All Modules DIGITAL FORENSICS

Digital Forensics · Complete Guide

Eight chapters from legal process and chain of custody through disk imaging, Windows artifacts, memory forensics, timeline analysis, network forensics, mobile and cloud evidence, and closing with anti-forensics detection and forensic report writing. Built for analysts who need evidence-grade collection and analysis skills beyond SOC-scoped triage and incident-lifecycle ownership.

8 CHAPTERS
~12 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
chain of custody disk forensics memory forensics timeline analysis network forensics mobile forensics cloud forensics anti-forensics

ALL CHAPTERS

/
01
BEGINNER 25 min

Digital Forensics Foundations: Legal Process, Order of Volatility & Chain of Custody

The branches of digital forensics, the legal and ethical framework for evidence collection, the order of volatility, chain of custody essentials, and the forensic investigation process.

chain of custody order of volatility forensic process
02
INTERMEDIATE 35 min

Disk and File System Forensics: Imaging, Partitions & Data Recovery

Forensic acquisition and imaging, write blockers, MBR versus GPT partitioning, NTFS/FAT32/exFAT internals, and deleted file recovery and data carving.

disk imaging NTFS data carving
03
INTERMEDIATE 35 min

Windows Artifact Forensics: Registry, Execution Evidence & Filesystem Metadata

Registry hives as evidence, execution and usage artifacts like Prefetch and Shellbags, NTFS filesystem metadata, and event log forensics.

registry forensics execution artifacts event log forensics
04
INTERMEDIATE 35 min

Memory Forensics: Acquisition, Volatility & Live System Analysis

Why memory-only evidence matters, memory acquisition methods, analysis with the Volatility framework, and process injection and hidden process artifacts.

memory forensics Volatility framework process injection
05
INTERMEDIATE 30 min

Timeline Analysis: MACB Timestamps, Super Timelines & Timestomping

Understanding MACB timestamps, building a super timeline, timeline analysis technique and pivot points, and detecting timestomping.

MACB timestamps super timeline timestomping
06
INTERMEDIATE 35 min

Network Forensics: Packet Capture, NetFlow & C2 Traffic Reconstruction

Sources of network evidence, packet analysis fundamentals, protocol and session reconstruction, and identifying C2 traffic in captures.

packet analysis NetFlow C2 detection
07
ADVANCED 40 min

Mobile and Cloud Forensics: iOS, Android & Cloud Provider Evidence

Mobile acquisition tiers, iOS and Android artifact categories, cloud forensics fundamentals, and cloud provider evidence sources like M365, Entra ID, and AWS CloudTrail.

mobile forensics cloud forensics iOS acquisition
08
ADVANCED 40 min

Anti-Forensics and Reporting: Evasion Techniques, Report Writing & Testimony

Common anti-forensic techniques and their detection tells, writing a defensible forensic report, and expert testimony basics.

anti-forensics forensic reporting expert testimony

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • No prior forensics experience required, Chapter 1 builds the legal and procedural foundation from scratch
  • Windows and Incident Response are good companion modules, since this module goes deeper into the evidence-collection and analysis skillset both assume
  • Basic familiarity with file systems and how an OS boots is useful but not assumed
  • No specific forensic-tool experience required, this module covers concepts and methodology, not step-by-step tool operation

WHAT YOU WILL KNOW AFTER

  • The legal and ethical framework for evidence collection, the order of volatility, and how to maintain a defensible chain of custody
  • How to acquire a forensically sound disk image and read NTFS, FAT32, and exFAT structures, including deleted file recovery
  • How to pull execution and usage evidence from the Windows registry, filesystem metadata, and event logs
  • How to acquire and analyze system memory with the Volatility framework, and spot process injection and hidden processes
  • How to build and pivot a forensic timeline, and detect timestomping by comparing NTFS timestamp attributes
  • How to read network evidence, from NetFlow to full packet capture, and identify C2 beaconing indicators
  • How mobile acquisition tiers work, and where to find evidence in cloud provider logs like M365 and AWS CloudTrail
  • How to recognize anti-forensic techniques, and write a forensic report that holds up under scrutiny

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.