Group Purchasing
Group Purchasing

What Is the GCFE Certification?

The GIAC Certified Forensic Examiner (GCFE) certification validates a practitioner's ability to collect and analyze data from Windows computer systems. It covers core forensic analysis skills including evidence acquisition, browser forensics, and tracing user and application activity, and it qualifies holders to conduct incident investigations spanning e-Discovery, forensic reporting, and Windows-based user activity tracing.

By the numbers

3 hrs

Exam duration

82

Questions

70%

Min. passing score

What GCFE Covers

GCFE's published exam objectives group into five practical domains.

Forensic Methodology and Triage

Covers Digital Forensic Fundamentals and Forensic Artifact Techniques, the core methodology and triage approach behind every investigation.

Registry, Cloud, and User Activity

Covers Cloud Storage Analysis, File and Program Analysis, and User Artifact Analysis, the artifacts left behind by registry activity, program execution, and cloud storage use.

Device and System Analysis

Covers System and Device Analysis, including file access artifacts and USB device history.

Email and Event Log Analysis

Covers Email Analysis and Event Log Analysis, tracing communications and system activity through logs.

Web Browser Forensics

Covers Browser Forensic Artifacts and Browser Structure and Analysis, examining what browsers reveal about user activity.

Prepare With This Course

FOR500: Windows Forensic Analysis

How FOR500 Prepares You for GCFE

FOR500: Windows Forensic Analysis is built around the exam objectives that make up the GIAC Certified Forensic Examiner (GCFE) certification: 

  • Section 1, Digital Forensics and Advanced Data Triage builds skills tested under Digital Forensic Fundamentals and Forensic Artifact Techniques.
  • Section 2, Registry Analysis, Application Execution, and Cloud Storage Forensics aligns with Cloud Storage Analysis, File and Program Analysis, and User Artifact Analysis.
  • Section 3, Shell Items and Removable Device Profiling builds skills tested under System and Device Analysis.
  • Section 4, Email Analysis, Windows Search, SRUM, and Event Logs aligns with Email Analysis and Event Log Analysis.
  • Section 5, Web Browser Forensics builds skills tested under Browser Forensic Artifacts and Browser Structure and Analysis.

Across all six sections, 22 hands-on labs and a capstone Windows Forensic Challenge give you the chance to apply each skill against real case evidence before you sit the exam. 

Read the full GCFE certification overview.

FOR500 Authors

Who It's For

Information Security Professionals

Incident Response Team Members

Law Enforcement Officers, Federal Agents, and Detectives

Media Exploitation Analysts

Frequently Asked Questions

The GCFE certification proves you can collect and analyze data from Windows computer systems, including e-Discovery, evidence acquisition, browser forensics, and tracing user and application activity. 

The GCFE exam is a single proctored exam, 3 hours long, with 82 questions and a minimum passing score of 70%. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC's renewal page

GCFE is built for information security professionals, incident response team members, law enforcement officers, federal agents and detectives, and media exploitation analysts, along with anyone with an information systems background who wants a deep understanding of Windows forensics. 

FOR500: Windows Forensic Analysis is the SANS course built to prepare you for the GCFE exam. 

Ready to earn your GCFE certification?

Add the GCFE exam attempt when you register for FOR500.

Already trained? Register for the exam directly through GIAC here.

GCFE Certification | GIAC Certified Forensic Examiner | SANS Institute