Jason, thanks for the detailed review. You were certainly very thorough in your description of the activities. This sounds like a good introduction to forensic analysis. It appears that it was limited to Windows forensics, but had some great topics on the subject. Prefetch files, link files, and the tons of registry artifacts can keep an investigator busy
It seems that people are pushing FTK these days. Access Data has some nice tools, but for some reason many investigators become dependent on FTK and never seek other options. This could lead to quite a few missed artifacts that FTK doesn't handle well, like Shadow Copies on Windows 7.
I am looking forward to your review of the Advanced Forensics course from SANS. This is where the magic will happen