NDG Forensics v2

Practice digital forensic investigation techniques: evidence collection, file system analysis, and incident documentation in isolated lab environments.

Open Source Cybersecurity NDG

About this course

Course Details

NDG Forensics v2 covers digital forensic investigation practices through a series of labs. You'll practice evidence collection, file system analysis, data recovery, chain of custody documentation, and incident reporting in isolated environments.

These labs prepare you for roles including computer forensic analyst, digital forensic examiner, incident responder, and security administrator.

What you'll learn

01 Analyze digital evidence using forensic methodologies and chain-of-custody procedures
02 Perform disk imaging and data recovery using industry-standard forensic tools
03 Examine file system artifacts, metadata, and timestamps across Linux and Windows
04 Investigate network-based evidence including packet captures and log analysis
05 Document forensic findings in reports suitable for legal and compliance review
Course outline
Labs 22 items
Lab 01: Creating a Forensic Image
Lab 02: Live Acquisition
Lab 03: Live Forensics
Lab 04: Registry Forensics
Lab 05: File Systems
Lab 06: Keyword Search and Analysis
Lab 07: Data Carving
Lab 08: Metadata and Link File Analysis
Lab 09: Recycle Bin Forensics
Lab 10: Steganography and Alternative Data Streams
Lab 11: Picture File Analysis
Lab 12: Email Analysis
Lab 13: Internet Browser Forensics
Lab 14: Timeline Analysis
Lab 15: IoT Forensics
Lab 16: Mobile Forensic Analysis
Lab 17: Log Capturing and Interpretation
Lab 18: Pagefile Analysis
Lab 19: Password Cracking
Lab 20: File Hashing and Hash Analysis
Lab 21: Chain of Custody
No Lab: Launch Cyber Range

What's in this course

Lab Exercises

Prerequisites

  • Basic understanding of operating systems (Linux and Windows)
  • Familiarity with file systems, storage, and data formats
  • Basic cybersecurity knowledge recommended

Best for

  • Learners pursuing careers in digital forensics and incident response
  • IT professionals who need to collect and analyze digital evidence
  • Security analysts building forensic investigation skills
  • Law enforcement or compliance staff involved in digital investigations
Resources & support

NDG Online provides technical support specifically related to the functionality of the lab environment only. Any questions or concerns regarding the learning material or lab content must be directed to your instructor. Self-paced learners who find they require additional support are encouraged to seek out a course at a local academic institution.

Support Center
Instructor information

Common questions

Do I need a law-enforcement background?

No. The course is built for IT and security professionals and learners moving into digital forensics. Basic operating system and file system knowledge is enough to start.

What kinds of evidence do I work with?

You perform disk imaging, examine file system artifacts and metadata on Linux and Windows, and investigate network evidence such as packet captures and logs.

How long do I have access?

Your purchase includes 3 months of access to the course content and labs.