Digital forensics is the process of identifying, collecting, preserving, analysing and presenting digital evidence from computers, mobile devices, networks and storage systems, in order to investigate cyber incidents, security breaches and cybercrime.
This two-day course covers that process end to end: how evidence is acquired without being altered, how an incident is investigated and analysed, what makes evidence admissible in court, and how findings are reported. It follows the best practice set out in ISO/IEC 27037 and includes hands-on sessions with digital forensic tools.
Course Objectives
Curriculum
The Forensic Process
Locating the systems, devices and data that hold relevant evidence.
Capturing evidence so that its integrity holds up to later challenge.
Working through the artefacts with forensic tools to establish what happened.
Ordering events into a sequence that explains the incident.
The handling and documentation that keep evidence usable in court.
Presenting findings clearly, including as an expert.
ISO/IEC 27037: the international standard for the identification, collection, acquisition and preservation of digital evidence. The course works to its best practices throughout, which is what separates a defensible investigation from one that collapses under challenge.
Who Should Attend
Before You Begin
Note: this is a hands-on technical programme. Participants who are comfortable at a command line and with file systems will get considerably more from the practical sessions.
Course Details
A two-day programme available as a virtual session, a public classroom batch or an in-house delivery at your own site.
Practical forensic exercises, hands-on demonstrations with digital forensic tools, investigation scenarios, evidence analysis activities and real-world cyber incident case studies.
Why Choose Us
Chosen by security teams, enterprises and law enforcement professionals.
Time spent working with forensic tools, not only hearing about them.
Built on ISO/IEC 27037 rather than ad hoc practice.
Real-world cyber incident scenarios throughout.
Part of the Quality Austria group network with international reach.
FAQ
The Digital Forensics Training Course is designed to help professionals understand cyber forensic investigation techniques, digital evidence handling, incident analysis and forensic reporting used in cybersecurity investigations and cybercrime response activities.
This course is suitable for IT professionals, cybersecurity practitioners, incident response teams, law enforcement personnel, software developers and employees involved in handling digital systems, cyber investigations or information security operations.
The training covers digital evidence acquisition, cyber incident investigation, forensic analysis, evidence preservation, reporting procedures, ISO 27037 best practices, forensic tools and technologies and hands-on practical forensic investigation exercises.
Digital forensics is the process of identifying, collecting, preserving, analysing and presenting digital evidence from computers, mobile devices, networks or digital storage systems to investigate cyber incidents, security breaches and cybercrimes.
Digital forensics helps organisations investigate cybersecurity incidents, identify attack sources, preserve legal evidence, support regulatory compliance, strengthen incident response capabilities and reduce the impact of cyber threats and data breaches.
Yes, the course includes practical forensic exercises, hands-on demonstrations with digital forensic tools, investigation scenarios, evidence analysis activities and real-world cyber incident case studies.
Participants are recommended to have basic knowledge of cybersecurity concepts, Windows and Linux operating systems, networking fundamentals, computer architecture and scripting concepts for better understanding of forensic investigation techniques.
Talk to our team about the next available batch or in-house delivery for your organisation.