← Back to the catalogueDigital Forensics
Intermediate to Advanced
Level
Classroom . Online . Hybrid
Mode
Course overview
A digital forensics course covering evidence acquisition, artefact analysis and reporting fit for review. The course follows evidence from seizure to court-ready report: imaging, hashing, chain of custody, file system and registry analysis, memory forensics, browser and email artefacts, and timeline reconstruction.
All exercises use open-source tooling on prepared disk and memory images.
Who it is for
- Security analysts and incident responders
- Law enforcement and legal support staff
- IT administrators handling investigations
- Audit and compliance teams
Prerequisites
Operating system fundamentals and basic command line.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Full Case Analysis and Forensic Report
Programme sheet
The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.
Learning outcomes
01
Acquire disk and memory images without altering evidence.
02
Maintain hashing and chain-of-custody records.
03
Analyse NTFS, FAT and ext file system artefacts.
04
Recover deleted and hidden data.
05
Extract registry, browser and email artefacts.
06
Reconstruct a timeline of user and system activity.
07
Write a factual report suitable for review.
Module structure
8 modulesModule 01
Forensic Principles
Evidence types . Documentation . Order of volatility . Legal admissibility . Anti-forensics awareness
Write blockers . Memory capture . Hash verification . Disk imaging . Live vs dead acquisition
Tools — FTK Imager, DumpIt
Module 03
File System Analysis
NTFS and MFT . ext4 . Slack space . FAT . Metadata . Deleted file recovery
Tools — Autopsy, Sleuth Kit
Module 04
Windows Artefacts
Registry hives . Shellbags . USB history . Prefetch . Event logs . LNK files
Lab
User Activity Reconstruction
Module 05
Memory Forensics
Process lists . Injected code . Malware indicators . TOOLS . VOLATILITY . Network connections
Module 06
Browser, Email and Mobile
Browser history and cache . Email headers . PST and MBOX . Mobile extraction overview
Module 07
Network and Log Forensics
PCAP analysis . Session reconstruction . Log correlation . Time zone handling
Tools — Wireshark, NetworkMiner
Module 08
Timeline and Reporting
Super timelines . Findings vs interpretation . Report structure . Expert conduct
Assessment & certification
Module assignments and labs
25%
Final project and review
40%
Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.
Career outcomes . Roles this programme prepares for
Digital Forensics AnalystIncident Response SpecialistCyber Crime InvestigatoreDiscovery AnalystSecurity Consultant