Choose your language
Forensic Computing Course
More than 2 million students worldwide

Forensic Computing Course

Master the full digital forensics workflow — from evidence acquisition and storage analysis to malware investigation and expert testimony. This course equips you with the technical skills and legal knowledge demanded by law enforcement, corporate security teams, and private forensic practices. Develop the competency to handle real cases, produce court-ready findings, and advance your career in one of cybersecurity's most rigorous disciplines.

Dedika for businesses

What you'll learn:

You will learn how to acquire and preserve digital evidence from hard drives, mobile devices, cloud computing environments, and live systems without compromising admissibility. The course covers file system internals, operating system artefact analysis across Windows, macOS, and Linux, and network traffic examination to reconstruct incidents from the ground up. You will develop skills in malware artefact identification, memory forensics, and anti-forensics detection. OSINT techniques, advanced file carving, and data recovery from damaged media are also covered in depth. Finally, you will learn to produce structured forensic reports and prepare for expert witness testimony that holds up under cross-examination.

How you study in practice Forensic Computing Course

How you practise Forensic Computing Course

For businesses looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Forensic Computing

  • Lesson 1 • Chain of Custody Fundamentals

    Teaches proper evidence tracking, labelling, and transfer procedures. Establishes habits that protect evidence admissibility throughout a case.

  • Lesson 2 • The Forensic Investigation Process

    Introduces the standard investigation lifecycle from identification through reporting. Provides a repeatable workflow students apply in every later chapter.

  • Lesson 3 • Legal and Ethical Obligations

    Examines the legal authority, privacy constraints, and professional ethics governing investigators. Ensures compliant evidence handling from the first case.

  • Lesson 4 • Forensic Lab Setup and Safety

    Covers physical and logical requirements for a forensic workspace. Students can configure a compliant lab environment before handling real evidence.

  • Lesson 5 • Defining Digital Forensics

    Covers the definition, history, and subdisciplines of forensic computing. Anchors all subsequent technical work in a shared conceptual framework.

Chapter 2See details

Digital Storage and Data Structures

  • Lesson 1 • File Systems In Depth

    Analyses FAT, NTFS, ext, and APFS file system internals. Students locate metadata, slack space, and deleted entries within each system.

  • Lesson 2 • Data Deletion and Recovery Concepts

    Explains how operating systems mark data as deleted without immediate erasure. Students understand recovery potential before attempting carving techniques.

  • Lesson 3 • Storage Media Types and Interfaces

    Surveys magnetic, solid-state, optical, and flash storage technologies. Knowing media characteristics guides correct acquisition and recovery strategies.

  • Lesson 4 • Data Encoding and Representation

    Covers binary, hexadecimal, ASCII, Unicode, and endianness. Accurate data interpretation depends on recognising encoding schemes in hex editors.

  • Lesson 5 • Disk Geometry and Addressing

    Explains sectors, clusters, LBA addressing, and partition structures. This knowledge is prerequisite for interpreting raw disk images.

Chapter 3See details

Evidence Acquisition and Imaging

  • Lesson 1 • Write Blocking and Evidence Integrity

    Introduces hardware and software write blockers to prevent media modification. Proper use is mandatory before any acquisition begins.

  • Lesson 2 • Live and Volatile Data Acquisition

    Addresses capturing RAM, running processes, and network state from live systems. Volatile data disappears at shutdown, making live acquisition a critical skill.

  • Lesson 3 • Hashing and Verification

    Teaches MD5, SHA-1, and SHA-256 hashing to verify image integrity. Hash verification is the primary proof that evidence was not altered during acquisition.

  • Lesson 4 • Mobile and Cloud Evidence Acquisition

    Covers logical, physical, and cloud-based acquisition for smartphones and online storage. Students adapt acquisition strategies to device lock states and cloud access constraints.

  • Lesson 5 • Disk Imaging Techniques

    Covers bit-for-bit imaging formats including raw, E01, and AFF. Students select the appropriate format based on case requirements and tool compatibility.

Chapter 4See details

Forensic Analysis Fundamentals

  • Lesson 1 • Keyword Searching and Indexing

    Teaches index-based and raw keyword searches across forensic images. Efficient searching reduces analysis time and surfaces relevant evidence faster.

  • Lesson 2 • Timeline Construction and Analysis

    Aggregates timestamps from multiple artefact sources into a unified event timeline. Timelines are the primary tool for reconstructing the sequence of events in a case.

  • Lesson 3 • Forensic Toolkits and Workflows

    Surveys leading forensic platforms and establishes a repeatable analysis workflow. Tool selection and workflow discipline directly affect analysis accuracy and efficiency.

  • Lesson 4 • File and Metadata Analysis

    Examines file headers, magic bytes, metadata fields, and embedded properties. Metadata often reveals creation context, authorship, and geographic location.

  • Lesson 5 • Hash Analysis and Known File Sets

    Uses hash databases to identify known-good and known-bad files rapidly. Filtering known files focuses analyst effort on truly unknown or suspicious content.

Chapter 5See details

Operating System Artifact Analysis

  • Lesson 1 • Windows Event Logs and Prefetch

    Mines event logs and prefetch files for logon events, process launches, and errors. These artefacts corroborate or contradict user and system activity claims.

  • Lesson 2 • macOS and Linux Artifact Analysis

    Targets plist files, bash history, syslog, and macOS unified logs. Cross-platform competency is essential as enterprise environments mix operating systems.

  • Lesson 3 • Windows Registry Forensics

    Analyses registry hives for user activity, program execution, and system configuration. The registry is one of the richest artefact sources in Windows investigations.

  • Lesson 4 • Browser and Internet Artifacts

    Recovers browsing history, cache, cookies, and download records from major browsers. Internet artefacts frequently establish motive, intent, and communication patterns.

  • Lesson 5 • User Account and Authentication Artifacts

    Examines account creation, logon records, and credential stores across platforms. Authentication artefacts establish who accessed a system and when.

Chapter 6See details

Network Forensics and Traffic Analysis

  • Lesson 1 • Packet Capture and Analysis

    Teaches live capture and offline analysis of PCAP files using packet analysers. Packet-level analysis reveals communication content, timing, and anomalies.

  • Lesson 2 • Network Evidence Correlation

    Combines packet captures, logs, and host artefacts into a unified network timeline. Correlation across sources produces stronger, more defensible findings.

  • Lesson 3 • Intrusion and Exfiltration Detection

    Identifies indicators of compromise, lateral movement, and data exfiltration in traffic. Recognising attack patterns enables accurate incident scoping.

  • Lesson 4 • Log-Based Network Investigation

    Analyses firewall, proxy, DHCP, and DNS logs to reconstruct network activity. Logs provide evidence when full packet capture is unavailable.

  • Lesson 5 • Network Fundamentals for Investigators

    Reviews TCP/IP, DNS, HTTP, and common protocols from an investigative perspective. Protocol knowledge is prerequisite for interpreting captured traffic accurately.

Chapter 7See details

Malware and Incident Response Forensics

  • Lesson 1 • Memory Forensics for Malware

    Extracts injected code, hidden processes, and network connections from RAM dumps. Memory forensics uncovers fileless malware invisible to disk-based analysis.

  • Lesson 2 • Malware Artifact Identification

    Locates persistence mechanisms, dropped files, and registry modifications left by malware. Identifying artefacts is the first step in scoping a compromise.

  • Lesson 3 • Dynamic Analysis in Safe Environments

    Executes malware in isolated sandboxes to observe runtime behaviour and network calls. Dynamic analysis reveals capabilities that static analysis cannot expose.

  • Lesson 4 • Incident Scoping and Containment Evidence

    Uses forensic findings to define the incident boundary and affected asset inventory. Accurate scoping drives containment decisions and prevents reinfection.

  • Lesson 5 • Static Malware Analysis Basics

    Examines malware binaries using strings, PE headers, and import tables without execution. Static analysis provides initial indicators without risk of infection.

Chapter 8See details

Forensic Reporting and Expert Testimony

  • Lesson 1 • Cross-Examination and Daubert Challenges

    Prepares students for adversarial questioning and scientific reliability challenges. Anticipating challenges strengthens both testimony and underlying methodology.

  • Lesson 2 • Evidence Presentation and Exhibits

    Covers creating annotated screenshots, timelines, and data visualisations as court exhibits. Clear exhibits help fact-finders understand complex digital evidence.

  • Lesson 3 • Writing for Technical and Non-Technical Audiences

    Teaches adapting technical language for legal, executive, and technical readers. Audience-appropriate writing maximises the impact and usability of findings.

  • Lesson 4 • Expert Witness Roles and Preparation

    Explains the distinction between fact and expert witnesses and preparation requirements. Understanding the role prevents testimony errors that undermine case outcomes.

  • Lesson 5 • Forensic Report Structure and Standards

    Defines the required sections, language standards, and objectivity requirements of forensic reports. A well-structured report is the primary deliverable of every investigation.

Certification

Your valid completion certificate

This course is for you:

  • IT support technician: ready to pivot into a specialised investigative security role.

  • Law enforcement officer: seeking technical skills to handle digital evidence independently.

  • Cybersecurity analyst: wanting to add formal forensic methodology to existing incident skills.

  • Recent computer science graduate: aiming to enter the forensic or investigative security field.

  • Corporate compliance professional: needing to understand digital investigations for internal cases.

  • Curious self-taught technologist: motivated to pursue a structured, career-grade forensic credential.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top upskilling courses

FAQ

Who is Dedika?

Is the certificate valid in Australia?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course