Skip to main content
BEGINNER TO INTERMEDIATE
12 WEEKS
19 MODULES

Digital Forensics

Reconstruct what happened, in a way that holds up

Forensics is not about tools recovering deleted files. It is about building a defensible account of events from fragmentary evidence, and being able to show your working. This course follows the real investigative process from acquisition through to a report that would survive scrutiny: hash-verified imaging, chain of custody, artifact correlation across disk and memory, and timeline reconstruction. Cases are drawn from public datasets so the work is realistic rather than contrived.

Instructor credential: I teach Digital Forensics at FAST-NUCES and hold advanced DFIR credentials from Belkasoft, including Windows, iOS, and YARA-based investigation training.

📦
19
Modules
12
weeks
📋
12
Units
🎯
48
Topics

👤Who this is for

  • Analysts moving into DFIR from a general IT or SOC background
  • Students who want investigative skills alongside offensive ones
  • Incident responders who need structure behind their triage
  • Anyone who has to produce evidence that will be read by non-technical people

Prerequisites

Familiarity with Windows file systems and the registry
Basic networking knowledge
No prior forensics experience required

Curriculum

12 units · 48 topics · 12 weeks

UNIT 01

Foundations of digital forensics

Forensic principles and legal context
Types of digital evidence
The investigative process lifecycle
Forensic workstation setup
UNIT 02

Evidence acquisition and integrity

Forensically sound imaging with FTK Imager
Hash verification (MD5, SHA-256)
Chain of custody documentation
Write blocking and evidence handling
UNIT 03

File system analysis

NTFS internals and MFT analysis
FAT32 and exFAT structures
Deleted file recovery techniques
File carving and slack space analysis
UNIT 04

Windows artifact analysis

Registry forensics (SAM, SYSTEM, SOFTWARE)
Event log analysis and correlation
Prefetch, Amcache, and ShimCache
LNK files, jump lists, and shellbags
UNIT 05

Browser and email forensics

Chrome, Firefox, and Edge artifacts
Browser history, cookies, and cached data
Email header analysis
Webmail and cloud artifact recovery
UNIT 06

Memory forensics fundamentals

Memory acquisition techniques
Volatility 3 framework and plugins
Process and DLL analysis in memory
Detecting code injection in memory dumps
UNIT 07

Advanced memory forensics

Recovering credentials from memory
Network connection reconstruction
Malware indicators in volatile memory
Timeline correlation with disk artifacts
UNIT 08

Network forensics

PCAP capture and analysis with Wireshark
Protocol reconstruction and stream following
Identifying data exfiltration patterns
DNS tunnelling and C2 traffic detection
UNIT 09

Mobile forensics

Android acquisition basics
SQLite database examination
Application data extraction and analysis
Mobile artifact interpretation
UNIT 10

Timeline reconstruction

Super timeline creation with Plaso
Cross-source event correlation
Identifying anti-forensic techniques
Building a defensible timeline narrative
UNIT 11

Casework and investigation

Multi-source case studies from public datasets
NIST CFREDS and Digital Corpora scenarios
Hypothesis-driven investigation methodology
Handling ambiguous and contradictory evidence
UNIT 12

Professional reporting

Writing for legal and executive audiences
Structuring findings for court admissibility
Presenting findings under challenge
Report templates and documentation standards

What you will be able to do

1Acquire and verify evidence without compromising its integrity
2Investigate real disk, memory, and network evidence
3Reconstruct a defensible attack or activity timeline
4Write investigative reports suitable for legal and executive readers

🛠 Tools you will use

AutopsyThe Sleuth KitFTK ImagerVolatility 3WiresharkMagnet AXIOMPlaso

🏆 Certification pathways

This course builds directly toward:

GCFECCEBelkasoft credentials

Frequently asked questions

Do I need a forensics background to start?

No. The course begins with acquisition fundamentals and evidence handling. You need familiarity with Windows file systems and the registry, plus basic networking, but no prior investigative experience is assumed.

What cases do we actually work on?

Public forensic datasets including Digital Corpora scenarios and NIST CFREDS challenges. These are full realistic disk images with genuine artifacts rather than sanitised exercises, so the investigative work and the ambiguity you have to resolve are both real.

Does this cover incident response as well as forensics?

It covers the forensic half thoroughly and the response half at a working level. You learn triage, acquisition, analysis and reporting. Full IR programme design, containment strategy, and organisational response planning are broader disciplines that sit outside this syllabus.

What tools and hardware do I need?

A machine with at least 16 GB RAM to run forensic VMs and process disk images. All software used is either free or has educational licences available. FTK Imager, Autopsy, Volatility 3, and Wireshark are the primary tools and all are free to download.

Are the skills applicable to legal proceedings?

Yes. The course teaches chain-of-custody documentation, write-blocked acquisition, hash verification, and report writing that meets evidentiary standards. While courtroom testimony preparation is outside the syllabus, the technical procedures follow forensic best practices accepted in legal contexts.

Is this course available online or in person?

Both options are available. Online delivery uses live sessions with screen sharing for guided walkthroughs of forensic images. In-person delivery is available in Islamabad and can be arranged for corporate teams at your location. Contact directly to discuss format and scheduling.

Interested in this training?

Reach out to discuss scheduling, format, and pricing. Corporate and group rates available.

Get in touch →View all courses

Other courses