
Discover the essentials of digital forensics, from identifying types and functions to defining investigation goals, using professional tools, preservative hashing, and producing an admissible evidence report.
Explore the history and core practices of digital forensics, including preservation, identification, extraction, and reporting. Learn about admissible evidence, acquisition of hidden files, and the tools for Windows and Linux/Android.
Explore digital forensics and threat intelligence by learning techniques used in Windows and Linux forensics, with guidance for work with law enforcement and related organizations.
Master the core process of computer and digital forensics—collecting, preserving, analyzing, and reporting data to produce admissible digital evidence across devices and networks.
Examine data, acquire and collect evidence, preserve it using forensic methods; authenticate each item and maintain chain of custody throughout analysis and presentation to the authority.
Preserve digital evidence by performing a bit-by-bit copy to keep it authentic, prevent changes or copying, and verify integrity using cryptographic hashes that produce identical values for the same data.
Explore the two system shutdown states—forceful and graceful—and their forensic implications, including potential data loss, logged-in user information, network information, IP addresses, and connected devices.
Practice using the investigation and forensics toolkit to create logical drive images, copy evidence bit by bit, manage evidence trees, and analyze RAM processes for export.
Explore SleuthKit and Autopsy for forensic analysis of digital evidence, including browser history and deleted files. Create cases, configure sources from logical or physical drives, and generate reports.
Learn how live acquisition and incident response collect digital evidence from running systems, explore tools like Helix, EnCase, and Case Forensic, and perform memory and drive acquisitions with guided workflows.
Explore the forensics toolkit 2 workflow by capturing and saving memory images for investigation, handling encrypted files with decryption options, and examining the file system with a hex viewer.
#Computer Forensics is the branch of forensics science which deals with the digital evidences that would be admissible in court. The field of digital forensics started early 90's when digital computer compromised. FBI CART program which was previously known as "Magnet Media Program" and the father of Computer Forensics Michael Anderson was the chief head of this program. Through blessings of Computer forensics the cases of Michael Jackson, German wings Flight 9525 etc. solved. IN this course you will learn about general forensics procedures, evidence handling and you will know how to use various tools which will help you to become an expert with more practice. The main objective of this course is that I just brief all lectures clearly which is understandable for everyone. There’s no need for computer/forensics' background to enroll this course if you have interest then you may get this course. This course is also helpful for cyber lawyers or prosecutors because gathering and preserving electronic evidence require a special set of considerations. Without a thorough understanding of digital forensics, your next move could compromise evidence or cause your findings to be inadmissible in court.
Shortly this course provides a general introduction to the concepts, theories, principles, and practice of digital forensics. Topics include data acquisition to reporting with lab sessions. Therefore, it also covers the required basics of Unix/Linux commands.
Learning Outcomes:
Step to CHFI From EC-Council
Procedural Professional in disaster management
Exploring in the field of threat intelligence
Data recovery using professional tools
Mitigation of admissibility
Windows/Linux/mobile forensics
Prepare yourself for GCFA
Preparing reports#
--------------------------------------