Information Technology and Programming Courses From $2000

Course Date

2026-11-02
2027-02-01
2027-05-03
2027-08-02

Course Cost

Note / Price varies according to the selected city

Price per participant, per week $2000

Register 3 participants on the same course and pay for 2 only

Members NO. : 1
$2000

Members NO. : 2
$4000

Members NO. : 3
$4000 (pay for 2)

Categories

Digital Forensics and Cyber Incident Investigation Training Course (Online / Remote)


Summary

The decisions a team makes in the first hour after discovering a suspicious login or a strange process on a server often determine whether the resulting evidence will still be usable weeks later. Rebuild the system too soon and the trail disappears; handle a drive carelessly and the chain of custody breaks. The Digital Forensics and Cyber Incident Investigation Training Course by Arab British Fellowship Training Academy is built around that pressure point – giving professionals a repeatable process for preserving, analysing, and reporting on digital evidence without compromising it.

Delivered within the Information Technology and Programming Courses portfolio, the programme moves from evidence acquisition and chain of custody through disk imaging, log analysis, and malware artefact examination, and ends with the forensic reporting that investigation findings ultimately depend on. Throughout, it treats investigation not as a purely technical exercise but as a function that has to coordinate cleanly with incident response, compliance, legal, and executive stakeholders.

Objectives and target group

By the end of this course, participants will be able to:

  • Respond to a suspected cyber incident with an evidence-preservation mindset from the first assessment onward.
  • Acquire digital evidence – volatile and non-volatile – using procedures that protect its integrity and admissibility.
  • Maintain a defensible chain of custody, including documentation, access controls, and hashing/validation.
  • Perform or oversee forensic disk imaging and distinguish original evidence from forensic and working copies.
  • Examine operating system, endpoint, and application artefacts to establish user and system activity.
  • Analyse security, authentication, network, and application logs to correlate events across systems.
  • Recognise malware artefacts, persistence indicators, and indicators of compromise.
  • Reconstruct incident timelines from multiple evidence sources and distinguish facts from assumptions.
  • Write forensic reports that communicate technical findings clearly to both technical and executive audiences.
  • Feed investigation findings into post-incident reviews and broader security-control improvements.

Target Audience

  • Security analysts, incident responders, and security operations personnel.
  • IT managers, system administrators, and infrastructure specialists who may need to preserve evidence.
  • Digital investigators and forensic specialists.
  • Risk, compliance, and internal audit professionals working with technology investigations.
  • IT and cybersecurity managers responsible for incident response readiness.
  • Legal and corporate investigation support teams handling technology-related cases.

Course Content

Module 1: The First Hour – Why Early Decisions Decide the Case

  • Initial assessment of a suspected cyber incident.
  • Evidence prioritisation before systems are modified, rebuilt, or isolated.
  • Coordination between security, IT, and investigation teams from the outset.

Module 2: Foundations and Scope of Digital Forensic Investigation

  • Definition, objectives, and corporate applications of digital forensics.
  • Types and sources of digital evidence across technology environments.
  • Roles, responsibilities, and challenges associated with digital evidence.

Module 3: Acquiring Evidence Without Destroying It

  • Principles of evidence acquisition and collection planning.
  • Volatile versus non-volatile evidence and acquisition risks.
  • Verifying and documenting acquired evidence.

Module 4: Chain of Custody and Keeping Evidence Defensible

  • Evidence identification, classification, and handling procedures.
  • Access controls, hashing, and integrity verification.
  • Common chain of custody failures and how to avoid them.

Module 5: Disk Imaging and Storage-Level Analysis

  • Logical and physical acquisition, forensic copies versus working copies.
  • File systems, deleted and hidden data, and file metadata.
  • Partition and volume analysis for relevant artefacts.

Module 6: Reading the System – Endpoint, OS and Log Artefacts

  • User activity indicators, authentication records, and persistence mechanisms.
  • Security, network, application, and server log analysis.
  • Correlating events across systems and identifying unusual activity.

Module 7: Malware Traces and Network/Cloud Evidence

  • Identifying malware artefacts, suspicious processes, and indicators of compromise.
  • Network evidence sources, connection records, and remote-access indicators.
  • Evidence considerations specific to cloud and distributed environments.

Module 8: Building the Timeline – Correlation and Analysis

  • Event sequencing and timeline reconstruction from multiple sources.
  • Evaluating evidence reliability and identifying gaps.
  • Developing defensible, evidence-supported findings.

Module 9: Writing Forensic Reports That Hold Up

  • Structuring investigative methodology, evidence, and timelines for a report.
  • Recording limitations, assumptions, and supporting documentation.
  • Communicating technical findings to management and non-technical stakeholders.

Module 10: From Investigation to Organisational Learning

  • Integrating forensic findings with incident response and recovery decisions.
  • Post-incident evidence review and identification of control weaknesses.
  • Evidence retention, quality assurance, and strengthening future readiness.

Related Course

In-Person

Digital Forensics and Cyber Incident Investigation Training Course

2026-11-02

2027-02-01

2027-05-03

2027-08-02

$4500