← Back to Courses

Digital Forensics 101

ULTRA-DETAILED: Master the forensics mindset, chain of custody, and digital evidence preservation.

Curriculum

20 Modules
1

The Forensics Mindset & Chain of Custody

Learn the ethical core, scientific methodology, and chain of custody protocols.

2

Evidence Acquisition (Imaging)

Creating bit-for-bit copies using FTK Imager, dd, and hardware write blockers.

3

File Systems: FAT/NTFS/EXT

Understanding how data is physically stored and deleted (MFT, Inodes).

4

Windows Forensics: Registry

Analyzing the Windows Registry for user activity, USB history, and autoruns.

5

Windows Forensics: Artifacts

Prefetch, Jump Lists, LNK files, and Shellbags.

6

Browser Forensics

Recovering history, cache, cookies, and passwords from Chrome/Firefox.

7

Email Forensics

Tracing headers, recovering deleted emails (PST/OST), and phishing analysis.

8

Memory (RAM) Forensics

Using Volatility to find malware, injected code, and passwords in RAM.

9

Network Forensics

Analyzing PCAP files with Wireshark to reconstruct attacks.

10

Mobile Forensics (iOS/Android)

Acquisition techniques, iTunes backups, and SQLite database analysis.

11

Linux Forensics

Investigating compromised Linux servers, logs (/var/log), and bash history.

12

Mac OS Forensics

APFS specifics, FSEvents, and property list (plist) analysis.

13

Malware Forensics

Static analysis basics for investigators (identifying packed files).

14

Timeline Analysis

Creating a super-timeline (Plaso) to reconstruct the entire incident.

15

Anti-Forensics

Detecting data destruction, encryption, and time stomping.

16

Database Forensics

Investigating SQL injection attacks and database logs.

17

Cloud Forensics (AWS/Azure)

Investigating cloud logs (CloudTrail) and compromised instances.

18

Report Writing for Court

Structuring a forensic report and expert witness preparedness.

19

Lab Management

Building and maintaining a secure forensics lab.

20

Capstone Case

Full investigation of a corporate espionage scenario.

Course Info

~600 Minutes
20 Modules
Start Learning