Windows OS Forensics (Coursera)

Offered by Infosec,
Windows OS Forensics (Coursera)

The Windows OS Forensics course covers windows file systems, Fat32, ExFat, and NTFS. You will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. You will also learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable you to validate the information from multiple forensic tools properly.

Class Deals by MOOC List - Click here and see Coursera's Active Discounts, Deals, and Promo Codes.

What You Will Learn

  • The student will learn about the windows file systems, Fat32, ExFat, and NTFS.
  • Students will learn how these systems store data, what happens when a file gets written to disc, & what happens when a file gets deleted from disc.
  • Students will learn how to recover deleted files.

Course 2 of 3 in the Computer Forensics Specialization.

Syllabus

WEEK 1
Bits, Bytes and Endienness
This module explains the various numbering schemas used throughout computer forensics. In this module, you'll explore the numbering schemas used in computer forensics. This knowledge allows the student to interpret data at the hex and binary levels. This skill is necessary to validate forensic software tools and gives the student an understanding of where to locate the data displayed by their forensic software. This information is notably beneficial for court proceedings.

WEEK 2
Disk Partition Schema
A look at the master boot record and the GUID partition table. This module demonstrates the difference between the master boot record and the GUID partition table. This information gives the student an understanding of where to locate both partitions and data on the drive. The forensic student learns how to interpret the master boot record and locate the volume boot record for each volume on the drive.

WEEK 3
The FAT File System
This module explores the structure of the FAT file system. This module covers the structure and layout of the FAT file system. The student develops an understanding of how the FAT file system writes a file to a drive and deletes a file from a drive. With this knowledge, the examiner can recover deleted data or recover data from a reformatted drive.

WEEK 4
The NTFS File System
In this module, you'll explore the details of the NTSF file system. NTSF is a crucial component of forensic examinations. This module explains how the file system organizes information and where data is located on the drive. It also covers where the metadata for the file is stored and the changes that occur at a file system level when someone deletes or creates a file.

WEEK 5
The ex-fat File System
Take a closer look at the details of the ex-FAT file system. In this module, the student learns the structure and layout of the ex-FAT file system, how the file system tracks files, where it stores the file metadata and how to recover deleted data.

WEEK 6
Windows Registry Forensics
Explore the complexities and challenges of Windows Registry forensics. This module covers the history and function of the Registry. It includes how to examine the live Registry, the location of the Registry files on the forensic image and how to extract files. After examining the files with forensic tools, the student can locate relevant artifacts such as USB device connection times, recently used documents, program last run times and programs set to run at startup.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Interagir com sistemas operativos (Coursera) Coursera
Google

Interagir com sistemas operativos (Coursera)

Neste curso, através de uma combinação de palestras em vídeo, demonstrações e experiências práticas, vai adquirir conhecimentos acerca dos componentes principais de um sistema operativo e como realizar tarefas críticas, como gerir software e utilizadores e configurar hardware. Vamos terminar com um exemplo de como este conteúdo pode surgir no contexto de uma entrevista.

Aug 3rd 2026
5-12 Weeks
Project Planning and Machine Learning (Coursera) Coursera
University of Colorado Boulder

Project Planning and Machine Learning (Coursera)

This course can also be taken for academic credit as ECEA 5386, part of CU Boulder’s Master of Science in Electrical Engineering degree. This is part 2 of the specialization. In this course students will learn : * How to staff, plan and execute a project; * How to build a bill of materials for a product; * How to calibrate sensors and validate sensor measurements; * How hard drives and solid state drives operate; * How basic file systems operate, and types of file systems used to store big data; * How machine learning algorithms work - a basic introduction; * Why we want to study big data and how to prepare data for machine learning algorithms.

Aug 10th 2026
4 Weeks
Computer Forensics (edX) EdX
Rochester Institute of Technology,RITx

Computer Forensics (edX)

Learn the process, techniques and tools for performing a digital forensics investigation to obtain data related to computer crimes. Digital forensics involves the investigation of computer-related crimes with the goal of obtaining evidence to be presented in a court of law.

Aug 17th 2026
5-12 Weeks
Introduction to Forensic Science (FutureLearn) FutureLearn
University of Strathclyde

Introduction to Forensic Science (FutureLearn)

Explore the methods underpinning forensic science, from crime scene investigation to reporting evidential value within a case. The course addresses four major evidence types: drugs of abuse, DNA, firearms and impression evidence, and discusses these through the exploration of a case-based scenario presented across a six-week modular framework.

Self Paced
5-12 Weeks
Digital Forensics Essentials (DFE) (edX) EdX
EC-Council

Digital Forensics Essentials (DFE) (edX)

Digital Forensics Essentials (DFE) is a first-of-its-kind MOOC certification that offers foundational knowledge and skills on digital forensics with add-on labs for hands-on experience. The rapid evolution of computers has brought technical devices as an active weapon to criminals. Cybercriminals have enjoyed the pleasure of being able to combine a large array of complex technologies to be successful in their mission. Due to the complexity of the attack, investigating a crime in the cyber world has become increasingly difficult to do.

Self Paced
Self-Paced
Forensic Psychology: Witness Investigation (FutureLearn) FutureLearn
The Open University

Forensic Psychology: Witness Investigation (FutureLearn)

How important are eyewitness testimonies in police investigations? Discover how forensic psychology prevents criminal injustice. Become a forensic psychologist and help solve crimes using eyewitness evidence. Have you ever questioned how reliable your own mind is? In this 8-week forensic psychology course, you’ll learn how the mind plays tricks on us and how this can impact criminal investigations. You’ll discover how cautious the police have to be during eyewitness investigation, and you’ll step into the shoes of a forensic psychologist.

Self Paced
5-12 Weeks
Operating Systems and You: Becoming a Power User (Coursera) Coursera
Google

Operating Systems and You: Becoming a Power User (Coursera)

In this course, you’ll learn how to use the major operating systems, Windows and Linux, which are a core component of IT. Through a combination of video lectures, demonstrations, and hands-on practice, you’ll learn about the main components of an operating system and how to perform critical tasks like managing software and users, and configuring hardware.

Aug 3rd 2026
5-12 Weeks
La science forensique au tribunal: témoin digne de foi? (Coursera) Coursera
University of Lausanne

La science forensique au tribunal: témoin digne de foi? (Coursera)

L’objectif de ce cours est d’encourager la réflexion critique en ce qui concerne la « science forensique », également appelée police technique et scientifique ou criminalistique. À l’heure actuelle, de manière générale, la plupart des gens sont fascinés par les possibilités techniques qu’offre la police scientifique. Ils sont bercés par une certaine illusion que les preuves de la science forensique sont infaillibles et fournissent des résultats factuels sûrs à 100 %. Ce cours – dispensé par des spécialistes du domaine – dépasse l’image conventionnelle véhiculée par des séries télévisées comme « Les Experts ».

Aug 10th 2026
5-12 Weeks