
Forensic Computing Course
Master the full digital forensics workflow — from evidence acquisition and storage analysis to malware investigation and expert testimony. This course equips you with the technical skills and legal knowledge demanded by law enforcement, corporate security teams, and private forensic practices. Build the competency to handle real cases, produce court-ready findings, and advance your career in one of cybersecurity's most rigorous disciplines.
What you will learn:
You will learn how to acquire and preserve digital evidence from hard drives, mobile devices, cloud environments, and live systems without compromising admissibility. The course covers file system internals, OS artifact analysis across Windows, macOS, and Linux, and network traffic examination to reconstruct incidents from the ground up. You will develop skills in malware artifact identification, memory forensics, and anti-forensics detection. OSINT techniques, advanced file carving, and data recovery from damaged media are also covered in depth. Finally, you will learn to produce structured forensic reports and prepare for expert witness testimony that holds up under cross-examination.
How you study in practice Forensic Computing Course
How you practice Forensic Computing Course
For companies that want to train their team
With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Forensic Computing
Foundations of Forensic Computing
Lesson 1 • Chain of Custody Fundamentals
Teaches proper evidence tracking, labeling, and transfer procedures. Establishes habits that protect evidence admissibility throughout a case.
Lesson 2 • The Forensic Investigation Process
Introduces the standard investigation lifecycle from identification through reporting. Provides a repeatable workflow students apply in every later chapter.
Lesson 3 • Legal and Ethical Obligations
Examines the legal authority, privacy constraints, and professional ethics governing investigators. Ensures compliant evidence handling from the first case.
Lesson 4 • Forensic Lab Setup and Safety
Covers physical and logical requirements for a forensic workspace. Students can configure a compliant lab environment before handling real evidence.
Lesson 5 • Defining Digital Forensics
Covers the definition, history, and subdisciplines of forensic computing. Anchors all subsequent technical work in a shared conceptual framework.
Chapter 2HideHide detailsSee detailsDigital Storage and Data Structures
Digital Storage and Data Structures
Lesson 1 • File Systems In Depth
Analyzes FAT, NTFS, ext, and APFS file system internals. Students locate metadata, slack space, and deleted entries within each system.
Lesson 2 • Data Deletion and Recovery Concepts
Explains how operating systems mark data as deleted without immediate erasure. Students understand recovery potential before attempting carving techniques.
Lesson 3 • Storage Media Types and Interfaces
Surveys magnetic, solid-state, optical, and flash storage technologies. Knowing media characteristics guides correct acquisition and recovery strategies.
Lesson 4 • Data Encoding and Representation
Covers binary, hexadecimal, ASCII, Unicode, and endianness. Accurate data interpretation depends on recognizing encoding schemes in hex editors.
Lesson 5 • Disk Geometry and Addressing
Explains sectors, clusters, LBA addressing, and partition structures. This knowledge is prerequisite for interpreting raw disk images.
Chapter 3HideHide detailsSee detailsEvidence Acquisition and Imaging
Evidence Acquisition and Imaging
Lesson 1 • Write Blocking and Evidence Integrity
Introduces hardware and software write blockers to prevent media modification. Proper use is mandatory before any acquisition begins.
Lesson 2 • Live and Volatile Data Acquisition
Addresses capturing RAM, running processes, and network state from live systems. Volatile data disappears at shutdown, making live acquisition a critical skill.
Lesson 3 • Hashing and Verification
Teaches MD5, SHA-1, and SHA-256 hashing to verify image integrity. Hash verification is the primary proof that evidence was not altered during acquisition.
Lesson 4 • Mobile and Cloud Evidence Acquisition
Covers logical, physical, and cloud-based acquisition for smartphones and online storage. Students adapt acquisition strategies to device lock states and cloud access constraints.
Lesson 5 • Disk Imaging Techniques
Covers bit-for-bit imaging formats including raw, E01, and AFF. Students select the appropriate format based on case requirements and tool compatibility.
Chapter 4HideHide detailsSee detailsForensic Analysis Fundamentals
Forensic Analysis Fundamentals
Lesson 1 • Keyword Searching and Indexing
Teaches index-based and raw keyword searches across forensic images. Efficient searching reduces analysis time and surfaces relevant evidence faster.
Lesson 2 • Timeline Construction and Analysis
Aggregates timestamps from multiple artifact sources into a unified event timeline. Timelines are the primary tool for reconstructing the sequence of events in a case.
Lesson 3 • Forensic Toolkits and Workflows
Surveys leading forensic platforms and establishes a repeatable analysis workflow. Tool selection and workflow discipline directly affect analysis accuracy and efficiency.
Lesson 4 • File and Metadata Analysis
Examines file headers, magic bytes, metadata fields, and embedded properties. Metadata often reveals creation context, authorship, and geographic location.
Lesson 5 • Hash Analysis and Known File Sets
Uses hash databases to identify known-good and known-bad files rapidly. Filtering known files focuses analyst effort on truly unknown or suspicious content.
Chapter 5HideHide detailsSee detailsOperating System Artifact Analysis
Operating System Artifact Analysis
Lesson 1 • Windows Event Logs and Prefetch
Mines event logs and prefetch files for logon events, process launches, and errors. These artifacts corroborate or contradict user and system activity claims.
Lesson 2 • macOS and Linux Artifact Analysis
Targets plist files, bash history, syslog, and macOS unified logs. Cross-platform competency is essential as enterprise environments mix operating systems.
Lesson 3 • Windows Registry Forensics
Analyzes registry hives for user activity, program execution, and system configuration. The registry is one of the richest artifact sources in Windows investigations.
Lesson 4 • Browser and Internet Artifacts
Recovers browsing history, cache, cookies, and download records from major browsers. Internet artifacts frequently establish motive, intent, and communication patterns.
Lesson 5 • User Account and Authentication Artifacts
Examines account creation, logon records, and credential stores across platforms. Authentication artifacts establish who accessed a system and when.
Chapter 6HideHide detailsSee detailsNetwork Forensics and Traffic Analysis
Network Forensics and Traffic Analysis
Lesson 1 • Packet Capture and Analysis
Teaches live capture and offline analysis of PCAP files using packet analyzers. Packet-level analysis reveals communication content, timing, and anomalies.
Lesson 2 • Network Evidence Correlation
Combines packet captures, logs, and host artifacts into a unified network timeline. Correlation across sources produces stronger, more defensible findings.
Lesson 3 • Intrusion and Exfiltration Detection
Identifies indicators of compromise, lateral movement, and data exfiltration in traffic. Recognizing attack patterns enables accurate incident scoping.
Lesson 4 • Log-Based Network Investigation
Analyzes firewall, proxy, DHCP, and DNS logs to reconstruct network activity. Logs provide evidence when full packet capture is unavailable.
Lesson 5 • Network Fundamentals for Investigators
Reviews TCP/IP, DNS, HTTP, and common protocols from an investigative perspective. Protocol knowledge is prerequisite for interpreting captured traffic accurately.
Chapter 7HideHide detailsSee detailsMalware and Incident Response Forensics
Malware and Incident Response Forensics
Lesson 1 • Memory Forensics for Malware
Extracts injected code, hidden processes, and network connections from RAM dumps. Memory forensics uncovers fileless malware invisible to disk-based analysis.
Lesson 2 • Malware Artifact Identification
Locates persistence mechanisms, dropped files, and registry modifications left by malware. Identifying artifacts is the first step in scoping a compromise.
Lesson 3 • Dynamic Analysis in Safe Environments
Executes malware in isolated sandboxes to observe runtime behavior and network calls. Dynamic analysis reveals capabilities that static analysis cannot expose.
Lesson 4 • Incident Scoping and Containment Evidence
Uses forensic findings to define the incident boundary and affected asset inventory. Accurate scoping drives containment decisions and prevents reinfection.
Lesson 5 • Static Malware Analysis Basics
Examines malware binaries using strings, PE headers, and import tables without execution. Static analysis provides initial indicators without risk of infection.
Chapter 8HideHide detailsSee detailsForensic Reporting and Expert Testimony
Forensic Reporting and Expert Testimony
Lesson 1 • Cross-Examination and Daubert Challenges
Prepares students for adversarial questioning and scientific reliability challenges. Anticipating challenges strengthens both testimony and underlying methodology.
Lesson 2 • Evidence Presentation and Exhibits
Covers creating annotated screenshots, timelines, and data visualizations as court exhibits. Clear exhibits help fact-finders understand complex digital evidence.
Lesson 3 • Writing for Technical and Non-Technical Audiences
Teaches adapting technical language for legal, executive, and technical readers. Audience-appropriate writing maximizes the impact and usability of findings.
Lesson 4 • Expert Witness Roles and Preparation
Explains the distinction between fact and expert witnesses and preparation requirements. Understanding the role prevents testimony errors that undermine case outcomes.
Lesson 5 • Forensic Report Structure and Standards
Defines the required sections, language standards, and objectivity requirements of forensic reports. A well-structured report is the primary deliverable of every investigation.
Your valid completion certificate
This course is for you:
IT support technician: ready to pivot into a specialized investigative security role.
Law enforcement officer: seeking technical skills to handle digital evidence independently.
Cybersecurity analyst: wanting to add formal forensic methodology to existing incident skills.
Recent computer science graduate: aiming to enter the forensic or investigative security field.
Corporate compliance professional: needing to understand digital investigations for internal cases.
Curious self-taught technologist: motivated to pursue a structured, career-grade forensic credential.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in the United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















