Digital Forensics & Incident Response
Investigate breaches like a pro — from disk and memory to a courtroom-ready report.
About this course
When an incident happens, someone has to reconstruct exactly what occurred. This advanced course teaches the DFIR workflow used by real responders: acquiring evidence without contaminating it, carving artifacts from disk and memory, building a timeline, and attributing activity.
You will analyse real memory images with Volatility, recover deleted files, trace a phishing-to-ransomware chain across a compromised host, and produce the kind of report that stands up to scrutiny. Chain of custody and legal considerations for the GCC are covered throughout.
Recommended after some security fundamentals — this course moves quickly and assumes comfort on the command line.
Syllabus
Your instructor
OSCP- and OSWE-certified penetration tester. Yousef has led red-team engagements for banks and telcos across Kuwait and the UAE, and teaches offensive security the way it is actually practised — hands on keyboard, against real targets in the lab.