Cyber Forensics Expert

Digital evidence reveals the story that suspects would rather keep hidden. In this intensive 8-day course, youโ€™ll learn how to conduct forensic investigations on Windows, macOS, browsers, cloud environments, and video footage, and gather evidence that will hold up in court.

  • Prerequisite: basic knowledge of Windows, information security, and TCP/IP โ€” suitable for law enforcement officers, forensic specialists, and experienced IT professionals.
  • 64 hours of intensive hands-on training: from Windows and registry forensics to Mac forensics, CCTV analysis, and cloud evidence.
  • Ready to work immediately as a forensic investigator for law enforcement, security, and incident response organizations.
  • Each student works in their own lab environment using real forensic tools and realistic investigation scenarios.

Upcoming Start Dates

No scheduled start date? Contact us โ€”we'll schedule it upon request.

Who is this program for?

For anyone who needs to collect, analyze, and present digital evidenceโ€”in investigative, legal, or security contexts.

CAREER CHANGER

You work for the police, the justice system, or a law enforcement agency, and you need in-depth technical knowledge to collect, analyze, and present digital evidence in a way that will hold up in court.

IT PROFESSIONAL

You handle incidents and want to reconstruct the entire digital attack chain. Forensic investigation gives you the tools to determine exactly what happenedโ€”and when, by whom, and through which system.

STARTER

You are a CISO, sysadmin, or technical specialist and want to develop the forensic skills needed to conduct internal investigations into data breaches, insider threats, or security incidentsโ€”and to report your findings in a legally sound manner.

What will you learn?

Youโ€™ll work in your own lab environment using real forensic tools on realistic scenariosโ€”developed and validated by experts in the forensic and security sectors.
WINDOWS & REGISTRY FORENSICS

You will learn how to conduct a forensic analysis of the Windows operating system on Windows 10, 11, and Server. You will analyze NTFS file systems, registry hives, Shell Items, LNK files, Shell Bags, and USB devices. You will create live memory images, perform Windows artifact analysis, and use a hex editor for in-depth evidence examination.

BROWSER, CLOUD, AND EMAIL FORENSICS

You will examine browser history, webmail, Microsoft 365, SharePoint, OneDrive, Teams, and Google Workspace. You will restore deleted registry keys and files, perform data recovery and file carving, and analyze email artifacts from servers and the cloud. You will detect anti-forensic techniques such as file wiping and time manipulation.

MAC FORENSICS

You conduct forensic investigations on macOS systems. You analyze system logs, Safari browser history, Keychain data, Time Machine backups, and the Spotlight database. You create Mac memory images and bash history, and examine authentication logs and syslogs.

CCTV & VIDEO FORENSICS

You will learn to conduct forensic analysis of video evidence: from metadata extraction and authenticity verification to detecting deepfakes and manipulated footage. You will work with DVR/NVR systems, analyze codecs and frames, recover deleted video files, and apply the legal frameworks for video evidence.

Structure of the Program

4 modules, 64 hours, 8 days. From Windows and registry forensics to Mac, cloud, browser, and CCTV video analysis. Each student works in their own lab environment using real forensic tools.
WINDOWS & REGISTRY FORENSICS

You will learn how to conduct forensic searches of the Windows file system and registry. You will analyze NTFS, FAT, and exFAT; work with registry hives, Shell Items, LNK files, and Shell Bags; and examine USB devices, system usage data, and the Windows Search Index. You will create live system and memory images and use a hex editor for evidence analysis. Each student works in their own lab environment.

BROWSER, CLOUD, AND EMAIL FORENSICS

You will investigate browser artifacts, including private browsing mode; analyze Microsoft 365, SharePoint, OneDrive, and Google Workspace; and recover deleted files and registry keys. You will perform data recovery, string searching, and file carving; analyze email from servers and the cloud; and detect anti-forensic techniques.

MAC FORENSICS

You will conduct forensic investigations on macOS systems. You will analyze system logs (system.log, install.log, appfirewall.log), Safari browsing history, Keychain data, Time Machine backups, and the Spotlight database. You will create Mac memory images and analyze bash history, syslogs, and authentication logs. Each student will work in their own lab environment.

CCTV & VIDEO FORENSICS

You will learn to conduct forensic analysis of video evidence: from metadata extraction and authenticity verification to detecting deepfakes and manipulated footage. You will work with DVR/NVR systems, analyze codecs, frames, and compression artifacts, recover deleted video files, and apply legal frameworks for video evidence, including the chain of custody.

What should you include on your resume?

Upon completion, you will have the following demonstrable skills:

  • Windows Forensics: NTFS Analysis, Registry Hives, Shell Items, USB Investigation
  • Browser and Cloud Forensics: Microsoft 365, Google Workspace, email forensics, file carving
  • Mac forensics: system logs, Safari, Keychain, Time Machine, Spotlight
  • CCTV & Video Forensics: DVR/NVR Analysis, Authenticity Investigations, Deepfake Detection
  • Anti-forensic detection: file wiping, time manipulation, application removal
  • Evidence Collection That Stands Up in Court: Chain of Custody and Forensic Reporting
  • Ready to work immediately as a forensic investigator for law enforcement, security, and incident response organizations

Digital evidence doesn't disappear on its ownโ€”but without the right knowledge, you won't be able to find it either. After this training, you will.

What do you get in return for your investment?

โ‚ฌโ€” excl. tax
Duration 64 academic hours
Course Load 8โ€“32 hours per week
Course Format Hybrid โ€” online, on-site, or customized
Location Schiphol-Rijk

Included

Learning StyleHoursDurationDays
Consecutive (8 days)32 hours2 weeksBy mutual agreement
Staggered Schedule8 hours8 weeks2โ€“3 half-days per week
  • Developed by security service specialists
  • Hands-on labs with real malware samples and forensic memory images โ€” no simulated environments
  • Personal guidance and coaching throughout the entire program
  • Access to our alumni network

Financing Options

Finance4Learning

With Finance4Learning, you can easily spread out your investment. The application process is quick, and weโ€™re happy to help you work out what fits your situation. Final approval depends on your personal circumstances.

EMPLOYER PAYS

Many employers cover the full cost of the training. We will provide a detailed proposal.

TEAM QUOTE

Open classes for individual employees, or a customized team program. Weโ€™ll put together a well-reasoned proposal.

Upcoming start dates.

There is currently no scheduled start date for this training program. Schedule a meeting to discuss when we can organize this training for you or your team.

Frequently Asked Questions

You have a basic understanding of Windows, information security, and TCP/IP networks. You donโ€™t need to be a programmerโ€”but a strong desire to learn is essential. The course is open to investigators, forensic specialists, sysadmins, and CISOs.

Classes are taught in Dutch. The course material, tools, and exams are in Englishโ€”which is also the standard practice in this field. A solid reading proficiency in English is sufficient to get started. A few times a year, we also offer a class taught entirely in Englishโ€”please contact us for the dates.

The course consists of 64 academic hours, spread over 8 days. You can choose between a continuous block or a schedule spread out over several 2-day blocks. The exact schedule is negotiable. A fully online option is available upon request.

Yes. The program explicitly focuses on methods for collecting evidence that is admissible in legal proceedings. Youโ€™ll learn how to work with the chain of custody, forensically sound imaging, and reportingโ€”so that your findings hold up in court.

This program is not suitable as an entry-level course for those without any IT background. Without a basic understanding of Windows and networking, the technical content will be too advanced too quickly. Not sure if you're ready? Contact usโ€”we'd be happy to help you figure it out.

Ready for the next step?

Schedule a no-obligation consultation or view the start dates.

Cyber Forensics Expert

Enter your information and we'll contact you within one business day. Together, we'll discuss whether this program is a good fit for your situation. You're not committing to anything yet.

By sharing your details, youโ€™ll receive our monthly newsletter with course start dates and cybersecurity insights. You can unsubscribe at any time.