About this Microcredential
Digital forensics plays a critical role in cyber incident investigations by uncovering, preserving and analysing digital evidence to determine what happened and how. As digital evidence becomes increasingly complex and dispersed across devices, systems and networks, skilled forensic investigation is essential for producing reliable and defensible findings.
The Digital Forensics Practical Extension will extend your existing digital forensics skills through hands-on investigation of realistic cyber incidents. In a dedicated virtual environment, you’ll acquire, preserve and analyse digital evidence from storage media, operating systems, volatile memory, network traffic and mobile devices using contemporary forensic tools and techniques. With the advanced practical skills you’ll gain, you’ll be well equipped to investigate digital evidence systematically and contribute to forensic investigations in a range of cybersecurity environments.
Key features
Conduct an end-to-end forensic investigation
Progress from evidence capture and validation to interpretation and reporting, producing timelines, findings and defensible forensic reports.
Reconstruct activity across major operating systems
Investigate Windows, Linux and macOS artefacts, including metadata, timestamps, deleted files, logs, registry data and user activity.
Use professional digital forensic tools
Gain hands-on experience with Autopsy, FTK Imager, Wireshark, Volatility, Mitmproxy and Npcap to examine and analyse digital evidence.
Protect the integrity of digital evidence
Apply appropriate forensic handling, hashing, validation and chain-of-custody processes to maintain evidence integrity and reliability.