Home / Courses / Digital Forensics & Incident Response
Forensics · Advanced

Digital Forensics & Incident Response

Investigate breaches like a pro — from disk and memory to a courtroom-ready report.

⏱ 22 hours ▤ 36 lessons ◎ 3 enrolled ✦ Certificate on completion

About this course

When an incident happens, someone has to reconstruct exactly what occurred. This advanced course teaches the DFIR workflow used by real responders: acquiring evidence without contaminating it, carving artifacts from disk and memory, building a timeline, and attributing activity.

You will analyse real memory images with Volatility, recover deleted files, trace a phishing-to-ransomware chain across a compromised host, and produce the kind of report that stands up to scrutiny. Chain of custody and legal considerations for the GCC are covered throughout.

Recommended after some security fundamentals — this course moves quickly and assumes comfort on the command line.

Syllabus

01 Evidence acquisition & chain of custody 5 lessons · 60 min
02 Disk forensics & file carving 6 lessons · 75 min
03 Memory forensics with Volatility 6 lessons · 80 min
04 Timeline & attribution 5 lessons · 55 min
05 The courtroom-ready report 4 lessons · 45 min

Your instructor

YA
Lead Offensive Security Instructor

OSCP- and OSWE-certified penetration tester. Yousef has led red-team engagements for banks and telcos across Kuwait and the UAE, and teaches offensive security the way it is actually practised — hands on keyboard, against real targets in the lab.

Course materials

Digital Forensics & Incident Response — syllabus (PDF) Download ↓
Digital Forensics & Incident Response — lab pack (PDF) Enroll to unlock