Skip to content
Intermediate Defence & response Certificate

Digital Forensics & Incident Response

Work a compromise from first alert to final report — evidence handling, timeline reconstruction, and disclosure.

6 weeks 32 lessons 18 practical labs
Overview
Structured around full incident scenarios rather than isolated exercises. You get a compromised environment and work it through properly, including the parts people skip: evidence preservation and the written report.

The reporting is assessed as heavily as the technical analysis, because in a real incident it is the deliverable.
Outcomes

What you will learn

Incident response process and its correct order
Evidence preservation and chain of custody
Disk and memory forensics
Log analysis and timeline reconstruction
Malware behaviour analysis in isolation
Determining whether data was exfiltrated
Writing reports for legal and insurance audiences
Before you start

Requirements

  • Linux fundamentals and networking knowledge
  • Introduction to Ethical Hacking recommended
Who teaches it
C

CyberKnight Faculty

Security engineers and assessors

Courses are written and taught by the same people who run our client engagements. What we find in real assessments becomes the lab material here, with client details removed.

Questions

About this course

Yes. On completion you receive a certificate listing the modules covered and the lab work completed. It reflects what you actually did rather than attendance.
You get direct instructor support. Ask on WhatsApp or Telegram and a person answers — usually the same day. Nobody here will make you feel foolish for asking something basic.
Only with written authorisation from whoever owns them. The techniques are taught for authorised assessment and defensive work. Running them against systems without permission is a criminal offence in most countries, regardless of your intent.