- Locating Evidence on Windows Systems
- Gathering Volatile Evidence
- Pslist
- Forensic Tool: fport
- Forensic Tool - Psloggedon
- Investigating Windows File Slack
- Examining File Systems
- Built-in Tool: Sigverif
- Word Extractor
- Checking Registry
- Reglite.exe
- Tool: Resplendent Registrar 3.30
- Microsoft Security ID
- Importance of Memory Dump
- Manual Memory Dumping in Windows 2000
- Memory Dumping in Windows XP and Pmdump
- System State Backup
- How to Create a System State Backup?
- Investigating Internet Traces
- Tool - IECookiesView
- Tool - IE History Viewer
- Forensic Tool: Cache Monitor
- CD-ROM Bootable Windows XP
- Bart PE
- Ultimate Boot CD-ROM
- List of Tools in UB CD-ROM
- Desktop Utilities
- File Analysis Tools
- File Management Tools
- File Recovery Tools
- File Transfer Tools
- Hardware Info Tools
- Process Viewer Tools
- Registry Tools
Source:
http://www.eccouncil.org/EC-Council%20Education/Chfi-Course.htmDon