store data, what happens when a file gets written to disc, & what happens when a file gets deleted from disc.
  • Students will learn how to recover deleted files.

Course 2 of 3 in the Computer Forensics Specialization.

Syllabus

WEEK 1
Bits, Bytes and Endienness
This module explains the various numbering schemas used throughout computer forensics. In this module, you'll explore the numbering schemas used in computer forensics. This knowledge allows the student to interpret data at the hex and binary levels. This skill is necessary to validate forensic software tools and gives the student an understanding of where to locate the data displayed by their forensic software. This information is notably beneficial for court proceedings.

WEEK 2
Disk Partition Schema
A look at the master boot record and the GUID partition table. This module demonstrates the difference between the master boot record and the GUID partition table. This information gives the student an understanding of where to locate both partitions and data on the drive. The forensic student learns how to interpret the master boot record and locate the volume boot record for each volume on the drive.

WEEK 3
The FAT File System
This module explores the structure of the FAT file system. This module covers the structure and layout of the FAT file system. The student develops an understanding of how the FAT file system writes a file to a drive and deletes a file from a drive. With this knowledge, the examiner can recover deleted data or recover data from a reformatted drive.

WEEK 4
The NTFS File System
In this module, you'll explore the details of the NTSF file system. NTSF is a crucial component of forensic examinations. This module explains how the file system organizes information and where data is located on the drive. It also covers where the metadata for the file is stored and the changes that occur at a file system level when someone deletes or creates a file.

WEEK 5
The ex-fat File System
Take a closer look at the details of the ex-FAT file system. In this module, the student learns the structure and layout of the ex-FAT file system, how the file system tracks files, where it stores the file metadata and how to recover deleted data.

WEEK 6
Windows Registry Forensics
Explore the complexities and challenges of Windows Registry forensics. This module covers the history and function of the Registry. It includes how to examine the live Registry, the location of the Registry files on the forensic image and how to extract files. After examining the files with forensic tools, the student can locate relevant artifacts such as USB device connection times, recently used documents, program last run times and programs set to run at startup.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Office Productivity Software and Windows Fundamentals (Coursera) Coursera
SkillUp EdTech

Office Productivity Software and Windows Fundamentals (Coursera)

As the most used operating system in the world, Windows skills are crucial in today’s workplace. Knowledge of Windows and office productivity software is highly valued and makes you a desirable job candidate. In this mini-course, you will learn about fundamental Windows functions as well as the basics of office productivity software. You will go over file and folder management, app installation, the Control Panel, useful Windows apps, screenshots, and Windows tips and shortcuts.

Sep 7th 2026
3 Weeks
Introduction to Forensic Science (FutureLearn) FutureLearn
University of Strathclyde

Introduction to Forensic Science (FutureLearn)

Explore the methods underpinning forensic science, from crime scene investigation to reporting evidential value within a case. The course addresses four major evidence types: drugs of abuse, DNA, firearms and impression evidence, and discusses these through the exploration of a case-based scenario presented across a six-week modular framework.

Self Paced
5-12 Weeks
Forensic Facial Reconstruction: Finding Mr. X (FutureLearn) FutureLearn
The University of Sheffield

Forensic Facial Reconstruction: Finding Mr. X (FutureLearn)

Learn about the forensic technique of facial reconstruction from the experts involved in a real crime case. On Saturday 22 January 2000, two men found a small holdall, abandoned on an industrial estate in the north of Sheffield. Upon opening the bag they made a gruesome discovery. A badly decomposed body. Who was this person? Why did they die? Where had the body been stored all of this time? On this course from The University of Sheffield, you’ll learn alongside the experts who worked to determine the identity of Mr. X. You’ll discover the forensic science techniques that were used to identify the body and understand the circumstances surrounding their death.

Sep 21st 2020
2 Weeks
Forensic Engineering: Learning from Failures (edX) EdX
Delft University of Technology,DelftX

Forensic Engineering: Learning from Failures (edX)

Don’t let good failures go to waste! Identify the causes of failure and use this knowledge to enhance safety and improve performance. What do collapsed buildings, infected hospital patients, and crashed airplanes have in common? If you know the causes of these events and conditions, they can all be prevented. In this course, you will learn how to use the TU Delft mind-set to investigate the causes of such events so you can prevent them in the future.

Self Paced
Self-Paced
Digital Forensics Essentials (DFE) (edX) EdX
EC-Council

Digital Forensics Essentials (DFE) (edX)

Digital Forensics Essentials (DFE) is a first-of-its-kind MOOC certification that offers foundational knowledge and skills on digital forensics with add-on labs for hands-on experience. The rapid evolution of computers has brought technical devices as an active weapon to criminals. Cybercriminals have enjoyed the pleasure of being able to combine a large array of complex technologies to be successful in their mission. Due to the complexity of the attack, investigating a crime in the cyber world has become increasingly difficult to do.

Self Paced
Self-Paced
Core 2: OS, Software, Security and Operational Procedures (Coursera) Coursera
IBM

Core 2: OS, Software, Security and Operational Procedures (Coursera)

Are you interested in becoming a proficient and sought-after IT professional? Are you currently or do you plan to pursue a career in an IT support, network technician, or other IT-related role? This IBM course, designed for individuals with IT Fundamentals knowledge, is part of a series of courses that will help you prepare for the CompTIA Core 2 Certification exam. You will gain a solid foundation in operating systems, IT support best practices and procedures, and the skills necessary to excel in an IT role.

Sep 14th 2026
5-12 Weeks