Skip to content
Module 16 hrs3 topics

Cybercrime and cyber forensics foundations

What cyber forensics is and how it differs from device-level digital forensics.

Start module
  1. What Is Cyber ForensicsCyber forensics is the discipline of collecting, preserving, and analysing digital evidence from networked environments to support criminal and civil investigations. This topic defines the field, distinguishes it from device-level digital forensics, and outlines the investigator's core responsibilities.13 min
  2. Cyber Forensics vs Digital Forensics: Scope and BoundariesWhile digital forensics focuses on disk imaging and OS artefacts, cyber forensics centres on network-sourced evidence, online accounts, and cybercrime investigation workflows. This topic maps the boundary between the two disciplines and explains when to cross-reference each.13 min
  3. Legal and Ethical Foundations of Cyber InvestigationsCyber investigators must operate within legal authority, respect privacy rights, and maintain chain of custody for evidence gathered across multiple jurisdictions. This topic introduces the ethical obligations, authorisation requirements, and documentation standards that underpin every cyber investigation.13 min
Module 26 hrs3 topics

Cybercrime typology

Hacking, fraud, ransomware, identity theft, and online exploitation.

Start module
  1. Hacking and Unauthorised Access OffencesUnauthorised access offences range from opportunistic intrusions to nation-state espionage, each leaving a distinct digital footprint. This topic covers the legal definitions, common methods, and investigative indicators associated with hacking crimes globally.13 min
  2. Online Fraud and Financial CybercrimeFinancial cybercrime encompasses phishing, business email compromise, card-not-present fraud, and investment scams that collectively cause hundreds of billions in annual losses. This topic examines each scheme's mechanics, common victim profiles, and the evidence trails investigators pursue.13 min
  3. Ransomware, Identity Theft and Online ExploitationRansomware, identity theft, and image-based sexual abuse represent distinct but overlapping categories of cybercrime that combine technical intrusion with human harm. This topic analyses their operational patterns, legislative frameworks across key jurisdictions, and evidentiary priorities for investigators.13 min
Module 36 hrs3 topics

Networks and the internet for investigators

How the internet works, IP addressing, DNS and attribution basics.

Start module
  1. IP Addressing and Routing Fundamentals for InvestigatorsUnderstanding IPv4 and IPv6 addressing, subnetting, and routing is essential for tracing the origin of network traffic and attributing communications to physical locations. This topic builds the investigator's working knowledge of how packets travel the internet and where attribution evidence resides.13 min
  2. DNS and Domain InvestigationThe Domain Name System is both an investigative resource and an adversary tool, used for attribution, fast-flux evasion, and command-and-control communication. This topic covers DNS record types, WHOIS and passive-DNS querying, and common attacker abuse patterns investigators encounter.13 min
  3. Network Protocols and Traffic InterpretationInvestigators reading packet captures or logs must understand TCP/IP, HTTP, SMTP, and related protocols to identify anomalous behaviour and extract evidence. This topic introduces protocol structures and the investigative significance of common header fields, connection states, and timing patterns.13 min
Module 46 hrs3 topics

Anatomy of a cyber attack

The attack lifecycle, common techniques, and indicators of compromise.

Start module
  1. The Cyber Attack LifecycleFrameworks such as the Unified Kill Chain and MITRE ATT&CK model intrusions as a sequence of phases from initial reconnaissance through impact and exfiltration. This topic explains each phase, the attacker decisions within it, and the investigative opportunities each phase creates.13 min
  2. Common Attack Techniques and Tactics, Techniques and ProceduresAttackers rely on a repeatable toolkit including spear-phishing, exploitation of public-facing applications, credential dumping, and lateral movement. This topic surveys the most frequently observed techniques and explains how documented TTPs guide both detection and investigation.13 min
  3. Indicators of Compromise: Identification and UseIndicators of compromise are observable artefacts such as malicious IP addresses, file hashes, registry keys, and domain names that signal a breach has occurred. This topic covers how investigators identify, validate, and share IOCs, and how attackers attempt to evade IOC-based detection.13 min
Module 56 hrs3 topics

Malware analysis basics

Types of malware and an introduction to static and dynamic analysis.

Start module
  1. Malware Taxonomy: Viruses, Trojans, Ransomware and MoreMalware is classified by its propagation mechanism, payload behaviour, and persistence strategy, and each category presents different investigative challenges. This topic maps the major malware families, their defining characteristics, and the typical artefacts they leave on infected systems.13 min
  2. Static Malware AnalysisStatic analysis examines a malware sample without executing it, using file-type identification, string extraction, hashing, and disassembly to characterise its capabilities. This topic introduces the analyst's toolkit and workflow for safe, repeatable static examination of suspicious files.13 min
  3. Dynamic Malware Analysis and Sandbox EnvironmentsDynamic analysis executes malware in a controlled sandbox to observe its runtime behaviour, network callbacks, file-system changes, and process activity. This topic explains sandbox selection, behavioural monitoring techniques, and the limitations investigators must account for when interpreting automated reports.13 min
Module 66 hrs3 topics

Web, email and social media investigation

Tracing online accounts, emails, headers and open-source evidence.

Start module
  1. Email Header Analysis and Sender TracingEmail headers encode a chronological relay path that investigators use to identify originating mail servers, authentication failures, and spoofing attempts. This topic provides a step-by-step method for parsing headers, interpreting SPF, DKIM and DMARC results, and obtaining subscriber records from providers.13 min
  2. Online Account and Social Media InvestigationSocial media platforms hold user-generated content, metadata, and account-linkage signals that are often critical to identifying suspects and establishing timelines. This topic covers open-source collection methods, platform preservation requests, and the legal processes for obtaining non-public account data.13 min
  3. Web OSINT and Digital Footprint AnalysisOpen-source intelligence drawn from websites, cached pages, public databases, and image metadata can reveal identities, locations, and behavioural patterns without any special legal authority. This topic introduces structured OSINT methodology, key tools and databases, and the evidentiary standards investigators must apply to open-source findings.13 min
Module 76 hrs3 topics

The dark web and cryptocurrency

Anonymity networks, marketplaces, and tracing cryptocurrency transactions.

Start module
  1. Tor and Anonymity NetworksTor, I2P, and similar overlay networks route traffic through multiple encrypted relays to conceal users' IP addresses, and are widely used by both privacy advocates and criminal actors. This topic explains how these networks function, their investigative challenges, and the deanonymisation techniques available to law enforcement.13 min
  2. Dark Web Marketplaces and Criminal InfrastructureDark web markets have hosted the trade of drugs, weapons, stolen data, and malware-as-a-service since the Silk Road era, creating investigative targets with distinctive operational security patterns. This topic covers marketplace structure, operational security failures that have led to takedowns, and evidence-collection strategies for hidden-service investigations.13 min
  3. Cryptocurrency Tracing and Blockchain AnalysisCryptocurrency transactions are pseudonymous rather than anonymous, and public ledgers enable investigators to trace fund flows, cluster addresses, and link wallets to real-world identities. This topic covers Bitcoin and Ethereum transaction anatomy, blockchain analytics tools, and the process of converting on-chain intelligence into legal evidence.13 min
Module 86 hrs3 topics

Cyber threat intelligence

Sources, indicators, attribution and how intelligence supports investigation.

Start module
  1. Threat Intelligence FundamentalsCyber threat intelligence converts raw data about adversary activity into actionable knowledge that informs detection, investigation, and strategic decision-making. This topic introduces the intelligence cycle, the four levels of threat intelligence (strategic, operational, tactical, technical), and the key frameworks used to structure and share intelligence.13 min
  2. Intelligence Sources, Feeds and Sharing PlatformsInvestigators draw threat intelligence from open-source feeds, commercial platforms, ISACs, dark-web monitoring, and inter-agency sharing networks. This topic surveys the major source categories, their reliability characteristics, and the STIX/TAXII standards that enable machine-readable intelligence exchange.13 min
  3. Attribution in Cyber InvestigationsAttributing a cyberattack to a specific actor, group, or nation-state requires combining technical indicators with behavioural patterns and contextual intelligence, and carries significant legal and geopolitical consequences. This topic explains the attribution ladder from IP address to actor identity, the confidence-level model, and the risks of false attribution.13 min
Module 96 hrs3 topics

Cyber law and jurisdiction

Computer-crime statutes, cross-border evidence, and lawful access.

Start module
  1. Computer Crime Statutes and Global Legal FrameworksComputer-crime legislation varies significantly across jurisdictions, though instruments such as the Budapest Convention on Cybercrime provide a common reference framework adopted by over 60 countries. This topic surveys key national statutes, the Budapest Convention's substantive and procedural provisions, and how investigators identify the applicable law for a given case.13 min
  2. Cross-Border Evidence and Mutual Legal AssistanceCybercrimes routinely involve suspects, victims, infrastructure, and evidence spread across multiple countries, making mutual legal assistance treaties (MLATs) and emergency preservation requests essential tools. This topic explains the MLAT process, the Council of Europe's Article 29 expedited preservation mechanism, and practical strategies for managing multi-jurisdictional investigations.13 min
  3. Lawful Access, Interception Law and Privacy ProtectionsInvestigators seeking real-time interception of communications or stored account data must navigate lawful-access regimes that balance investigative need against constitutional and human-rights protections. This topic covers court orders, production orders, subscriber-data requests, and the legal constraints on compelled decryption in key jurisdictions.13 min
Module 106 hrs3 topics

The cyber investigation process

From report to evidence to report, end to end.

Start module
  1. Intake, Scoping and Evidence PreservationThe first actions taken after receiving a cybercrime report determine whether critical evidence is preserved or lost, and set the scope and priority of the subsequent investigation. This topic covers triage criteria, victim-system preservation orders, volatile-data capture, and the documentation required to establish chain of custody from the outset.13 min
  2. Cyber Investigation Tools and Analytical WorkflowA structured analytical workflow -- from log ingestion and timeline reconstruction to hypothesis testing and evidence correlation -- ensures that findings are reproducible and defensible in court. This topic introduces the core toolset used in cyber investigations, including SIEM platforms, network forensics tools, and link-analysis software, and explains how to document each analytical step.13 min
  3. Cyber Investigation Reporting and Court PresentationThe culmination of a cyber investigation is an expert report that translates technical findings into plain language admissible as evidence and comprehensible to judges, juries, and counsel. This topic covers report structure, the standards for expert witness testimony in cyber cases, and common challenges that opposing experts raise against digital evidence.13 min

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.