1. Investigating Windows Endpoints

    • Buy now
    • Learn more
  2. Welcome and Introduction

    • Welcome and Introduction
  3. Initial Setup

    • Initial Setup
  4. Windows Event Logs

    • Fundamentals
    • In-depth Analysis
    • Tools and Best Practices
  5. The Registry

    • Fundamentals
    • NTUSER.DAT
    • UsrClass.dat and ShellBags
    • USB Forensics, Networks, and More
    • Scalable Analysis
  6. Evidence of Execution

    • Introduction
    • Prefetch
    • Shimcache/AppCompatCache
    • AmCache
    • PCA
    • MUICache
    • UserAssist
    • SRUM
  7. Persistence, Privilege Escalation, and Lateral Movement

    • Services and Scheduled Tasks
    • LSASS, NTDS.dit, WDigest
    • SMB, RDP, WMI, PsExec, UAL
  8. Anatomy of NTFS

    • Introduction
    • Metafiles, MFT, Journaling, ADS
    • MACB Timestamps
    • Parsing the MFT and USN Journal
    • $I30 Index Attributes
  9. File Deletion and Recovery

    • The Recycle Bin
    • "Permanent" Deletion
    • File Carving with PhotoRec
  10. LNK Files and Jump Lists

    • LNK Files
    • Jump Lists
  11. Timelining

    • The Sleuth Kit (TSK) fls and mactime
    • Plaso/Log2Timeline
    • MFTECmd
  12. Additional Content

    • Web Browser Forensics
    • Thumbs.db and Thumbcache
    • Windows Activity Timeline
    • Windows Search Index
    • Trouble at ACME
  13. Knowledge Assessment

    • Knowledge Assessment
  1. Products
  2. Course
  3. Section

Persistence, Privilege Escalation, and Lateral Movement

  1. Investigating Windows Endpoints

    • Buy now
    • Learn more
  2. Welcome and Introduction

    • Welcome and Introduction
  3. Initial Setup

    • Initial Setup
  4. Windows Event Logs

    • Fundamentals
    • In-depth Analysis
    • Tools and Best Practices
  5. The Registry

    • Fundamentals
    • NTUSER.DAT
    • UsrClass.dat and ShellBags
    • USB Forensics, Networks, and More
    • Scalable Analysis
  6. Evidence of Execution

    • Introduction
    • Prefetch
    • Shimcache/AppCompatCache
    • AmCache
    • PCA
    • MUICache
    • UserAssist
    • SRUM
  7. Persistence, Privilege Escalation, and Lateral Movement

    • Services and Scheduled Tasks
    • LSASS, NTDS.dit, WDigest
    • SMB, RDP, WMI, PsExec, UAL
  8. Anatomy of NTFS

    • Introduction
    • Metafiles, MFT, Journaling, ADS
    • MACB Timestamps
    • Parsing the MFT and USN Journal
    • $I30 Index Attributes
  9. File Deletion and Recovery

    • The Recycle Bin
    • "Permanent" Deletion
    • File Carving with PhotoRec
  10. LNK Files and Jump Lists

    • LNK Files
    • Jump Lists
  11. Timelining

    • The Sleuth Kit (TSK) fls and mactime
    • Plaso/Log2Timeline
    • MFTECmd
  12. Additional Content

    • Web Browser Forensics
    • Thumbs.db and Thumbcache
    • Windows Activity Timeline
    • Windows Search Index
    • Trouble at ACME
  13. Knowledge Assessment

    • Knowledge Assessment

3 Lessons
    • Services and Scheduled Tasks
    • LSASS, NTDS.dit, WDigest
    • SMB, RDP, WMI, PsExec, UAL