
Introduction to the course, key topics to be covered, and call to action.
Introduction to the section, key topics to be covered, and call to action.
A brief discussion on what digital forensics is and its applications
Discussion on the 4 processes involved in digital forensics investigation
Discussion on the different types of digital evidence and where to locate them in the computer system.
Discussion on where digital forensics seats in cyber security life-cycle
Providing real world scenarios on the application of digital forensics in real threat attacks on organizations.
A demo showing how to acquire data from a windows system. From registry, browsers, logfiles, etc
Discussion on chain custody, and its role in the admissibility of evidence, and the role of forensics analyst in providing expert witnesses in court
Discussion on the need for privacy and ethics in forensics investigation.
Discussion on the international laws and guidelines governing digital evidence
Introduction to the section, key topics to be covered, and call to action.
Discussion on type of acquisition and Image formats.
Discussion on the precaution while handling digital evidence
Discussion the use of write blockers while imaging digital sources of evidence and best practices.
Demonstration on the use of FTK imager
Demonstration on the use of dd in Linux
Demonstration on the application of hash- function in digital evidence management
Discussion on maintain forensics soundness and readiness in the industry
Discussion of the chain of custody and evidence management
Discussion on evidence handling, storage and management.
Introduction to the section, key topics to be covered, and call to action.
Discussion on the different file systems and how evidence can be acquired, and area of interest in the file systems.
Demonstration on timeline analysis and metadata in digital evidence presentation and analysis
Demonstration on the recovery of deleted files and encrypted files.
Discussion on the importance of browser history analysis in digital forensics and time line analysis
Demonstration on the use of prefetch, registry files on windows for digital investigation analysis
Demonstration on the tracking of document opened and USB accessed during forensic investigations
Interpreting windows logs for access control management in digital investigations.
Time line analysis and the usage of autopsy in digital forensics investigation
Discussion on evidence correlation and data sources in digital forensics.
Interpreting network anomalies and suspicious gaps in network logs
The Master Cyber Investigation and Digital Forensics specialisation is designed to provide a comprehensive, practical, and ethically grounded understanding of digital forensics principles, investigative methodologies, and forensic toolkits. This program helps learners understand what digital forensics in cybersecurity is and why digital forensics is important in modern cybersecurity environments.
Through this course, participants will gain expertise in digital forensics analysis, uncovering digital evidence, analysing compromised systems, recovering deleted or hidden data, tracing unauthorised activity and validating the integrity of digital environments. The curriculum follows a structured approach aligned with real-world cybercrime investigations, combining theory with case studies, hands-on labs, and guided forensic exercises.
Learners will build job-ready skills in computer forensics, including file system analysis, memory forensics, disk imaging, log analysis, chain-of-custody documentation, and report building while learning to work with industry-standard forensic tools and frameworks. The specialisation emphasises a holistic understanding of the entire digital investigation lifecycle, from evidence identification and preservation to analysis, interpretation, and legal reporting, thereby mirroring real cybercrime investigation process workflows. You will gain insights into how cybercriminals operate and how digital traces are created and concealed, and how cyber forensic examiners reconstruct events using advanced digital forensic tools with precision, patience, and methodological rigour.
By the end of this program, learners will be prepared to perform professional digital investigations, contribute to incident response, and support cybercrime investigation and digital forensics efforts within organisations. They will also develop the confidence to evaluate forensic findings, communicate technical conclusions clearly, and support decision-making processes during cybersecurity incidents. This specialisation empowers aspiring investigators, IT professionals, and security practitioners with the technical expertise, analytical mindset, and ethical foundation required to navigate the rapidly expanding world of digital forensics while promoting integrity, resilience, and responsible investigative practices across modern digital environments.