Skip to content
normSight — Cyber Security

Defensive Trainings

Digital Forensics

The Digital Forensics (DFP) course builds the ability to collect and analyse evidence from disk, memory and network data after an incident, and to produce a legally defensible report.

Digital Forensics Professional

  • Study at Your Own Pace

DFP offers lifetime access to course materials and convenient access to the world’s best Digital Forensics virtual labs: Hera Lab.

Highly Practical

Digital Forensics is an interactive course combining core materials and concepts with supplementary video demonstrations, and it gives you the opportunity to apply and test your knowledge through our Hera Lab environment.

The Course at a Glance

  • Learn how to acquire volatile and non-volatile data using a range of techniques
  • Get to grips with file structure, then analyse file headers, malicious documents and file metadata
  • Learn to navigate partitions, recover corrupted disks and locate hidden data
  • Learn how to analyse both FAT and NTFS file systems
  • Get to know file carving and build your own custom carving signatures
  • Learn how to analyse the Windows registry, LNK files, prefetch files and previously connected USB devices
  • Learn to conduct thorough investigations against Skype, Explorer shellbags and the Windows recycle bin
  • Become competent at forensically investigating network attacks

Course Material

  • High-quality video training materials
  • Interactive slides
  • Hands-on tasks in our industry-leading virtual labs

Course Delivery

  • Self-paced / HTML5, PDF, MP4
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

  • Module 1: Introduction to Digital Forensics
  • Module 2: Data Acquisition
  • Module 3: Data Representation and File Examination
  • Module 4: Disks
  • Module 5: File Systems
  • Module 6: Windows Forensics
  • Module 7: Network Forensics
  • Module 8: Log Analysis
  • Module 9: Timeline Analysis
  • Module 10: Reporting

Prerequisites

  • A solid understanding of the fundamentals of modern operating systems
  • Basic knowledge of networks and network protocols, and of programming languages

Who Can Attend

  • Security professionals, forensic investigators and forensic specialists
  • Incident responders and threat hunters
  • Digital forensics instructors and students
  • Red team members looking to refresh their techniques, tactics and procedures

Laboratuvarlar

Integrated with Hera Lab, the most advanced virtual lab in IT security, this product offers an unmatched practical learning experience. Hera is the only virtual lab that provides each student with fully isolated access to every one of the real-world network scenarios available on the platform.

Students can access Hera Lab from anywhere over VPN.

Lab IDDescriptionCategory
Lab 1How to Acquire DataInstructional
Lab 2Acquiring Data Using LinuxInstructional
Lab 3Basic File Header AnalysisInstructional
Lab 4Extracting Metadata from DocumentsInstructional
Lab 5Basic PDF and Word Document AnalysisInstructional
Lab 6Analysing Microsoft Office DocumentsInstructional
Lab 7Recovering a Corrupted Disk – MBR CaseInstructional
Lab 8Recovering a Corrupted Disk – GPT CaseInstructional
Lab 9Finding Hidden Partitions and Partition GapsInstructional
Lab 10Analysing the FAT File SystemInstructional
Lab 11Examining Deleted Files, Formatted Disks and Slack SpaceInstructional
Lab 12Navigating NTFS File System FeaturesInstructional
Lab 13File Carving and Building Custom SignaturesInstructional
Lab 14Windows Registry AnalysisInstructional
Lab 15Analysing Different Windows ArtefactsInstructional
Lab 16USB Forensic AnalysisInstructional
Lab 17Analysing the Windows Recycle BinInstructional
Lab 18Traffic Analysis Using Wireshark – Part 1Instructional
Lab 19Traffic Analysis Using Wireshark – Part 2Instructional
Lab 20Network File CarvingInstructional
Lab 21Examining Network ScansInstructional
Lab 22Investigating Network AttacksInstructional
Lab 23Using the Snort IDSInstructional
Lab 24Analysing SSL/TLS Certificates and TrafficInstructional
Lab 25Log Analysis Using LinuxInstructional

Frequently Asked Questions

What is the difference between forensics and incident response?

Incident response focuses on stopping the attack and restoring the system. Forensics focuses on establishing what happened, based on evidence, without compromising its integrity. The two run alongside each other.

Which evidence sources does the course cover?

Disk images, memory (RAM) analysis, file system artefacts, operating system records and network traffic analysis are all in scope.

Does it teach how to write a court-admissible report?

Yes. Preserving the chain of custody, documenting findings reproducibly and reporting discipline form a dedicated part of the course.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.