
Data forensics Course
Master the full digital forensics pipeline — from seizing evidence to testifying in court. This course gives you the technical depth and legal grounding to investigate Windows systems, mobile devices, cloud platforms, and network traffic. Whether you are pursuing a career in law enforcement, corporate security, or consulting, you will graduate with skills that hold up under cross-examination.
What you will learn:
You will build a complete forensic skill set covering evidence acquisition, file system analysis, memory forensics, and network investigation. You will learn how to image storage media, parse Windows artifacts, extract data from mobile devices, and analyse packet captures for signs of intrusion. The course also covers anti-forensics detection, database forensics, OSINT integration, and incident response triage. You will write professional forensic reports and prepare for expert witness testimony. Scripting and automation modules teach you to accelerate repetitive analysis tasks using Python. By the end, you will have the technical knowledge and procedural discipline required for real-world forensic casework.
How you study in practice Data forensics Course
How you practise Data forensics Course
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Digital Forensics
Foundations of Digital Forensics
Lesson 1 • Legal and Ethical Obligations
Covers admissibility requirements, chain-of-custody rules, and investigator ethics. Ensures learners understand constraints that govern every forensic action.
Lesson 2 • What Is Digital Forensics
Defines digital forensics, its scope, and its role in investigations. Anchors all subsequent technical work in a clear disciplinary framework.
Lesson 3 • Setting Up a Forensic Lab Environment
Guides learners through hardware, software, and procedural requirements for a forensic workspace. Establishes safe, repeatable conditions for all lab exercises.
Lesson 4 • The Forensic Investigation Lifecycle
Maps the end-to-end process from incident identification to case closure. Learners gain a repeatable mental model for structuring any investigation.
Lesson 5 • Types of Digital Evidence
Catalogues volatile, non-volatile, and network-based evidence categories. Prepares learners to recognise and prioritise evidence sources in real scenarios.
Chapter 2HideHide detailsSee detailsData Storage and File System Fundamentals
Data Storage and File System Fundamentals
Lesson 1 • File System Internals
Examines FAT, NTFS, ext4, and APFS file system structures in forensic detail. Learners extract metadata and locate artefacts within each file system.
Lesson 2 • Encoding, Hashing, and Data Integrity
Introduces character encoding, cryptographic hashing, and integrity verification. Learners apply hashing to confirm evidence authenticity throughout an investigation.
Lesson 3 • File Deletion and Data Remnants
Explains what happens at the file system level when files are deleted. Learners understand where recoverable data persists after deletion.
Lesson 4 • Storage Media Architecture
Explains HDD, SSD, and flash storage internals relevant to forensic recovery. Connects physical media behaviour to evidence acquisition strategies.
Lesson 5 • Partition Schemes and Boot Structures
Covers MBR, GPT, and volume structures that organise storage media. Learners learn to interpret partition tables to map evidence locations.
Chapter 3HideHide detailsSee detailsEvidence Acquisition and Preservation
Evidence Acquisition and Preservation
Lesson 1 • Principles of Forensic Acquisition
Establishes write-blocking, bit-for-bit imaging, and verification as non-negotiable acquisition standards. Grounds all acquisition techniques in defensible methodology.
Lesson 2 • Disk and Media Imaging
Covers tools and procedures for imaging HDDs, SSDs, and removable media. Learners produce and verify forensic images in standard formats.
Lesson 3 • Cloud and Remote Evidence Collection
Explains legal authorisation and technical methods for collecting cloud-hosted evidence. Learners document cloud acquisition to satisfy chain-of-custody requirements.
Lesson 4 • Mobile Device Acquisition
Covers logical, file system, and physical extraction methods for smartphones and tablets. Learners select the appropriate extraction level based on device state.
Lesson 5 • Live System and Memory Acquisition
Addresses capturing volatile data from running systems before shutdown. Learners prioritise and collect RAM, process lists, and network state.
Chapter 4HideHide detailsSee detailsForensic Analysis of Windows Systems
Forensic Analysis of Windows Systems
Lesson 1 • Windows Timeline and Filesystem Artifacts
Analyses NTFS timestamps, $MFT, $LogFile, and $UsnJrnl for file activity reconstruction. Learners build chronological timelines of file system events.
Lesson 2 • Windows Event Log Analysis
Covers EVTX log structure, key event IDs, and log correlation techniques. Learners identify authentication, process, and security events relevant to investigations.
Lesson 3 • Windows Registry Forensics
Examines registry hives as a rich source of user and system activity artefacts. Learners parse hive files to extract configuration, usage, and timeline data.
Lesson 4 • Browser and Communication Artifacts
Extracts browsing history, cached files, cookies, and email artefacts from Windows systems. Learners link online activity to user accounts and timeframes.
Lesson 5 • Windows Artifact Analysis
Targets prefetch, LNK files, jump lists, and shellbags as execution and access evidence. Learners reconstruct programme execution and file access timelines.
Chapter 5HideHide detailsSee detailsMemory Forensics and Malware Analysis
Memory Forensics and Malware Analysis
Lesson 1 • Malware Artifact Extraction
Guides extraction of suspicious executables, strings, and configuration data from memory. Learners produce actionable indicators of compromise from memory evidence.
Lesson 2 • Memory Architecture and Acquisition Review
Reviews virtual memory layout, process address spaces, and kernel structures relevant to analysis. Connects acquisition concepts from Chapter 3 to analytical techniques.
Lesson 3 • Process and Network Analysis in Memory
Identifies running processes, DLL loads, and active network connections within memory images. Learners detect anomalous processes and hidden network activity.
Lesson 4 • Code Injection and Rootkit Detection
Covers common injection techniques including DLL injection, process hollowing, and reflective loading. Learners identify injected code regions and rootkit hooks.
Lesson 5 • Static and Dynamic Malware Analysis Basics
Introduces safe static examination and controlled dynamic execution of extracted malware samples. Learners characterise malware behaviour without compromising the investigation environment.
Chapter 6HideHide detailsSee detailsNetwork Forensics and Log Analysis
Network Forensics and Log Analysis
Lesson 1 • Intrusion and Attack Pattern Recognition
Teaches recognition of scanning, exploitation, and lateral movement patterns in network data. Learners map observed traffic to known attack stages.
Lesson 2 • Network Evidence Sources and Collection
Catalogues packet captures, NetFlow, firewall logs, and proxy logs as primary network evidence. Learners identify which sources answer specific investigative questions.
Lesson 3 • Packet Capture Analysis
Covers deep packet inspection, protocol dissection, and stream reassembly techniques. Learners reconstruct sessions and extract transferred files from PCAP evidence.
Lesson 4 • Wireless and VoIP Forensics
Addresses evidence collection and analysis from Wi-Fi and voice-over-IP communications. Learners apply packet analysis skills to wireless and telephony evidence.
Lesson 5 • Log Aggregation and Correlation
Explains normalisation, aggregation, and correlation of logs from multiple network devices. Learners build unified timelines from heterogeneous log sources.
Chapter 7HideHide detailsSee detailsMobile and Cloud Forensics
Mobile and Cloud Forensics
Lesson 1 • Cloud Storage and Collaboration Forensics
Covers artefact recovery from cloud storage, email, and collaboration platforms. Learners use API access and local sync artefacts to reconstruct cloud activity.
Lesson 2 • IoT and Wearable Device Forensics
Introduces evidence sources from smart home devices, wearables, and connected vehicles. Learners identify and collect IoT artefacts relevant to investigations.
Lesson 3 • Mobile Operating System Internals
Examines iOS and Android file system layouts, data partitions, and app storage models. Learners navigate mobile storage structures to locate forensic artefacts.
Lesson 4 • Mobile Application Artifact Analysis
Targets SQLite databases, plist files, and cached data within mobile applications. Learners extract communication, location, and activity artefacts from app data.
Lesson 5 • Cross-Platform Evidence Correlation
Integrates mobile, cloud, and desktop artefacts into a unified investigative picture. Learners resolve conflicts and gaps across platforms to build a coherent timeline.
Chapter 8HideHide detailsSee detailsForensic Reporting and Expert Testimony
Forensic Reporting and Expert Testimony
Lesson 1 • Case Management and Documentation
Establishes systems for managing evidence, notes, and communications throughout a case. Learners apply documentation practices that protect case integrity from start to finish.
Lesson 2 • Timeline and Visualization Techniques
Covers tools and methods for creating visual timelines and evidence maps. Learners produce graphics that clarify complex event sequences for any audience.
Lesson 3 • Preparing for Expert Testimony
Prepares learners for deposition and courtroom testimony as a forensic expert witness. Learners practise explaining methodology and defending findings under cross-examination.
Lesson 4 • Writing for Non-Technical Audiences
Teaches plain-language translation of technical forensic findings for legal and executive readers. Learners rewrite complex findings without sacrificing accuracy.
Lesson 5 • Forensic Report Structure and Standards
Defines required components of a forensic report and professional writing standards. Learners draft reports that meet evidentiary and organisational requirements.
Your valid completion certificate
This course is for you:
IT professional: wants to formalise investigative skills already used on the job.
Cybersecurity analyst: ready to move beyond detection into structured evidence-based investigation.
Law enforcement officer: needs technical depth to handle digital evidence in criminal cases.
Compliance or fraud investigator: handles data disputes and needs defensible forensic methodology.
Career changer: comes from a technical background and is targeting the forensics field.
Computer science learner: building specialised skills to stand out in a competitive job market.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in South Africa?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















