Provided by: Blue Cape Security, LLC
Instructor: *Markus Schober - Founder*
📍 Virtual or On-site
This three-day live virtual workshop is an intensive, hands-on experience designed to help participants build and refine their Windows forensic analysis skills — from foundational knowledge to full case investigations.
Over the first two days, you’ll follow the structured learning path from the 201 Practical Windows Forensics course, gaining a deep understanding of forensic methodologies, Windows artifacts, and investigation tools used by professionals in the field.
On Day 3, you’ll apply your knowledge in selected IR200 investigation scenarios, learning how to conduct an end-to-end forensic investigation and build a complete timeline of attacker activity. The final day also includes exam preparation and guidance for those planning to pursue the Practical Windows Forensic Analyst (PWFA) certification.
By the end of the workshop, you’ll be equipped to perform comprehensive forensic investigations and ready to take the PWFA exam with confidence.
This workshop is designed for aspiring digital forensic analysts, SOC analysts, and incident responders looking to develop a strong foundation in Windows forensic analysis.
It’s equally valuable for IT and security professionals preparing for the PWFA certification or seeking to strengthen their investigative skills.