Choose your language
Digital forensics and Cybersecurity Course
More than 2 million students worldwide

Digital forensics and Cybersecurity Course

Master the technical and legal skills that define professional digital forensics and cybersecurity investigation. This course takes you from core evidence principles to advanced memory, network, and cloud forensics. You will graduate ready to investigate real incidents, testify as an expert, and protect organisations from evolving threats.

Dedika for businesses

What you will learn:

You will build a complete forensic skill set covering evidence acquisition, disk and file system analysis, memory forensics, and network traffic investigation. You will learn how to set up a compliant forensic lab, maintain chain of custody, and produce court-admissible evidence. The course covers incident response workflows, threat hunting, malware analysis, and cloud forensics. You will also study mobile and IoT device investigation, threat intelligence integration, and penetration testing fundamentals. By the end, you will know how to write professional forensic reports and perform effectively as an expert witness.

How you study in practice Digital forensics and Cybersecurity Course

How you practise Digital forensics and Cybersecurity Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Digital Forensics

  • Lesson 1 • Legal and Ethical Foundations

    Covers admissibility standards, chain of custody, and investigator ethics. Connects legal requirements to every subsequent technical procedure.

  • Lesson 2 • Types of Digital Evidence

    Catalogues volatile, non-volatile, and network-based evidence categories. Prepares learners to recognise evidence types before learning acquisition techniques.

  • Lesson 3 • The Forensic Investigation Process

    Presents the standard phases: identification, preservation, collection, analysis, and reporting. Learners map each phase to real-world investigative tasks.

  • Lesson 4 • Introduction to Digital Forensics

    Defines digital forensics, its scope, and its role in legal and corporate investigations. Grounds learners in the discipline before any technical content.

  • Lesson 5 • Forensic Lab Setup and Standards

    Describes hardware, software, and procedural requirements for a compliant forensic lab. Learners understand the environment in which all subsequent work occurs.

Chapter 2See details

Cybersecurity Fundamentals for Investigators

  • Lesson 1 • Security Controls and Their Forensic Relevance

    Reviews firewalls, IDS/IPS, SIEM, and access controls as sources of forensic artefacts. Learners learn to query security tools for evidence.

  • Lesson 2 • Cryptography Essentials

    Introduces hashing, symmetric and asymmetric encryption, and PKI as they apply to evidence integrity and encrypted data challenges.

  • Lesson 3 • Networking Concepts for Forensics

    Covers TCP/IP, DNS, DHCP, and packet structure as they relate to evidence interpretation. Provides the network literacy required for later traffic analysis chapters.

  • Lesson 4 • Operating System Internals

    Examines Windows, Linux, and macOS artefacts relevant to forensic analysis. Learners learn where the OS stores evidence before performing disk analysis.

  • Lesson 5 • Threat Actors and Attack Taxonomy

    Classifies threat actors, motives, and common attack categories to frame investigative hypotheses. Directly supports the incident response chapters that follow.

Chapter 3See details

Evidence Acquisition and Preservation

  • Lesson 1 • Hashing and Evidence Integrity

    Demonstrates MD5, SHA-1, and SHA-256 verification workflows to prove evidence has not been altered. Ties integrity verification to chain of custody documentation.

  • Lesson 2 • Live System and Volatile Data Capture

    Addresses RAM capture, running process lists, and network state collection on live systems. Prepares learners for memory forensics in the next chapter.

  • Lesson 3 • Disk Imaging Principles and Tools

    Covers bit-for-bit imaging, image formats, and leading acquisition tools. Establishes the technical baseline for all subsequent disk analysis work.

  • Lesson 4 • Mobile Device Acquisition

    Covers logical, file system, and physical extraction methods for smartphones and tablets. Addresses the unique challenges of mobile evidence preservation.

  • Lesson 5 • Network Traffic Capture

    Teaches packet capture placement, tool configuration, and evidence preservation for network data. Connects to network forensics analysis covered later.

Chapter 4See details

Disk and File System Forensics

  • Lesson 1 • Partition and Volume Analysis

    Analyses MBR, GPT, and volume shadow copies to find hidden or deleted partitions. Expands the scope of disk examination beyond the primary partition.

  • Lesson 2 • File Recovery and Data Carving

    Covers deleted file recovery, slack space analysis, and signature-based carving. Learners apply these techniques to recover evidence from unallocated space.

  • Lesson 3 • File System Structures

    Examines FAT, NTFS, ext4, and APFS structures to locate evidence at the sector level. Understanding structure is prerequisite to recovery and carving techniques.

  • Lesson 4 • Metadata and Timestamp Analysis

    Extracts and interprets file metadata, EXIF data, and MACB timestamps to build event timelines. Directly feeds the timeline analysis section of this chapter.

  • Lesson 5 • Timeline Construction from Disk Artefacts

    Aggregates timestamps from multiple disk sources into a unified event timeline. Learners produce a timeline that supports investigative conclusions.

Chapter 5See details

Memory and Malware Forensics

  • Lesson 1 • Process and DLL Analysis

    Identifies malicious processes, injected DLLs, and hollowed processes within memory images. Core technique for detecting fileless and in-memory malware.

  • Lesson 2 • Malware Identification and Classification

    Applies static and behavioural indicators to classify malware families found in memory. Prepares learners for deeper malware analysis in the next section.

  • Lesson 3 • Network Artefacts in Memory

    Extracts active connections, listening ports, and socket structures from RAM. Connects memory findings to network forensics evidence for corroboration.

  • Lesson 4 • Memory Structure and Acquisition Review

    Reviews RAM layout, virtual address spaces, and acquisition methods before analysis begins. Ensures learners can work with memory images from the previous chapter.

  • Lesson 5 • Malware Analysis Techniques

    Introduces static disassembly, dynamic sandbox execution, and code unpacking for malware samples. Learners produce an analysis report suitable for incident response.

Chapter 6See details

Network Forensics and Log Analysis

  • Lesson 1 • Packet Capture Analysis

    Teaches deep packet inspection, stream reassembly, and protocol decoding using capture files. Builds on acquisition skills to produce actionable network evidence.

  • Lesson 2 • Flow Data and NetFlow Analysis

    Uses flow records to identify anomalous traffic patterns and data exfiltration without full packet data. Complements full packet analysis for high-volume environments.

  • Lesson 3 • Intrusion Detection and Attribution

    Applies network evidence to confirm intrusion, identify lateral movement, and support attribution. Culminates network forensics skills into a complete investigation narrative.

  • Lesson 4 • System and Security Log Correlation

    Correlates Windows event logs, syslog, and firewall logs to build a cross-source attack timeline. Integrates with SIEM concepts introduced in Chapter 2.

  • Lesson 5 • Web and Application Log Analysis

    Parses web server, application, and proxy logs to reconstruct attacker web activity. Directly supports investigation of web-based attack vectors.

Chapter 7See details

Incident Response and Threat Hunting

  • Lesson 1 • Incident Response Lifecycle

    Maps the preparation, detection, containment, eradication, recovery, and lessons-learned phases to forensic tasks. Provides the operational framework for this chapter.

  • Lesson 2 • Post-Incident Analysis and Lessons Learned

    Structures root cause analysis, gap identification, and control improvement after an incident. Closes the IR lifecycle and feeds improvements back into security posture.

  • Lesson 3 • Containment and Eradication Strategies

    Examines network isolation, account disabling, and malware removal while preserving evidence. Balances operational recovery needs with forensic integrity requirements.

  • Lesson 4 • Triage and Rapid Assessment

    Covers rapid host triage, artefact prioritisation, and scope determination under time pressure. Enables investigators to make fast, evidence-based containment decisions.

  • Lesson 5 • Threat Hunting Fundamentals

    Introduces hypothesis-driven hunting using TTPs, threat intelligence, and behavioural analytics. Extends reactive IR skills into proactive detection capability.

Chapter 8See details

Forensic Reporting and Expert Testimony

  • Lesson 1 • Writing for Technical and Legal Audiences

    Adapts forensic findings for attorneys, executives, and technical peers without sacrificing accuracy. Develops the communication versatility investigators need in practice.

  • Lesson 2 • Expert Witness Preparation

    Prepares learners for deposition, direct examination, and cross-examination as a forensic expert. Addresses the unique pressures of testifying in adversarial proceedings.

  • Lesson 3 • Case File Management and Archiving

    Establishes procedures for organising, securing, and archiving complete case files for future reference. Ensures long-term defensibility of investigative work product.

  • Lesson 4 • Forensic Report Structure and Standards

    Defines required report sections, objectivity standards, and documentation best practices. Establishes the reporting framework used throughout the final project.

  • Lesson 5 • Evidence Presentation and Visualisation

    Covers timeline charts, network diagrams, and artefact maps that make complex evidence accessible. Directly supports both written reports and courtroom presentations.

Certification

Your valid completion certificate

This course is for you:

  • IT Administrator: wants to formalise incident handling skills with investigative rigor.

  • Career Changer: brings analytical thinking and is ready to enter cybersecurity professionally.

  • Security Analyst: needs deeper forensic methodology to support escalated threat investigations.

  • Law Enforcement Officer: handles digital evidence and wants stronger technical examination skills.

  • Compliance Professional: must understand how digital investigations protect organisational liability.

  • Computer Science Graduate: seeks a specialised, career-defining edge in the security job market.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQ

Who is Dedika?

Is the certificate valid in South Africa?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course