Advance Training Certification in Computer Forensic Investigation

Course overview

This course provides students with a comprehensive understanding of how to identify, collect, preserve and analyze digital evidence from storage devices such as hard drives, SSDs and external media.

The course focuses on the principle of forensic imaging, data recovery and analysis of file system while maintaining the integrity of evidence. Students will gain practical experience in using professional forensic tools to recover deleted, hidden, or encrypted data and to interpret digital traces relevant to investigations.

Emphasis is placed on the legal and ethical standards that guide digital evidence handling and reporting in forensic examinations.

Programme Details

  • Duration: 2 Months.
  • Mode: Offline (Hands-on Lab training).
  • Batch Size: Limited to 5 students for individualised mastery.
  • Location: A-525-527, Anthurium Tower, Noida Sector 73.

Topics covered

  • Introduction to Computer Forensics and its importance with real life cases
  • Different types of storage media and their types
  • How HDD, SSD & Hybrid drive work and their parts
  • Different types of interfaces of disk and their connectors
  • Understanding Disk Structure and File Systems
  • Types of data & How data store in a device
  • Introduction to operating system
  • Seizures of digital evidence and detailing
  • Collection of evidence by disassembling
  • Collection of evidence from running machine – RAM capturing
  • Examination of Encrypted and Protected Volumes
  • Introduction to Malware, rootkit & spyware
  • Standard procedure for handling disk evidence
  • Introduction to write blockers and their types
  • Forensic Imaging and Evidence Acquisition
  • Data Integrity Verification and Hashing Techniques
  • Recovery of Deleted, Hidden, and Encrypted Data
  • Metadata and File Signature Analysis
  • Law related to Computer Forensic
  • Chain of Custody and Evidence Management
  • Forensic Report Preparation and Documentation
  • Practical Case Study and Investigation Simulation

Hands-on Training list

  1. Parts/components of disks — identify and describe HDD and SSD components and their functions.
  2. RAM — locate and explain pagefile.sys and hiberfil.sys and where to check them.
  3. Registry — show where to find important registry values and how to view them.
  4. SOPs — write standard operating procedures covering the entire workflow up to courtroom presentation.
  5. Crime-scene photography — document proper crime-scene photography techniques and forensic investigative steps.
  6. Laptop disassembly — safely disassemble laptops and extract internal drives for analysis.
  7. Live forensics — detect whether a disk is encrypted and use an Encrypted Disk Detector (EDD).
  8. Live forensics — capture RAM correctly and preserve volatile evidence.
  9. VirusTotal — use VirusTotal for online malware scanning and interpreting results.
  10. Hashing — calculate and verify hash values using tools like Hash My Files and AccuHash.
  11. FTK – RAM Capture — hands-on practice creating forensically sound images and RAM captures.
  12. Volatility & CAINE — hands-on use of Volatility and CAINE for memory and system analysis.
  13. Data recovery — recover data from HDDs, SSDs, memory cards and USB drives, including common failure scenarios.
  14. TX1 procedures — perform TX1 tasks: hashing, secure wiping, recovery of formatted drives, full/partial/logical/physical imaging, and document each step.
  15. FTK tool kit : investigation procedure.
  16. Windows Forensic Investigation
  17. Mac forensic Investigation
  18. Reporting — prepare detailed forensic reports using Autopsy and FTK Toolkit with clear findings, methodology, and exhibits.

What will we learn?

  1. Understand and hands-on Forensic tools used in computer forensic.
  2. Understand the fundamentals of disk forensics and its importance in real-life investigations.
  3. Workflow and protocol followed in laboratories.
  1. Learn about bits, bytes, hexadecimal characters, ASCII, and Unicode encoding.
  2. Explore different types of memory: RAM, ROM, Cache, and registers, including system files.
  3. Identify and understand various storage devices: HDD, SSD, SSHD, optical drives, and enterprise storage.
  4. Calculate disk capacity using CHS addressing and measure hard disk performance.
  5. Understand SSD architecture: NAND flash, flash controllers, and pros/cons of SSDs.
  6. Learn about disk interfaces: PATA, SATA, SCSI, SAS, PCIe.
  7. Study registry files (SAM, SYSTEM, SOFTWARE, SECURITY, NTUSER.dat) and their forensic relevance.
  8. Differentiate between types of data: active, latent, hidden, archival, deleted, and overwritten.
  9. Understand disk space concepts: allocated vs. unallocated, slack space, unused space.
  10. Explore operating systems (Windows, macOS, Linux) and their components.
  11. Learn about file systems: FAT, NTFS, ReFS, HFS+, APFS, Ext2/3/4, ReiserFS, XFS, JFS, Btrfs.
  12. Understand the process of digital evidence seizure and chain of custody (COC).
  13. Learn the complete SOP from evidence seizure to courtroom presentation.
  14. Practice crime scene photography and CSI kit usage.
  15. Practice evidence collection from disassembled systems and running machines.
  16. Understand full disk encryption (FDE), its forensic challenges, and tools used for detection and decryption.
  17. Use tools like Encrypted Disk Detector, Elcomsoft, Passware Kit, BitLocker, VeraCrypt, and TrueCrypt.
  18. Capture RAM and perform logical file collection using FTK.
  19. Analyze malware using VirusTotal and understand types like spyware and rootkits.
  20. Learn hashing concepts and tools: MD5, SHA-1, SHA-256, Hash My Files, AccuHash.
  21. Follow standard lab procedures for handling disk evidence and documentation.
  22. Use write blockers (hardware/software) and understand NIST requirements.
  23. Operate forensic tools like Tx1 for hashing, wiping, and disk imaging.
  24. Analyze cases using FTK and Autopsy, and create detailed forensic reports.
  25. Explore additional forensic tools: Magnet AXIOM, VOLATILITY, Belkasoft, Paladin, Caine.
  26. Understand Indian laws related to disk forensics and digital evidence handling.
  27. Document and report findings from forensic extractions and analysis.