Cybersecurity · Beginner → Expert
🔎 Digital Forensics and Incident Response
Perform defensible incident response and forensic analysis across endpoints, disks, memory, logs, networks and cloud evidence while preserving chain of custody.
Course roadmap
Pass each module exam to unlock the next module.
Module 1 · Beginner
Incident Response Lifecycle and Forensic Readiness
Locked
Module 2 · Beginner
Evidence Handling, Integrity and Chain of Custody
Locked
Module 3 · Beginner
Disk, Filesystem and Artifact Fundamentals
Locked
Module 4 · Beginner
Windows Forensic Artifacts
Locked
Module 5 · Intermediate
Linux Forensic Artifacts
Locked
Module 6 · Intermediate
Memory Forensics Concepts
Locked
Module 7 · Intermediate
Browser, Email and User Activity Artifacts
Locked
Module 8 · Intermediate
Network and Packet Evidence
Locked
Module 9 · Advanced
Log Timeline Construction and Event Correlation
Locked
Module 10 · Advanced
Malware Triage and Static Analysis Safety
Locked
Module 11 · Advanced
Cloud and SaaS Incident Evidence
Locked
Module 12 · Advanced
Acquisition, Imaging and Preservation
Locked
Module 13 · Expert
Containment, Eradication and Recovery Decisions
Locked
Module 14 · Expert
Forensic Reporting and Expert Communication
Locked
Module 15 · Expert
Legal, Privacy and Organizational Boundaries
Locked
Module 16 · Expert
Expert Capstone: End-to-End Incident Investigation
Locked
Certification gate
Final course exam
Pass mark: 80%. Time limit: 360 minutes. All module exams must be passed first.
Locked until modules are passed