We use cookies to ensure you get the best user experience. For more information see our cookie policy.
To access material, start machines and answer questions login.
User accounts play a crucial role in cyber security. They are access points to sensitive systems and data, making them a focus of most cyber attacks. To help us with our investigations, we need to understand better user accounts and the forensic artefacts they leave behind.
This room delves into Windows forensics, focusing on user account activity and system interactions. We will be examining logs, network traffic, and policies. All of these create system artefacts unique to Windows that can give us a better understanding of how an attack happened.
In order to benefit from the content in this room, it is recommended to already have knowledge covering:
Start the lab machine in split-screen view by clicking on the green “Start Lab Machine” button on the upper right section of this task. If the is not visible, use the blue “Show Split View” button at the top of the page. Alternatively, you can connect to the using the credentials below via “Remote Desktop”.
Note: The may take a few minutes to start up.
| Username | Administrator |
| Password | Passw0rd! |
| IP | MACHINE_IP |
The Windows User Account Forensics room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in