Digital Forensics Essentials
Acquire the evidence, reconstruct the timeline, and prove what happened.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
9 hours
Estimated time
What you will be able to do
- You will be able to explain what makes digital evidence forensically sound and admissible, and apply that standard from the first moment you touch a system.
- You will be able to maintain a defensible chain of custody, verify evidence integrity with cryptographic hashes, and use write-blockers so the original data is never altered.
- You will be able to apply the order of volatility to decide what to collect first, and capture volatile data such as random-access memory (RAM) before it is lost.
- You will be able to create and verify a bit-for-bit forensic image of a disk in standard formats such as raw (dd) and the Expert Witness Format (E01).
- You will be able to analyze a memory image to surface running processes, network connections, and signs of code injection or credential theft.
- You will be able to examine a disk to recover deleted files, carve data from unallocated space, and read the file-system metadata that records file activity.
- You will be able to interpret operating-system artifacts, such as system logs, the Windows Registry, and program-execution records, to establish who did what and when.
- You will be able to reconstruct a unified timeline from multiple evidence sources and write a clear, defensible forensic report of your findings.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Forensic Foundations and Evidence Handling
Great forensics starts before you analyze anything: it starts with how you think about evidence and how you handle it. This module sets the ground rules of the field, from forensic soundness and courtroom admissibility to the Digital Forensics and Incident Response (DFIR) analyst's role during a live incident. You will learn to protect evidence integrity and keep a chain of custody that makes every later finding trustworthy.
2 lessons · 5 quiz questions
- 02
Acquiring Digital Evidence
Evidence collected the wrong way can be worthless, so acquisition is a discipline of its own. This module teaches the order of volatility, so you know to capture fleeting data such as memory before you ever image a disk. You will then learn to create and verify a bit-for-bit forensic image that is a provable, exact copy of the original.
2 lessons · 5 quiz questions · assignment
- 03
Analyzing Memory and Disk
With a sound copy in hand, the investigation begins. This module opens the two richest sources of evidence: a captured memory image and the disk itself. You will learn to read memory for running programs and attacker activity, then examine the disk to recover deleted files and understand how the file system stores and tracks data.
2 lessons · 5 quiz questions
- 04
Artifacts, Timelines, and Reporting
Individual files rarely tell the whole story; the story lives in the artifacts an operating system leaves behind and in the order events occurred. This module shows how to read file-system and operating-system artifacts, then weave them into a single timeline that reveals what happened step by step. You will finish by writing a clear, defensible report that turns your analysis into evidence others can act on.
2 lessons · 5 quiz questions · assignment