{"repo":"bluecapesecurity/PWF","free":true,"listed":false,"github":"https://github.com/bluecapesecurity/PWF","clone":"git clone https://github.com/bluecapesecurity/PWF.git","description":"Practical Windows Forensics Training","language":"PowerShell","stars":780,"topics":["cybersecurity","forensics","blueteam","purpleteam"],"license":null,"category":"security-tools","readme_excerpt":"Practical Windows Forensics (PWF) Lab Repository Provided by Blue Cape Security This repository gives you a practical, DIY workflow to generate Windows forensic evidence and start a structured investigation. It is designed for practitioners who want to: - Build a Windows lab - Simulate attacker behavior - Acquire memory and disk images - Begin forensic analysis with realistic artifacts Important Update PWF is no longer a standalone DIY course. PWF is now part of the Analyst 1 Training Track at Blue Cape Security, which includes: - Practical Windows Forensics (PWF) - FOR200 Windows Forensic Investigation Scenarios - PWFA certification (a 7-day practical Windows forensics exam focused on delivering a meticulous forensic timeline) If you want guided instruction for the analysis process, enroll in the Analyst 1 track: - https://bluecapesecurity.com/analyst1/ You can also explore additional free and paid SOC/DFIR training at: - https://bluecapesecurity.com/ What You Can Do With This Repo (Free) You can still use this repository for self-paced lab execution: 1. Set up your lab using Blue Cape Security free tutorials. 2. Run the attack simulation script. 3. Acquire memory and disk images. 4. Start analysis on your forensic workstation. If you want expert-led analysis training, use the Analyst 1 Training Track link above. Prerequisites - Virtualization platform: VirtualBox or VMWare - Host system resources: - 4 GB+ RAM for running Windows VMs (the two VMs do not need to run at the sa","default_branch":null,"files":null,"tree":[],"storefront":"/r/bluecapesecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bluecapesecurity/PWF/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}