This hands-on course introduces the forensic value of the Windows Recycle Bin and how it can be used to uncover evidence of deleted file activity. You will learn how Windows stores deleted items and how to analyze key artifacts, including $R and $I files, to extract information such as original file paths, sizes, and deletion timestamps.
The course covers essential tools and techniques used to parse and interpret Recycle Bin data, including practical usage of tools like RBCmd.exe and Rifiuti2. You will also explore the difference between recovered and permanently deleted files, and how to extract useful evidence even when files are no longer accessible.
Through hands-on exercises and a guided lab, you will apply these techniques in real scenarios, reinforcing your ability to investigate and analyze Recycle Bin artifacts effectively.
NICE Framework Alignment
This course is strategically aligned to the NIST NICE Workforce Framework for Cybersecurity, supporting key DFIR job roles and competencies:
-
PD-WRL-002 — Digital Forensics
Applying structured forensic investigation techniques in Windows artifact analysis
-
IN-WRL-002 — Digital Evidence Analysis
Identifying, collecting, and interpreting digital evidence from the Windows Recycle Bin
This alignment ensures the course reflects real-world cybersecurity workforce requirements and develops practical skills in digital forensic investigation and evidence interpretation.
-
Self-Paced Learning: Access course materials at your convenience, allowing you to learn at your own pace.
-
Interactive Labs: Engage in practical exercises and labs to apply theoretical knowledge in real-world scenarios.
-
Virtual Lab Access: Enroll in the course with an option that includes 10 hours of virtual lab access for hands-on practice. Visi our
Virtual Lab Environment
-
Technical Requirements: Ensure you have a workstation with at least 16GB RAM and 100GB disk space, along with an internet connection, to participate in the hands-on labs.
-
-
-
-
-
-
Check-in Quiz (Hands-on) - Solution
-
-
-
Recovering Permanently Deleted Files
-
-
-
-
Lab 01 - Recycle Bin - Solutions
- Understand the differences between $R and $I Recycle Bin files and learn how to parse them
- Learn the role of timestamps in Recycle Bin artifacts
- Parse the hex content of $R and $I files
- Learn how to use RBCmd.exe and Rifiuti2 Recycle Bin parsing tools for forensic investigation
- Review artifacts left behind from permanently deleting or recovering files
- Identify artifacts left behind from permanently deleting or recovering files