Digital Forensics
Evidence acquisition, chain of custody, and incident reconstruction — optional deep dive.
What you'll actually learn
Digital forensics isn't about finding evidence — it's about finding evidence in a way that still holds up after someone else tries to tear it apart. This track covers how to acquire evidence without altering it, why chain of custody is a legal requirement and not paperwork theater, and how to reconstruct the actual sequence of an incident from artifacts (timestamps, deleted files, memory dumps) that most people would overlook or accidentally destroy just by looking at them wrong.
What you'll be able to do
You'll take a compromised system's disk image and memory dump and reconstruct what actually happened — not a guess, a defensible timeline built from artifacts, handled the way a real investigation requires so the evidence remains admissible. That's the real difference between "I think this is what happened" and being able to prove it.
Syllabus
Frequently asked
Roughly 2 hours across 7 hands-on quests — you can go at your own pace and pick up exactly where you left off.
You should be comfortable with Defense & Detection first — the skill tree unlocks Digital Forensics once you've cleared those.
Yes — Digital Forensics is fully available on the free tier, starting with a free first quest and no payment method required to sign up. Plus and Elite remove pacing limits but don't gate any of the Digital Forensics curriculum behind a paywall.
Create a free account and begin your first quest — no card required.
Start free