This course is part of Computer Forensics Specialization.
This course cannot be purchased separately - to access the complete learning experience, graded assignments, and earn certificates, you'll need to enroll in the full Computer Forensics Specialization program. You can audit this specific course for free to explore the content, which includes access to course materials and lectures. This allows you to learn at your own pace without any financial commitment.
4.8
(47 ratings)
4,337 already enrolled
Instructors:
English
What you'll learn
Examine registry structure and locate registry files
Analyze user activities and system configurations
Recover program execution and USB device history
Extract critical forensic evidence from registry hives
Use forensic tools to parse and interpret registry data
Skills you'll gain
This course includes:
6.7 Hours PreRecorded video
1 quiz
Access on Mobile, Tablet, Desktop
FullTime access
Shareable certificate
Top companies offer this course to their employees
Top companies provide this course to enhance their employees' skills, ensuring they excel in handling complex projects and drive organizational success.





There are 8 modules in this course
This comprehensive course teaches digital forensics professionals how to examine and analyze the Windows Registry for evidence. Students learn about registry structure, location of registry files, and extraction techniques. The curriculum covers detailed analysis of various registry hives including NTUSER.DAT, SAM, Software, System, USRClass.dat, and AmCache, revealing user activities, system configurations, and application usage. Through hands-on examination, participants learn to recover critical forensic artifacts such as user account information, program execution history, USB device connections, and system settings.
Introduction to the Windows Registry
Module 1 · 45 Minutes to complete
Preparing to Examine the Windows Registry
Module 2 · 57 Minutes to complete
NTUser.Dat Hive File Analysis
Module 3 · 2 Hours to complete
SAM Hive File
Module 4 · 50 Minutes to complete
Software Hive File
Module 5 · 1 Hours to complete
System Hive File
Module 6 · 1 Hours to complete
USRClass.dat Hive File
Module 7 · 32 Minutes to complete
AmCache Hive File
Module 8 · 1 Hours to complete
Fee Structure
Individual course purchase is not available - to enroll in this course with a certificate, you need to purchase the complete Professional Certificate Course. For enrollment and detailed fee structure, visit the following: Computer Forensics Specialization
Instructor
Experienced Police Detective with Expertise in Forensic Analysis and Public Safety
Denise is an accomplished Police Detective with extensive experience in the law enforcement industry. She possesses a strong skill set in forensic analysis, firearms handling, public safety, law enforcement, and computer forensics. Denise has a solid background in military and protective services and holds an Associate’s Degree in Criminal Justice/Police Science from Manchester Community College.
Testimonials
Testimonials and success stories are a testament to the quality of this program and its impact on your career and learning journey. Be the first to help others make an informed decision by sharing your review of the course.
4.8 course rating
47 ratings
Frequently asked questions
Below are some of the most commonly asked questions about this course. We aim to provide clear and concise answers to help you better understand the course content, structure, and any other relevant information. If you have any additional questions or if your question is not listed here, please don't hesitate to reach out to our support team for further assistance.