Professional Certificate of Digital Forensic Analysis in Windows
240,00€
Course Description
150 hours to reconstruct what happened on a Windows system and make it hold up in court. Disk, memory, malware and network traffic analysis, with the expert-witness report template we use in real judicial proceedings.
Duration150 hours
LevelProfessional
Format100 % online, at your own pace
Access12 months
Exam35-question test · 80 % · 60 min
PracticalDisk image analysis · 80 %
OutcomeQualifies you to act as a digital forensic expert witness
CertificateVerifiable digital badge
Spanish companies: eligible for FUNDAE funding. If your employer pays for it, we handle the paperwork together with our partner training body. Ask us before enrolling.
Course aims
- This course provides the student with the necessary knowledge at a conceptual and practical level to be able to carry out a professional Digital Forensic Analysis of Windows systems, malware files and network connections.
- The student will obtain the necessary knowledge to develop his own methodology and to be able to carry out his own analysis with the corresponding executive and technical reports, which can be presented in court with all the legal guarantees.
Table of Contents
show
1. Introduction to forensic analysis.
- Â Concept of forensic analysis.
- History.
- Some real cases.
2. Legal foundations of forensic analysis.
- Â Introduction.
- Expert’s action.
- Expert opinion.
- Expert and trial.
3. Forensic procedures for the acquisition of evidence.
- Â Chain of custody.
- Anticipated evidence.
- Preservation of evidence.
- Identification and collection of evidence.
- Cloning and integrity.
4. Practical test of a forensic analysis of a disk image of a Windows system (Trojan).
- Technical report in practical exercise format containing:
- Tools to carry out the analysis.
- Preparation of the scenario.
- Execution of the exercise and analysis of the results.
- Executive report to present to the management of the contracting company.
5. Expert report of a forensic analysis of hard disks of a Windows system (Ransomware).
- Actual expert report containing:
- Legal safeguards.
- Tools to carry out the analysis.
- Scenario preparation.
- Execution of the exercise and analysis of the results.
6. Final exam and case study – JMSec Certificate of Completion
- Final theoretical exam.
- Ethical hacking case study.
Methodology
- The course is carried out using the following elements:
- For each lesson the student will be provided documents in PDF format.
- Â The student will have to perform workshops and practical laboratories using virtual machines.
- In order to demonstrate the student’s progress in the course, the student will take a final test, as well as a practical test that will be evaluated by a tutor.
This course is also designed to be able to be taken offline using the different downloadable resources provided.
Students on this courseTaken from systems, from criminology and from the SOC
“I had been administering systems for years and had never done a serious post-incident analysis. The Windows course gave me the full method.”Christian N.IT specialist
“I needed the technical side that criminology did not give me. I now understand the digital chain of custody and can work with computer evidence without depending on a third party.”Marta A.Criminologist
“In the SOC you detect; with forensics you understand what actually happened. They are two halves of the same job and I was missing this one.”Francisco C.SOC analyst

