Windows Artifacts Exercise

Cal Lee, Kam Woods | BitCuratorEdu Project

Description

This hands-on exercise introduces students to forensic artifacts produced by Windows operating systems and tools to analyze them. These slides are excerpted from Cal Lee and Kam Woods’s SAA “Advanced Digital Forensics” class. The sample data referenced in these slides is available here: https://github.com/BitCurator/bcc-dfa-sample-data/

The exercise is available for free download as a PDF or Google Slides, below.

Learning object type

Lesson plan/materials

Learning objectives

This learning object might be used in a lesson to satisfy the following learning objectives:

  • Practice using tools in the BitCurator Environment.

More learning objects

View all BitCuratorEdu Learning Objects

About this resource

This resource was released by the BitCuratorEdu project and is licensed under a Creative Commons Attribution 4.0 International License.

Most resources from the BitCuratorEdu project are intentionally left with basic formatting and without project branding. We encourage educators, practitioners, and students to adapt these materials as much as needed and share them widely.

The BitCuratorEdu project was an effort (2018-2022) funded by the Institute of Museum and Library Services (IMLS) to study and advance the adoption of digital forensics tools and methods in libraries and archives through professional education efforts. This project was a partnership between Educopia Institute and the School of Information and Library Science at the University of North Carolina at Chapel Hill, along with the Council of State Archivists (CoSA) and several Masters-level programs in library and information science.

Google Slides PDF
Cite this resource:
Cal Lee, Kam Woods. (May 26, 2022). Windows Artifacts Exercise. BitCuratorEdu Project.