Course Duration
5 Days

Cyber
Authorized Training

IT

Course cost:
was £4,655 + VAT
£4,190 + VAT

IT Certification Overview

This five-day advanced-level forensic analysis course provides in-depth knowledge and skills for professionals seeking to investigate and analyse Windows Internals from a forensic and security perspective. Focusing on system structures, low-level debugging, memory analysis, and hidden artefact detection, the course equips learners with the tools to uncover, analyse, and respond to complex system behaviours and threats.

Newto Training Reviews

What Our Happy Alumni Say About Us

Prerequisites

  • Strong understanding of Windows operating systems.
  • Experience in system administration or development roles.
  • Completion of the Windows Internals Intermediate course or equivalent knowledge is recommended.
  • Familiarity with debugging tools and core Windows internal concepts is beneficial.

Target audience

  • IT professionals specialising in system administration or low-level troubleshooting.
  • Security professionals focused on incident response, threat hunting, or digital forensics.
  • Developers and engineers working with Windows internals, debugging, or driver analysis.

Learning Objectives

By the end of this course, participants will be able to:

  • Analyse Windows internals using advanced debugging techniques and tools.
  • Investigate registry, memory, and filesystem artefacts for forensic purposes.
  • Identify hidden drivers, injected code, and stealth techniques.
  • Understand virtualisation-based security features and their forensic implications.
  • Perform crash dump analysis and troubleshoot system failures.

Windows Internals Forensic Analysis Course Content

WinDbg and debugging model

  • Introduction to the Debugger Data Model.
  • Scripting with JavaScript in WinDbg.
  • Advanced debugger techniques for forensic analysis.

Configuration Manager and registry

  • Registry fundamentals and internal structure.
  • Key Control Block (KCB) cache mechanisms.
  • Parsing registry hives on disk and in memory.

Boot lifecycle

  • Boot unification and boot process internals.
  • Boot Configuration Database (BCD) structure.
  • Boot loader behaviour and components.
  • ACPI tables and AML interpreter.
  • Viewing ACPI tables using the debugger.

Windows driver model

  • Devices and driver architecture.
  • Driver routines and communication methods.
  • Plug and Play driver mechanisms.
  • Identifying and analysing loaded drivers.

Virtualization

  • Hyper-V architecture and components.
  • Detecting Hyper-V and analysing environments.
  • Partition structures and boot configuration.
  • Intercepts, hypercalls, and hypercall interfaces.

Secure kernel and trustlets

  • Secure kernel capabilities and structure.
  • Secure mode calls and system interactions.
  • VTL0 to VTL1 communication mechanisms.

Hyper-V enclaves

  • Enclave concepts and architecture.
  • Initialisation and memory layout.
  • Security boundaries and protections.
  • System calls, import binding, and enclave execution.

Stealth code and detection

  • Techniques for hiding drivers and kernel components.
  • Detecting hidden drivers and stealth mechanisms.
  • User-mode code hiding and process injection techniques.

Filesystem cache forensics

  • Shared memory concepts.
  • Filesystem cache structures and behaviour.
  • Identifying and analysing cached files.

NTFS forensics

  • NTFS control block structures.
  • Parsing NTFS data structures.
  • Locating cached and hidden file artefacts.

TCP/IP forensics

  • Network stack architecture.
  • TCP/IP internal objects and structures.
  • Port pools and control blocks analysis.

Operating system crashes

  • Crash dump configuration and collection.
  • Manual and automated crash dump analysis.
  • Using Driver Verifier for fault detection.

Exams and assessments

There are no formal exams included in this course.

Learners are assessed through practical exercises, guided development tasks, and instructor-led review during the course.

Hands-on learning

The course is dedicated to practical, instructor-supported exercises.

Hands-on tasks are designed to connect theory to real-world forensic analysis scenarios.

Upcoming Dates

Dates and locations are available on request. Please contact us for the latest schedule.

Advance Your Career with Windows Internals Forensic Analysis

Gain the skills you need to succeed. Enrol in Windows Internals Forensic Analysis with Newto Training today.