← Back to the catalogue
Domain 05 . Security

Digital Forensics

50
Hours of teaching
Intermediate to Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A digital forensics course covering evidence acquisition, artefact analysis and reporting fit for review. The course follows evidence from seizure to court-ready report: imaging, hashing, chain of custody, file system and registry analysis, memory forensics, browser and email artefacts, and timeline reconstruction.

All exercises use open-source tooling on prepared disk and memory images.

Who it is for
  • Security analysts and incident responders
  • Law enforcement and legal support staff
  • IT administrators handling investigations
  • Audit and compliance teams
Prerequisites
Operating system fundamentals and basic command line.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Full Case Analysis and Forensic Report

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Acquire disk and memory images without altering evidence.
02
Maintain hashing and chain-of-custody records.
03
Analyse NTFS, FAT and ext file system artefacts.
04
Recover deleted and hidden data.
05
Extract registry, browser and email artefacts.
06
Reconstruct a timeline of user and system activity.
07
Write a factual report suitable for review.

Module structure

8 modules
Module 01

Forensic Principles

Evidence types . Documentation . Order of volatility . Legal admissibility . Anti-forensics awareness
Module 02

Acquisition

Write blockers . Memory capture . Hash verification . Disk imaging . Live vs dead acquisition
Tools — FTK Imager, DumpIt
Module 03

File System Analysis

NTFS and MFT . ext4 . Slack space . FAT . Metadata . Deleted file recovery
Tools — Autopsy, Sleuth Kit
Module 04

Windows Artefacts

Registry hives . Shellbags . USB history . Prefetch . Event logs . LNK files
Lab
User Activity Reconstruction
Module 05

Memory Forensics

Process lists . Injected code . Malware indicators . TOOLS . VOLATILITY . Network connections
Module 06

Browser, Email and Mobile

Browser history and cache . Email headers . PST and MBOX . Mobile extraction overview
Module 07

Network and Log Forensics

PCAP analysis . Session reconstruction . Log correlation . Time zone handling
Tools — Wireshark, NetworkMiner
Module 08

Timeline and Reporting

Super timelines . Findings vs interpretation . Report structure . Expert conduct

Assessment & certification

Module assignments and labs
25%
Internal assessments
15%
Mini projects
20%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
Digital Forensics AnalystIncident Response SpecialistCyber Crime InvestigatoreDiscovery AnalystSecurity Consultant
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security