Choose your language
Data forensics Course
More than 2 million students worldwide

Data forensics Course

Master the full digital forensics pipeline — from seizing evidence to testifying in court. This course gives you the technical depth and legal grounding to investigate Windows systems, mobile devices, cloud platforms, and network traffic. Whether you're pursuing a career in law enforcement, corporate security, or consulting, you'll graduate with skills that hold up under cross-examination.

Dedika for businesses

What you will learn:

You'll build a complete forensic skill set covering evidence acquisition, file system analysis, memory forensics, and network investigation. You'll learn how to image storage media, parse Windows artefacts, extract data from mobile devices, and analyse packet captures for signs of intrusion. The course also covers anti-forensics detection, database forensics, OSINT integration, and incident response triage. You'll write professional forensic reports and prepare for expert witness testimony. Scripting and automation modules teach you to accelerate repetitive analysis tasks using Python. By the end, you'll have the technical knowledge and procedural discipline required for real-world forensic casework.

How you study in practice Data forensics Course

How you practise Data forensics Course

For businesses looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Digital Forensics

  • Lesson 1 • Legal and Ethical Obligations

    Covers admissibility requirements, chain-of-custody rules, and investigator ethics. Ensures students understand constraints that govern every forensic action.

  • Lesson 2 • What Is Digital Forensics

    Defines digital forensics, its scope, and its role in investigations. Anchors all subsequent technical work in a clear disciplinary framework.

  • Lesson 3 • Setting Up a Forensic Lab Environment

    Guides students through hardware, software, and procedural requirements for a forensic workspace. Establishes safe, repeatable conditions for all lab exercises.

  • Lesson 4 • The Forensic Investigation Lifecycle

    Maps the end-to-end process from incident identification to case closure. Students gain a repeatable mental model for structuring any investigation.

  • Lesson 5 • Types of Digital Evidence

    Catalogs volatile, non-volatile, and network-based evidence categories. Prepares students to recognise and prioritise evidence sources in real scenarios.

Chapter 2See details

Data Storage and File System Fundamentals

  • Lesson 1 • File System Internals

    Examines FAT, NTFS, ext4, and APFS file system structures in forensic detail. Students extract metadata and locate artifacts within each file system.

  • Lesson 2 • Encoding, Hashing, and Data Integrity

    Introduces character encoding, cryptographic hashing, and integrity verification. Students apply hashing to confirm evidence authenticity throughout an investigation.

  • Lesson 3 • File Deletion and Data Remnants

    Explains what happens at the file system level when files are deleted. Students understand where recoverable data persists after deletion.

  • Lesson 4 • Storage Media Architecture

    Explains HDD, SSD, and flash storage internals relevant to forensic recovery. Connects physical media behaviour to evidence acquisition strategies.

  • Lesson 5 • Partition Schemes and Boot Structures

    Covers MBR, GPT, and volume structures that organise storage media. Students learn to interpret partition tables to map evidence locations.

Chapter 3See details

Evidence Acquisition and Preservation

  • Lesson 1 • Principles of Forensic Acquisition

    Establishes write-blocking, bit-for-bit imaging, and verification as non-negotiable acquisition standards. Grounds all acquisition techniques in defensible methodology.

  • Lesson 2 • Disk and Media Imaging

    Covers tools and procedures for imaging HDDs, SSDs, and removable media. Students produce and verify forensic images in standard formats.

  • Lesson 3 • Cloud and Remote Evidence Collection

    Explains legal authorisation and technical methods for collecting cloud-hosted evidence. Students document cloud acquisition to satisfy chain-of-custody requirements.

  • Lesson 4 • Mobile Device Acquisition

    Covers logical, file system, and physical extraction methods for smartphones and tablets. Students select the appropriate extraction level based on device state.

  • Lesson 5 • Live System and Memory Acquisition

    Addresses capturing volatile data from running systems before shutdown. Students prioritise and collect RAM, process lists, and network state.

Chapter 4See details

Forensic Analysis of Windows Systems

  • Lesson 1 • Windows Timeline and Filesystem Artifacts

    Analyzes NTFS timestamps, $MFT, $LogFile, and $UsnJrnl for file activity reconstruction. Students build chronological timelines of file system events.

  • Lesson 2 • Windows Event Log Analysis

    Covers EVTX log structure, key event IDs, and log correlation techniques. Students identify authentication, process, and security events relevant to investigations.

  • Lesson 3 • Windows Registry Forensics

    Examines registry hives as a rich source of user and system activity artifacts. Students parse hive files to extract configuration, usage, and timeline data.

  • Lesson 4 • Browser and Communication Artifacts

    Extracts browsing history, cached files, cookies, and email artefacts from Windows systems. Students link online activity to user accounts and timeframes.

  • Lesson 5 • Windows Artifact Analysis

    Targets prefetch, LNK files, jump lists, and shellbags as execution and access evidence. Students reconstruct programme execution and file access timelines.

Chapter 5See details

Memory Forensics and Malware Analysis

  • Lesson 1 • Malware Artifact Extraction

    Guides extraction of suspicious executables, strings, and configuration data from memory. Students produce actionable indicators of compromise from memory evidence.

  • Lesson 2 • Memory Architecture and Acquisition Review

    Reviews virtual memory layout, process address spaces, and kernel structures relevant to analysis. Connects acquisition concepts from Chapter 3 to analytical techniques.

  • Lesson 3 • Process and Network Analysis in Memory

    Identifies running processes, DLL loads, and active network connections within memory images. Students detect anomalous processes and hidden network activity.

  • Lesson 4 • Code Injection and Rootkit Detection

    Covers common injection techniques including DLL injection, process hollowing, and reflective loading. Students identify injected code regions and rootkit hooks.

  • Lesson 5 • Static and Dynamic Malware Analysis Basics

    Introduces safe static examination and controlled dynamic execution of extracted malware samples. Students characterise malware behaviour without compromising the investigation environment.

Chapter 6See details

Network Forensics and Log Analysis

  • Lesson 1 • Intrusion and Attack Pattern Recognition

    Teaches recognition of scanning, exploitation, and lateral movement patterns in network data. Students map observed traffic to known attack stages.

  • Lesson 2 • Network Evidence Sources and Collection

    Catalogues packet captures, NetFlow, firewall logs, and proxy logs as primary network evidence. Students identify which sources answer specific investigative questions.

  • Lesson 3 • Packet Capture Analysis

    Covers deep packet inspection, protocol dissection, and stream reassembly techniques. Students reconstruct sessions and extract transferred files from PCAP evidence.

  • Lesson 4 • Wireless and VoIP Forensics

    Addresses evidence collection and analysis from Wi-Fi and voice-over-IP communications. Students apply packet analysis skills to wireless and telephony evidence.

  • Lesson 5 • Log Aggregation and Correlation

    Explains normalisation, aggregation, and correlation of logs from multiple network devices. Students build unified timelines from heterogeneous log sources.

Chapter 7See details

Mobile and Cloud Forensics

  • Lesson 1 • Cloud Storage and Collaboration Forensics

    Covers artefact recovery from cloud storage, email, and collaboration platforms. Students use API access and local sync artefacts to reconstruct cloud activity.

  • Lesson 2 • IoT and Wearable Device Forensics

    Introduces evidence sources from smart home devices, wearables, and connected vehicles. Students identify and collect IoT artefacts relevant to investigations.

  • Lesson 3 • Mobile Operating System Internals

    Examines iOS and Android file system layouts, data partitions, and app storage models. Students navigate mobile storage structures to locate forensic artefacts.

  • Lesson 4 • Mobile Application Artifact Analysis

    Targets SQLite databases, plist files, and cached data within mobile applications. Students extract communication, location, and activity artefacts from app data.

  • Lesson 5 • Cross-Platform Evidence Correlation

    Integrates mobile, cloud, and desktop artefacts into a unified investigative picture. Students resolve conflicts and gaps across platforms to build a coherent timeline.

Chapter 8See details

Forensic Reporting and Expert Testimony

  • Lesson 1 • Case Management and Documentation

    Establishes systems for managing evidence, notes, and communications throughout a case. Students apply documentation practices that protect case integrity from start to finish.

  • Lesson 2 • Timeline and Visualisation Techniques

    Covers tools and methods for creating visual timelines and evidence maps. Students produce graphics that clarify complex event sequences for any audience.

  • Lesson 3 • Preparing for Expert Testimony

    Prepares students for deposition and courtroom testimony as a forensic expert witness. Students practise explaining methodology and defending findings under cross-examination.

  • Lesson 4 • Writing for Non-Technical Audiences

    Teaches plain-language translation of technical forensic findings for legal and executive readers. Students rewrite complex findings without sacrificing accuracy.

  • Lesson 5 • Forensic Report Structure and Standards

    Defines required components of a forensic report and professional writing standards. Students draft reports that meet evidentiary and organisational requirements.

Certification

Your valid completion certificate

This course is for you:

  • IT professional: wants to formalise investigative skills already used on the job.

  • Cybersecurity analyst: ready to move beyond detection into structured evidence-based investigation.

  • Law enforcement officer: needs technical depth to handle digital evidence in criminal cases.

  • Compliance or fraud investigator: handles data disputes and needs defensible forensic methodology.

  • Career changer: comes from a technical background and is targeting the forensics field.

  • Computer science student: building specialised skills to stand out in a competitive job market.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQ

Who is Dedika?

Is the certificate valid in the United Kingdom?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course