
Digital forensics Course
Master the full digital forensics workflow, from lab setup and evidence acquisition to malware analysis and expert testimony. This course covers Windows, Linux, macOS, cloud, and mobile environments using industry-standard tools and legally defensible methods. Build the technical depth and professional credibility that employers and courts demand.
What you will learn:
You will learn how to acquire and preserve digital evidence from hard drives, mobile devices, memory, and cloud infrastructure without compromising its integrity. The course covers file system internals, Windows registry forensics, network packet analysis, and memory forensics using structured, repeatable methodologies. You will analyse malware behaviour through both static and dynamic techniques and correlate artefacts across disk, memory, and network sources to build complete incident timelines. Supplementary modules extend your skills to Linux, macOS, IoT devices, blockchain investigations, and OSINT attribution. By the end, you will write professional forensic reports and be prepared to present findings as an expert witness.
How you study in practice Digital forensics Course
How you practise Digital forensics Course
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Digital Forensics
Foundations of Digital Forensics
Lesson 1 • Types of Digital Evidence
Surveys volatile, non-volatile, and network-based evidence categories. Prepares learners to recognise evidence sources before acquisition begins.
Lesson 2 • The Forensic Investigation Process
Introduces the standard phases: identification, preservation, analysis, and reporting. Provides the procedural backbone applied throughout the entire course.
Lesson 3 • Legal and Ethical Foundations
Examines admissibility standards, chain of custody, and investigator ethics. Ensures every technical action taken later meets evidentiary requirements.
Lesson 4 • Defining Digital Forensics
Covers the discipline's definition, history, and relationship to cybersecurity and law. Anchors all subsequent technical work in a clear professional framework.
Lesson 5 • Setting Up a Forensic Lab
Details hardware, software, and environmental requirements for a defensible forensic workspace. Learners can configure a basic lab ready for hands-on exercises.
Chapter 2HideHide detailsSee detailsEvidence Acquisition and Preservation
Evidence Acquisition and Preservation
Lesson 1 • Principles of Forensic Imaging
Explains bit-for-bit copying, hashing, and verification to ensure image integrity. Establishes the technical standard all acquisition tasks must meet.
Lesson 2 • Cloud and Remote Evidence Acquisition
Explores legal holds, API-based collection, and provider cooperation for cloud data. Prepares learners for evidence sources that lack physical media.
Lesson 3 • Live System and Memory Acquisition
Teaches volatile data capture from running systems before shutdown destroys evidence. Connects directly to later memory analysis techniques.
Lesson 4 • Mobile Device Acquisition
Addresses logical, file-system, and physical extraction methods for smartphones and tablets. Highlights platform-specific challenges that affect evidence completeness.
Lesson 5 • Acquiring Data from Storage Media
Covers disk, SSD, USB, and optical media acquisition workflows. Learners practise imaging each media type using industry-standard tools.
Chapter 3HideHide detailsSee detailsFile Systems and Storage Analysis
File Systems and Storage Analysis
Lesson 1 • Anti-Forensic Techniques and Detection
Identifies methods used to hide, destroy, or obfuscate evidence at the storage level. Learners learn to detect and counter these techniques during analysis.
Lesson 2 • Deleted File Recovery
Demonstrates how deletion works at the file system level and how data persists. Learners apply carving and metadata techniques to recover deleted content.
Lesson 3 • File System Fundamentals
Explains partition tables, volume structures, and common file system types. Provides the structural knowledge needed to navigate forensic images accurately.
Lesson 4 • NTFS Forensic Artefacts
Examines MFT records, journal files, and alternate data streams unique to NTFS. These artefacts reveal file history and anti-forensic attempts on Windows systems.
Lesson 5 • Database and Email Storage Analysis
Covers SQLite, PST, and OST formats commonly found on user devices. Learners extract and interpret records from application-level storage containers.
Chapter 4HideHide detailsSee detailsWindows Forensic Analysis
Windows Forensic Analysis
Lesson 1 • Browser and Internet Artefacts
Extracts history, cache, cookies, and download records from major browsers. Connects web activity to user intent and potential data exfiltration.
Lesson 2 • Windows Timeline and Activity Cache
Analyses the ActivitiesCache database and Windows Timeline for recent user actions. Provides a chronological view of document access and application use.
Lesson 3 • Windows Registry Forensics
Maps registry hive structure and identifies keys that record user and system activity. Registry analysis underpins most Windows artefact investigations.
Lesson 4 • Windows Event Log Analysis
Teaches parsing of Security, System, and Application logs to reconstruct events. Learners correlate log entries to build timelines of attacker or user behaviour.
Lesson 5 • Program Execution Artefacts
Identifies Prefetch, Shimcache, Amcache, and BAM records that prove program execution. These artefacts are critical for malware investigations and user activity reconstruction.
Chapter 5HideHide detailsSee detailsMemory Forensics
Memory Forensics
Lesson 1 • Network Connections in Memory
Extracts active and recently closed network connections from memory structures. Links processes to external communications for threat attribution.
Lesson 2 • Memory Acquisition Methods
Reviews tools and techniques for capturing RAM from live and hibernated systems. Addresses acquisition fidelity issues that affect downstream analysis accuracy.
Lesson 3 • Memory Architecture and Structures
Explains virtual address spaces, kernel structures, and process memory layout. This foundation is required to interpret memory analysis tool output correctly.
Lesson 4 • Malware and Rootkit Detection in Memory
Applies DKOM detection, hook analysis, and YARA scanning to identify advanced threats. Learners produce memory-based indicators of compromise for incident response.
Lesson 5 • Process and DLL Analysis
Identifies running processes, loaded modules, and injected code within memory images. Detects malware hiding through process hollowing and DLL injection.
Chapter 6HideHide detailsSee detailsNetwork Forensics
Network Forensics
Lesson 1 • Intrusion and Exfiltration Detection
Identifies attack patterns, lateral movement, and data exfiltration in network evidence. Learners apply traffic baselining and anomaly detection to real-world scenarios.
Lesson 2 • Log-Based Network Investigation
Analyses firewall, proxy, DNS, and DHCP logs to trace host activity and connections. Complements packet analysis when full captures are unavailable.
Lesson 3 • Packet Capture and Analysis
Teaches filtering, stream reassembly, and protocol dissection using capture analysis tools. Learners reconstruct sessions and extract transferred files from packet data.
Lesson 4 • Wireless Network Forensics
Covers 802.11 frame analysis, rogue access point detection, and wireless log review. Extends network forensics skills to environments where wired captures are unavailable.
Lesson 5 • Network Evidence Fundamentals
Reviews TCP/IP stack, protocols, and traffic capture points relevant to forensic investigation. Establishes the networking knowledge required for all subsequent packet analysis.
Chapter 7HideHide detailsSee detailsMalware Forensics and Incident Response
Malware Forensics and Incident Response
Lesson 1 • Incident Timeline Construction
Correlates artefacts from disk, memory, and network to build a unified attack timeline. Timeline accuracy directly determines the quality of the final forensic report.
Lesson 2 • Dynamic Malware Analysis
Executes malware in isolated sandboxes and monitors system and network behaviour. Produces behavioural indicators that complement static findings.
Lesson 3 • Static Malware Analysis
Applies file hashing, string extraction, and PE header analysis to suspicious files. Learners identify indicators of compromise without executing malware.
Lesson 4 • Malware Classification and Behaviour
Categorises malware families and describes their forensic footprints on host and network. Provides the threat context needed to guide targeted artefact collection.
Lesson 5 • Containment and Remediation Guidance
Translates forensic findings into actionable containment steps and remediation priorities. Bridges the gap between investigation and operational security response.
Chapter 8HideHide detailsSee detailsForensic Reporting and Expert Testimony
Forensic Reporting and Expert Testimony
Lesson 1 • Technical Writing for Forensics
Develops precise, jargon-controlled writing that conveys complex findings to varied audiences. Clarity in writing directly affects how evidence is understood by decision-makers.
Lesson 2 • Expert Witness Preparation
Prepares learners to qualify as expert witnesses and present findings under examination. Covers deposition, direct examination, and cross-examination strategies.
Lesson 3 • Case Study: End-to-End Report Production
Applies all reporting skills to a realistic scenario from evidence receipt to final report. Learners receive structured feedback to reach professional reporting standards.
Lesson 4 • Forensic Report Structure and Standards
Defines required report sections, objectivity standards, and documentation best practices. A well-structured report is the primary deliverable of every forensic engagement.
Lesson 5 • Chain of Custody Documentation
Formalises evidence handling records from acquisition through presentation. Gaps in custody documentation can invalidate otherwise sound forensic work.
Your valid completion certificate
This course is for you:
IT support technician: ready to specialise in investigations and evidence handling.
Cybersecurity analyst: wanting to add forensic investigation depth to incident response skills.
Law enforcement officer: seeking technical skills to handle digital evidence independently.
Computer science graduate: looking to enter the forensics or cybersecurity job market confidently.
Corporate compliance professional: needing to understand how digital investigations protect organisations.
Career changer: drawn to investigative work and comfortable learning technical tools from scratch.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in South Africa?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















