Skip to content
Module 115 hrs5 topics

Foundations: Hardware, OS & Indian Cyber Law

How modern computers store data, how operating systems boot and lay out files, the cyber crime taxonomy a digital forensic examiner needs, and the Indian statutory frame: IT Act 2000, BNS 2023 cyber sections, BSA 2023 Section 63.

Start module
  1. Computer Hardware Fundamentals for Forensic ExaminersMotherboard to NVMe SSD, register-level volatility to TRIM destruction, mapped onto IT Act 2000, BSA 2023 Section 63.14 min
  2. Operating Systems, Boot Process and File SystemsUEFI to MFT to APFS snapshots, MAC timestamps, file slack and shadow copies, mapped to BSA 2023 Section 63 admissibility.15 min
  3. Cyber Crime Taxonomy and the IT Act 2000The Indian cyber crime taxonomy a digital forensic examiner must know, mapped onto the IT Act 2000 sections, the ITAA 2008 amendment, and the post Shreya Singhal frame.10 min
  4. BNS 2023 Cyber Provisions and BSA 2023 Electronic EvidenceHow BNS 2023 cyber sections and BSA 2023 Section 63 frame electronic evidence in Indian trials, with Anvar PV, Arjun Pandit Rao Khotkar and Shafhi Mohammad mapped onto practice.10 min
  5. The Digital First Responder: Order of Volatility, Seizure and ImagingHow a digital first responder handles a live computer scene in India: order of volatility under RFC 3227, RAM capture, write blockers, dd vs E01 vs AFF4 imaging, dual hashing, and BSA Sec 63 admissibility.14 min
Module 218 hrs5 topics

Computer Forensics: OS Artifacts & Data Recovery

Windows, Linux and macOS artifact-level forensics: registry, event logs, prefetch, ShellBags, ADS, plist, Keychain, Time Machine; plus file carving and recovery from formatted, hidden and encrypted storage.

Start module
  1. Windows Forensic Artifacts I: Registry, Event Logs and PrefetchRegistry hives, EVTX event logs, and Prefetch as proof of execution: a working examiner's reference, with the Eric Zimmerman toolset and the Indian SFSL triage workflow.17 min
  2. Windows Forensic Artifacts II: ShellBags, ADS, LNK, Hibernation and Slack SpaceShellBags, NTFS Alternate Data Streams, LNK shortcuts, hiberfil.sys, pagefile, slack space, VSS and Recycle Bin internals for Indian digital forensic examiners.11 min
  3. Linux Forensic Artifacts: File System, Logs, Cron and Shell Historyext4, /var/log, auditd, journalctl, bash history, cron persistence, SUID, SELinux and plaso timelining for Indian digital forensic examiners working Linux servers.15 min
  4. macOS Forensic Artifacts: plist, Keychain, Time Machine and Browser TracesAPFS, launchd, .plist parsing, Keychain extraction, Time Machine snapshot recovery, the Unified Log, FSEvents and Safari/Chrome traces, with the Indian Mac forensics case practice that's now landing in CFSL queues.15 min
  5. Data Recovery, File Carving and Recovering Deleted, Hidden & Encrypted ContentWhat 'deleted' means at the filesystem level, signature-based carving with PhotoRec and Foremost, SSD TRIM realities, BitLocker/FileVault/LUKS/VeraCrypt recovery paths, cold-boot key extraction, and the steganography detection workflow Indian CFSL teams actually run.14 min
Module 312 hrs4 topics

Internet, Email & Surveillance Forensics

Web browser artifact recovery, email header tracing and spoofed-mail investigation, DVR/NVR surveillance forensics, and how virtual machines and cloud-backed endpoints change the examiner's playbook.

Start module
  1. Web Browser Forensics: Cookies, Cache, History and Session RecoveryWhere Chrome, Firefox, Safari and Edge keep history, cookies, cached objects and saved credentials; how to recover incognito traces; and how the artefacts read in Indian banking-fraud and phishing cases.14 min
  2. Email Forensics: Protocols, Header Tracing and Spoofed Mail InvestigationSMTP, POP3 and IMAP ports; reading Received headers bottom-up; SPF, DKIM and DMARC checks; PST, OST and mbox parsing; and the Indian IT Act and BNS provisions for prosecuting phishing and spoofed mail.14 min
  3. DVR/NVR and Surveillance System ForensicsHow Indian cyber cells acquire and parse DVR and NVR evidence: proprietary file systems, H.264/H.265 frame extraction, BSA 2023 Section 63 admissibility, and the Tomaso Bruno cautionary line.15 min
  4. Virtual Machine and Cloud-Backed Endpoint ForensicsVMDK, VHDX, qcow2 and the snapshot chain; OneDrive Files On-Demand and iCloud placeholders; Docker overlay2; and how Indian cyber cells handle VM and cloud-stored evidence under BNSS 105.17 min
Module 418 hrs6 topics

Network Forensics

Networking fundamentals to live capture: OSI/TCP-IP, network attack taxonomy, wireless attacks across WEP/WPA/WPA2/WPA3, defence architecture, packet capture and DPI, and malware static + dynamic analysis.

Start module
  1. Computer Networking Fundamentals: OSI, TCP/IP, IPv4/IPv6 and SubnettingNetworking from signalling to subnetting for digital forensic examiners in India: OSI vs TCP/IP, IPv4 classes and CIDR, IPv6 SLAAC, MAC addressing, switching, routing, Wi-Fi 7, and which header fields survive each layer of a packet capture under CERT-In's 180-day log retention rule.16 min
  2. Network Attacks: Sniffing, ARP Poisoning, MITM, DDoS, XSS and SQLiThe attack taxonomy for Indian digital forensic examiners: passive vs active sniffing, ARP and DNS spoofing, BGP hijacks, MITM and SSLstrip, OWASP Top 10 web attacks, volumetric and application-layer DDoS, phishing and zero-days, with CERT-In incident response and the I4C escalation path.18 min
  3. Wireless Network Attacks: WEP, WPA, WPA2, WPA3 and Rogue Access PointsWEP RC4 cracking, WPA2 PMKID and KRACK, WPA3 Dragonblood, evil-twin and captive-portal phishing, NFC and QR fraud, IMSI catchers and the Indian wireless threat landscape.14 min
  4. Network Security Architecture: Firewalls, IDS/IPS, IPSec, SSL/TLS, VPN, PKI and SIEMStateful and NGFW firewalls, Snort and Suricata IDS, IPSec AH/ESP, TLS 1.2/1.3 cipher suites, IPSec and WireGuard VPNs, Kerberos and Indian PKI, SIEM and the CERT-In 2022 Direction.16 min
  5. Live Packet Capture, Traffic Analysis and Deep Packet InspectionFrom promiscuous mode and SPAN ports to BPF capture filters, NetFlow, JA3/JA3S fingerprints and honeynets, with the CERT-In CCMP reporting clock and Indian SOC playbook in mind.17 min
  6. Malware Forensics: Static, Dynamic, Sandbox and Memory AnalysisPE headers, ImpHash, YARA, Cuckoo and Any.Run, Volatility 3 and MemProcFS, IoCs and persistence, walked through the AIIMS Delhi ransomware incident and CERT-In's malware advisory workflow.16 min
Module 512 hrs4 topics

Cloud Forensics & Anti-Forensics

Cloud technology, virtualization and the multi-tenant problem; cloud forensics challenges across IaaS/PaaS/SaaS; logging, VM snapshot acquisition and incident response; plus anti-forensic techniques and the counter-moves.

Start module
  1. Cloud Technology, Virtualization and Cloud Security ArchitectureNIST SP 800-145 definitions, IaaS/PaaS/SaaS, hypervisors and containers, shared responsibility, IAM and KMS, with DPDP Act 2023, RBI localisation and MeitY-empanelled CSPs.17 min
  2. Cloud Forensics: Multi-Tenant, API and Jurisdictional ChallengesNIST IR 8006 cloud forensics, volatility and multi-tenancy, CloudTrail-class API evidence, VM snapshot acquisition, and the Indian legal frame: DPDP Act 2023, CERT-In Direction 2022, MLAT and IT Rules 2021.17 min
  3. Cloud Logging, VM Snapshots and Cloud Incident ResponseCloud forensic logging across AWS, Azure and GCP, EBS and managed-disk snapshot acquisition, NIST 800-61 incident response in cloud accounts, and the CERT-In April 2022 180-day retention rule that anchors Indian cloud cases.14 min
  4. Anti-Forensic Techniques and Investigator Counter-MethodsAnti-forensics in 2026: data destruction, steganography, timestomping, log clearing, encrypted containers, memory rootkits and cloud account churn, with the investigator counter-moves and the Indian legal frame under BNSS Section 91, BSA Section 39, and Selvi v State of Karnataka.14 min
Module 618 hrs6 topics

Mobile, Wireless & IoT Forensics

Mobile network generations and SIM/IMEI fundamentals, Android and iOS forensics with SQLite, wireless and mobile network attacks, the acquisition stack from logical to chip-off, mobile cloud backups and IoT device forensics.

Start module
  1. Mobile Technologies: 2G to 5G, GSM/CDMA, SIM and IMEICellular generations, GSM and CDMA architecture, SIM file system, IMEI structure and Indian SIM-swap and CEIR workflows.12 min
  2. Mobile Operating Systems: Android, iOS, SQLite and App ForensicsAndroid and iOS architecture, SQLite WAL recovery, per-app artefact paths, UPI app forensics and encryption models for Indian digital forensic examiners.14 min
  3. Wireless and Mobile Network Attacks: Phreaking, SIM Swap, NFC and QRPhone phreaking history through Captain Crunch's 2600 Hz whistle to modern IMSI catchers, vishing and CLI spoofing, Wi-Fi MITM on Indian airport SSIDs, SIM swap fraud under the TRAI 24-hour cool-off, NFC cloning with Flipper Zero and Proxmark, and QRJacking against UPI counters.19 min
  4. Mobile Phone Forensics: Acquisition Methods, JTAG, Chip-Off and ToolkitsFaraday-bag seizure, the NIST SP 800-101 R1 six-level extraction ladder from manual through chip-off and micro-read, JTAG soldering on test points, chip-off BGA reballing, Cellebrite UFED and Magnet AXIOM workflows in Indian state cyber cells, CDR-driven location reconstruction and SQLite WAL recovery.21 min
  5. Mobile Cloud and Backup Forensics: iCloud, Google Drive and App PermissionsiCloud backup contents and E2E classes, Advanced Data Protection, Google Drive/Android backups, WhatsApp E2E backups, TCC.db, BNSS 91 production orders and the Indian MLAT route for Apple, Google and Meta.18 min
  6. IoT Forensics: Smart Home, Wearables, MQTT/CoAP and Firmware AnalysisSmart speakers, Ring and CP Plus cameras, Mi Band and boAt wearables, MQTT and CoAP protocols, binwalk and Ghidra firmware analysis, UART/JTAG/eMMC acquisition, and BSA Section 63 plus DPDP Act admissibility for IoT-collected evidence.17 min
Module 715 hrs6 topics

Social Media Forensics & Cryptography

Social media crime taxonomy and evidence collection across APIs and OSINT, plus the cryptography a digital forensic examiner must understand: symmetric and asymmetric systems, hashing, PKI, digital signatures, cryptanalysis and Diffie-Hellman.

Start module
  1. Social Media Crime: Cyberbullying, Grooming, Stalking and Fake AccountsThe Indian social media landscape, the offence taxonomy across cyberbullying, grooming, stalking, fake accounts, NCII, sextortion and romance scams, the deepfake era from the Rashmika Mandanna case onwards, and the IT Act, BNS, POCSO and Intermediary Guidelines 2021 frame that prosecutes each.11 min
  2. Social Media Evidence Collection: API, Direct, Indirect and OSINTSources of social media evidence, the four collection methods (direct without login, direct with login, API-based and indirect), the OSINT toolset from Maltego to Sherlock, EXIF and document metadata extraction, geolocation pivots, recovery of deleted content via Wayback and provider subpoena, and authentication at trial under BSA Section 63.13 min
  3. Cryptography Fundamentals: Symmetric vs Asymmetric, Substitution and TranspositionCIAN goals, symmetric vs asymmetric trade-offs, the key-distribution problem, classical substitution and transposition ciphers, key types, confusion and diffusion, the forensic attack model, and how CCA India and UPI bind these ideas to real Indian infrastructure.15 min
  4. Symmetric Cryptosystems: DES, AES, RC4 and BlowfishBlock vs stream, the seven modes of operation an examiner must know, DES through Triple-DES, AES internals, why RC4 is dead, Blowfish and Twofish, ChaCha20-Poly1305, and how Aadhaar, UPI and the RBI 2023 PoS mandate map onto AES-256.15 min
  5. Asymmetric Cryptosystems, Hashing, PKI and Digital SignaturesRSA, ECC, SHA-2/3, HMAC, X.509 and the Indian CCA PKI stack with Class 3 DSC and UPI cryptography.13 min
  6. Cryptanalysis, Cryptographic Attacks and Diffie-Hellman Key ExchangeClassical and modern cryptanalysis, side channels, padding oracles, post-quantum readiness and the Diffie-Hellman key exchange.14 min

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.