
Digital Forensics and Investigation Course
Master the tools, techniques, and legal standards used by professional digital forensic investigators. This course takes you from foundational principles through advanced analysis of Windows systems, mobile devices, networks, and malware. You will learn to collect, preserve, and present digital evidence that holds up in court.
What you will learn:
You will build a complete skill set in digital forensics, starting with investigative frameworks, legal authority, and chain of custody protocols. From there, you will analyze Windows artifacts, mobile platforms, and network traffic to reconstruct events and identify threat actors. You will also examine malware behavior, detect anti-forensic techniques, and investigate cloud and virtual environments. Hands-on coverage of industry-standard tools prepares you to handle real casework with confidence. By the end, you will know how to document findings and communicate them clearly to legal teams, executives, and law enforcement.
How you study in a practical way Digital Forensics and Investigation Course
How you practice Digital Forensics and Investigation Course
For companies who want to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Digital Forensics
Foundations of Digital Forensics
Lesson 1 • Legal and Ethical Framework
Examines the legal authority, privacy considerations, and ethical obligations governing investigations. Ensures students operate within lawful and professional boundaries.
Lesson 2 • Types of Digital Evidence
Categorizes volatile, non-volatile, and network-based evidence and their forensic significance. Prepares students to recognize evidence types in subsequent technical chapters.
Lesson 3 • The Investigative Process Model
Introduces structured investigation models and their phases from identification to reporting. Provides a repeatable framework students apply throughout the course.
Lesson 4 • Defining Digital Forensics
Covers the definition, history, and scope of digital forensics as a discipline. Grounds students in the field's purpose before advancing to technical methods.
Chapter 2HideHide detailsSee detailsDigital Storage and Data Fundamentals
Digital Storage and Data Fundamentals
Lesson 1 • Storage Media and Architecture
Covers HDD, SSD, flash, and optical media architectures and their forensic implications. Connects hardware knowledge to evidence acquisition strategies in later chapters.
Lesson 2 • Data Encoding and Representation
Teaches binary, hexadecimal, ASCII, and Unicode encoding as applied to forensic data interpretation. Students decode raw bytes to identify evidence artifacts accurately.
Lesson 3 • Deleted Data and Slack Space
Explains how deletion works at the file system level and where residual data persists. Students recover evidence from unallocated space and slack regions.
Lesson 4 • File Systems In Depth
Examines FAT, NTFS, ext, and APFS file system structures and metadata. Enables students to navigate and interpret file system artifacts during analysis.
Chapter 3HideHide detailsSee detailsEvidence Acquisition and Preservation
Evidence Acquisition and Preservation
Lesson 1 • Chain of Custody Management
Establishes documentation, labeling, and storage protocols that preserve evidence integrity. Students create and maintain custody records that withstand legal scrutiny.
Lesson 2 • Principles of Forensic Acquisition
Defines write-blocking, bit-for-bit imaging, and verification hashing as core acquisition principles. Establishes the integrity standards all subsequent acquisition tasks must meet.
Lesson 3 • Disk and Drive Imaging
Covers imaging formats such as raw, E01, and AFF and the tools used to create them. Students perform full and targeted disk acquisitions with verified integrity.
Lesson 4 • Live and Volatile Data Acquisition
Addresses capturing RAM, running processes, and network state from live systems. Prepares students to collect ephemeral evidence before system shutdown.
Lesson 5 • Mobile and Removable Media Acquisition
Covers acquisition methods for smartphones, tablets, USB drives, and memory cards. Students apply appropriate extraction levels based on device type and access.
Chapter 4HideHide detailsSee detailsForensic Analysis of Windows Systems
Forensic Analysis of Windows Systems
Lesson 1 • Browser and Application Artifacts
Extracts browsing history, cached files, cookies, and application-specific artifacts. Students reconstruct user online behavior and application usage patterns.
Lesson 2 • Windows Registry Forensics
Examines registry hive structure, key locations, and artifact types relevant to investigations. Students extract user activity, program execution, and device connection evidence.
Lesson 3 • Windows Event Log Analysis
Covers event log formats, critical event IDs, and log correlation techniques. Students reconstruct logon events, privilege escalation, and security incidents from logs.
Lesson 4 • Windows Memory and Paging Analysis
Covers pagefile, hibernation file, and memory dump analysis for Windows systems. Students recover passwords, process data, and network connections from memory artifacts.
Lesson 5 • File System and Metadata Artifacts
Analyzes NTFS timestamps, LNK files, jump lists, and prefetch data for user activity. Students build timelines from metadata artifacts to support investigative conclusions.
Chapter 5HideHide detailsSee detailsNetwork Forensics and Traffic Analysis
Network Forensics and Traffic Analysis
Lesson 1 • Protocol Analysis and Reconstruction
Covers TCP/IP, DNS, HTTP, and email protocol analysis for evidence extraction. Students reconstruct sessions and communications from raw packet captures.
Lesson 2 • Network Forensics Fundamentals
Introduces network evidence sources, capture points, and the forensic value of traffic data. Connects network concepts to the broader investigative process established earlier.
Lesson 3 • Network Timeline and Attribution
Synthesizes network evidence into timelines and maps activity to specific hosts or users. Students produce attribution reports supported by corroborated network artifacts.
Lesson 4 • Intrusion Detection and Log Analysis
Examines firewall, IDS, proxy, and DHCP logs for indicators of compromise. Students correlate log sources to identify attack timelines and affected hosts.
Lesson 5 • Wireless Network Forensics
Addresses Wi-Fi traffic capture, authentication artifacts, and rogue access point detection. Students analyze wireless evidence to identify unauthorized access events.
Chapter 6HideHide detailsSee detailsMobile Device Forensics
Mobile Device Forensics
Lesson 1 • Mobile Application Artifact Analysis
Examines social media, browser, and productivity app databases for user activity evidence. Students extract and interpret app-specific artifacts to reconstruct user behavior.
Lesson 2 • Location and Sensor Data Analysis
Analyzes GPS logs, Wi-Fi location data, and cell tower records to establish device location history. Students map movement patterns to support investigative timelines.
Lesson 3 • Mobile Platform Architectures
Compares iOS and Android architectures, file systems, and security models relevant to forensics. Provides the platform knowledge required for targeted extraction and analysis.
Lesson 4 • Communication and Messaging Artifacts
Extracts SMS, MMS, call logs, and third-party messaging app data from mobile devices. Students recover deleted messages and reconstruct communication timelines.
Lesson 5 • Mobile Extraction Techniques
Covers logical, file system, physical, and advanced extraction methods for mobile devices. Students select and apply the appropriate method based on device state and access.
Chapter 7HideHide detailsSee detailsMalware Forensics and Incident Response
Malware Forensics and Incident Response
Lesson 1 • Static Malware Analysis
Covers file hashing, string extraction, PE header analysis, and signature-based detection. Students characterize malware without execution to safely identify indicators of compromise.
Lesson 2 • Dynamic Malware Analysis
Examines sandbox execution, behavioral monitoring, and network traffic generated by malware. Students observe malware actions in a controlled environment to document its capabilities.
Lesson 3 • Malware Artifact Documentation
Structures findings from malware investigations into indicators of compromise and formal reports. Students produce deliverables usable by both technical teams and legal stakeholders.
Lesson 4 • Malware Classification and Behavior
Categorizes malware types by behavior, persistence mechanism, and forensic footprint. Establishes the taxonomy students use when identifying malware artifacts in investigations.
Lesson 5 • Incident Response Integration
Applies the incident response lifecycle to malware events, from detection through containment. Students coordinate forensic collection with response actions to preserve evidence.
Chapter 8HideHide detailsSee detailsForensic Reporting and Expert Testimony
Forensic Reporting and Expert Testimony
Lesson 1 • Case File Management and Closure
Covers case file organization, evidence return or disposal, and post-case review processes. Students close investigations in a manner that satisfies legal and organizational requirements.
Lesson 2 • Expert Witness Roles and Responsibilities
Defines the expert witness role, qualification standards, and duties of impartiality. Students understand their obligations before, during, and after providing expert testimony.
Lesson 3 • Evidence Presentation Techniques
Covers visual aids, timelines, and exhibit preparation for presenting digital evidence. Students create clear exhibits that support investigative conclusions for diverse audiences.
Lesson 4 • Courtroom Testimony Skills
Prepares students for direct examination, cross-examination, and handling adversarial questioning. Students practice delivering clear, composed, and credible testimony under pressure.
Lesson 5 • Forensic Report Structure and Standards
Defines the components, language standards, and objectivity requirements of a forensic report. Students draft reports that meet professional and legal admissibility expectations.
Your valid completion certificate
This course is for you:
IT support technician: ready to specialize in a higher-demand investigative role.
Law enforcement officer: seeking technical skills to handle digital evidence independently.
Cybersecurity analyst: wanting to add structured forensic investigation to existing defenses.
Paralegal or attorney: needing to understand digital evidence for stronger case preparation.
Career changer: drawn to investigative work and comfortable learning technical subject matter.
System administrator: looking to pivot toward incident investigation and evidence handling.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in the Philippines?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















