IWE — Investigating Windows Endpoints
13Cubed's Windows endpoint forensics certification by Richard Davis (Microsoft DART, former SANS instructor) — widely regarded as the highest-quality affordable alternative to SANS FOR500/GCFE. Covers the full Windows artifact landscape: registry, LNK files, shellbags, browser history, email artifacts, prefetch, evidence of execution artifacts (ShimCache, AmCache, PCA, SRUM, UserAssist), NTFS anatomy, file deletion and recovery, and timeline construction with Plaso/Log2Timeline. Two capstone investigation challenges using real forensic disk images. The assessment includes 60 MCQ questions plus 20 practical questions (40% weight) requiring analysis of a compromised forensic image — more hands-on than GIAC's CyberLive component per practitioner comparisons. Non-proctored and open-book, which limits employer recognition versus GCFE, but the training quality genuinely rivals SANS FOR500 content. Covers approximately 80-90% of GCFE content at under 10% of the SANS training cost. Does not cover disk acquisition, memory forensics, or cloud forensics.
| Issuer | 13Cubed |
| Level | intermediate |
| Domains | Digital Forensics & Incident Response |
| Practical weight | 50% |
| Cost (USD) | 795 |
| Renewal | Never expires |
| Skills | windows_artifact_analysis, registry_analysis, lnk_file_analysis, browser_forensics, email_forensics, file_system_analysis, evidence_handling, timeline_analysis |
Official certification page
Browse all 426 cybersecurity certifications on EBCertMap