What does a typical digital forensics training programme look like?

Example 2-day “Digital Forensics in Practice” training programme

(fully adjustable – this is the version most frequently ordered by law firms, police units and corporate security teams in Poland)

Day / ModuleContent
Day 1 – Theory & legal framework• Polish evidence law & chain of custody requirements
• ISO/IEC 27037 and NIST SP 800-86 standards
• Correct seizure and documentation of devices
• Write-blockers, forensic imaging, hashing (hands-on)
• Live demo: creating a verified forensic image of a phone and laptop
Day 1 – Tools & core techniques• Overview of professional tools (Magnet AXIOM, Autopsy, X-Ways, Cellebrite, FTK Imager, Arsenal Image Mounter)
• File system analysis (NTFS, APFS, ext4)
• Metadata, timeline creation (log2timeline, Plaso)
• Recovery of deleted data and carving
Day 2 – Communication, apps & cloud• Mobile forensics (iOS & Android): logical, file-system and full physical extractions
• Analysis of WhatsApp, Signal, Telegram, iMessage, e-mail
• Cloud forensics (iCloud, Google Takeout, Office 365)
• Internet history, cookies, cache reconstruction
Day 2 – Reporting & court• Structure of forensic report and court opinion
• How to write findings that are understandable to judges and lawyers
• Common mistakes that cause reports to be rejected
• Mock cross-examination – how to defend your opinion in court
Day 2 – Practical workshop• Participants work in teams on real (anonymised) cases)
• Seizure → imaging → analysis → timeline → final report
• Each team presents its findings and receives feedback

Participants leave with:

The same programme can be delivered 1-day (condensed) or 3-day (deep-dive with advanced encryption and anti-forensics).