BBuddyAI Learn
Cybersecurity · Beginner → Expert

🔎 Digital Forensics and Incident Response

Perform defensible incident response and forensic analysis across endpoints, disks, memory, logs, networks and cloud evidence while preserving chain of custody.

Course roadmap

Pass each module exam to unlock the next module.

Module 1 · Beginner

Incident Response Lifecycle and Forensic Readiness

Locked
Module 2 · Beginner

Evidence Handling, Integrity and Chain of Custody

Locked
Module 3 · Beginner

Disk, Filesystem and Artifact Fundamentals

Locked
Module 4 · Beginner

Windows Forensic Artifacts

Locked
Module 5 · Intermediate

Linux Forensic Artifacts

Locked
Module 6 · Intermediate

Memory Forensics Concepts

Locked
Module 7 · Intermediate

Browser, Email and User Activity Artifacts

Locked
Module 8 · Intermediate

Network and Packet Evidence

Locked
Module 9 · Advanced

Log Timeline Construction and Event Correlation

Locked
Module 10 · Advanced

Malware Triage and Static Analysis Safety

Locked
Module 11 · Advanced

Cloud and SaaS Incident Evidence

Locked
Module 12 · Advanced

Acquisition, Imaging and Preservation

Locked
Module 13 · Expert

Containment, Eradication and Recovery Decisions

Locked
Module 14 · Expert

Forensic Reporting and Expert Communication

Locked
Module 15 · Expert

Legal, Privacy and Organizational Boundaries

Locked
Module 16 · Expert

Expert Capstone: End-to-End Incident Investigation

Locked
Certification gate

Final course exam

Pass mark: 80%. Time limit: 360 minutes. All module exams must be passed first.

Locked until modules are passed