Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

This course is coming soon. It is not yet open for enrollment, and no payment is taken.

The outline and outcomes below reflect what this course will cover. Check back soon.

Coming soonBeginner

Digital Forensics Essentials

Acquire, preserve and analyze evidence the right way.

By LearnDefend DFIR Unit · Digital Forensics

About this course

The foundations of sound digital forensics: order of volatility, preserving a chain of custody, reading the key artifacts on a Windows host, and building a timeline that would stand up to scrutiny.

What you'll learn

  • Preserve evidence with order of volatility and chain of custody.
  • Read key Windows forensic artifacts.
  • Build a defensible forensic timeline.

Course outline

  1. 1Principles and chain of custody
  2. 2Acquisition and order of volatility
  3. 3Windows artifacts
  4. 4Timeline analysis

Prerequisites

  • Basic understanding of file systems and operating systems.
Digital Forensics Essentials | LearnDefend