Get in Touch
 Duration 35 hours

Course Outline

Computer forensics allows for the systematic and meticulous identification of evidence in cases involving computer-related crime and abuse. This scope covers a wide range of activities, from tracking a hacker’s movements through a client’s systems to identifying the source of defamatory emails or uncovering signs of fraud.

Module 1: Introduction

Module 2: Computer Forensic Incidents

Module 3: Investigation Process

Module 4: Disk Storage Concepts

Module 5: Digital Acquisition & Analysis

Module 6: Forensic Examination Protocols

Module 7: Digital Evidence Protocols

Module 8: CFI Theory

Module 9: Digital Evidence Presentation

Module 10: Computer Forensic Laboratory Protocols

Module 11: Computer Forensic Processing Techniques

Module 12: Digital Forensics Reporting

Module 13: Specialized Artifact Recovery

Module 14: e-Discovery and ESI

Module 15: Mobile Device Forensics

Module 16: USB Forensics

Module 17: Incident Handling

Mile2 - Lab 1: Preparing Forensic Workstation

  • Installing AccessData FTK Imager
  • Installing Autopsy
  • Using the National Software Reference Library (NSRL) for Autopsy
  • Installing 7z
  • Installing Registry Viewer
  • Installing the Password Recovery Tool Kit (PRTK - 5.21)

Lab 2: Chain of Custody

  • Chain of Custody Search and Seizure
  • Chain of Custody Forensic Imaging

Lab 3: Imaging Case Evidence via FTK Imager

Lab 4: Initiating a New Case in Autopsy

  • Setting Up a Case in Autopsy

Lab 5: Analyzing Evidence in Autopsy (Case #1)

  • Investigating User MTBG’s attempt to hack a former employer
  • Examining Evidence within Autopsy

Case Study Scenario:

  • Identifying the required evidence (Challenge)

Final Report for the MTBG Case

Lab 6: Analyzing Evidence in Autopsy (Case #2)

  • The Greg Schardt case

Case Study Scenario:

  • Identifying the required evidence (Challenge)

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories