BEGINNER TO INTERMEDIATE
⏱ 12 WEEKS
19 MODULES
Digital Forensics
Reconstruct what happened, in a way that holds up
Forensics is not about tools recovering deleted files. It is about building a defensible account of events from fragmentary evidence, and being able to show your working. This course follows the real investigative process from acquisition through to a report that would survive scrutiny: hash-verified imaging, chain of custody, artifact correlation across disk and memory, and timeline reconstruction. Cases are drawn from public datasets so the work is realistic rather than contrived.
✓
Instructor credential: I teach Digital Forensics at FAST-NUCES and hold advanced DFIR credentials from Belkasoft, including Windows, iOS, and YARA-based investigation training.
👤Who this is for
- →Analysts moving into DFIR from a general IT or SOC background
- →Students who want investigative skills alongside offensive ones
- →Incident responders who need structure behind their triage
- →Anyone who has to produce evidence that will be read by non-technical people
⚡Prerequisites
•Familiarity with Windows file systems and the registry
•Basic networking knowledge
•No prior forensics experience required
Curriculum
12 units · 48 topics · 12 weeks
UNIT 01
Foundations of digital forensics
✦Forensic principles and legal context
✦Types of digital evidence
✦The investigative process lifecycle
✦Forensic workstation setup
UNIT 02
Evidence acquisition and integrity
✦Forensically sound imaging with FTK Imager
✦Hash verification (MD5, SHA-256)
✦Chain of custody documentation
✦Write blocking and evidence handling
UNIT 03
File system analysis
✦NTFS internals and MFT analysis
✦FAT32 and exFAT structures
✦Deleted file recovery techniques
✦File carving and slack space analysis
UNIT 04
Windows artifact analysis
✦Registry forensics (SAM, SYSTEM, SOFTWARE)
✦Event log analysis and correlation
✦Prefetch, Amcache, and ShimCache
✦LNK files, jump lists, and shellbags
UNIT 05
Browser and email forensics
✦Chrome, Firefox, and Edge artifacts
✦Browser history, cookies, and cached data
✦Email header analysis
✦Webmail and cloud artifact recovery
UNIT 06
Memory forensics fundamentals
✦Memory acquisition techniques
✦Volatility 3 framework and plugins
✦Process and DLL analysis in memory
✦Detecting code injection in memory dumps
UNIT 07
Advanced memory forensics
✦Recovering credentials from memory
✦Network connection reconstruction
✦Malware indicators in volatile memory
✦Timeline correlation with disk artifacts
UNIT 08
Network forensics
✦PCAP capture and analysis with Wireshark
✦Protocol reconstruction and stream following
✦Identifying data exfiltration patterns
✦DNS tunnelling and C2 traffic detection
UNIT 09
Mobile forensics
✦Android acquisition basics
✦SQLite database examination
✦Application data extraction and analysis
✦Mobile artifact interpretation
UNIT 10
Timeline reconstruction
✦Super timeline creation with Plaso
✦Cross-source event correlation
✦Identifying anti-forensic techniques
✦Building a defensible timeline narrative
UNIT 11
Casework and investigation
✦Multi-source case studies from public datasets
✦NIST CFREDS and Digital Corpora scenarios
✦Hypothesis-driven investigation methodology
✦Handling ambiguous and contradictory evidence
UNIT 12
Professional reporting
✦Writing for legal and executive audiences
✦Structuring findings for court admissibility
✦Presenting findings under challenge
✦Report templates and documentation standards