{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 36 - Windows Forensics and Tools | Episode 9:  Uncovering Hidden Evidence","slug":"course-36-windows-forensics-and-tools-episode-9-uncovering-hidden-evidence","published_at":"2026-06-07T06:00:03+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-9-uncovering-hidden-evidence","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-36-windows-forensics-and-tools-episode-9-uncovering-hidden-evidence--72013747","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013747/windows_restore_points_trap_stealthy_hackers.mp3","summary":"In this lesson, you’ll learn about: Windows System Restore Points in digital forensics1. What Are System Restore Points? A Windows feature that creates snapshots of system state Designed for recovery after: System failures Bad updates Software issues 🔹 Key Idea They act as a historical snapshot of system behavior 2. Why They Matter in Forensics Restore points preserve evidence that may be: Deleted Wiped Modified 🔹 Forensic Value Helps reconstruct: System changes Malware introduction Configuration modifications 3. What Is Stored in Restore Points Registry snapshots Selected system files Configuration data Logs and application traces 👉 Important Insight: They preserve system state, not just individual files 4. Metadata Preservation🔹 Key Concept Restore points preserve MAC times: Modified Accessed Created 🔹 Why it matters Enables accurate timeline reconstruction Helps detect tampering or backdating attempts 5. Trigger Events for Restore Points🔹 When Windows creates them Software installation System updates Every ~24 hours of uptime Manual user trigger 👉 Key Insight: Restore points are often created during high system activity periods 6. Internal Structure of Restore Points🔹 Storage Location Hidden directory: C:\\System Volume Information 🔹 Folder Structure Stored as sequential folders: RP1 RP2 RP3 etc. 7. File Tracking Mechanism🔹 Key Component filelist.xml 🔹 Purpose Defines: Which file types are monitored Which directories are included 👉 Key Insight: Acts as a control map for snapshot creation 8. Change Tracking System🔹 Important File change.log 🔹 Function Records: Original filenames File locations Snapshot changes 👉 Forensic Value: Helps reconstruct original file paths even after renaming 9. System Management and Registry Control🔹 Registry Role Controls: Enable/disable re…","meta_description":"In this lesson, you’ll learn about: Windows System Restore Points in digital forensics1. What Are System Restore Points? A Windows feature that creates sn…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1518,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-36-windows-forensics-and-tools-episode-9-uncovering-hidden-evidence/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-9-uncovering-hidden-evidence.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}