Digital Evidence & Chain of Custody
Legal foundations, evidence bagging, logging, vouchers, and contamination prevention.
View Module Sample Evidence PackEach pathway is designed to build practical operator capability with real evidence packages, Australian legal constraints, and live lab environments.
Legal foundations, evidence bagging, logging, vouchers, and contamination prevention.
View Module Sample Evidence PackLive response, imaging, timeline construction, and artefact recovery using Autopsy and Volatility.
View ModuleForensic handwriting comparison, signature verification, questioned document examination, and expert witness preparation.
Study This ModulePacket capture analysis, flow record examination, C2 beacon detection, and intrusion evidence identification with Wireshark, Zeek, and Suricata.
View ModuleStatic and dynamic analysis, PE/ELF dissection, sandbox execution, disassembly with Ghidra, debugging with x64dbg, and YARA rule development.
View ModuleEnd-to-end IR methodology, live-response triage, root cause analysis, expert report writing, and courtroom testimony preparation with mock cross-examination.
View ModuleEvery graduate completes evidence handling with valid forensic rigour, documentation, and structured reasoning chains.
Disks, phones, memory, cloud credentials. Collection according to current AFP and state forensic guidelines with unbroken chain-of-custody documentation.
View Module →Volatile evidence capture, memory acquisition with WinPmem and LiME, Volatility 3 analysis, and process reconstruction from RAM dumps.
View Module →File system artefact recovery, MFT analysis, slack space examination, super-timeline buildout with Plaso, and deleted artefact reconstruction.
View Module →Static and dynamic analysis, PE/ELF dissection, unpacking, disassembly with Ghidra, debugging with x64dbg, and YARA rule development for IOC extraction.
View Module →Questioned document examination, signature verification, forger trait identification, ACE-V methodology, and expert opinion construction.
View Module →Structuring expert forensic statements, qualifying opinions for admissibility, witness-box preparation, and handling adversarial cross-examination.
View Module →www.hacking101.com.au/forensic-analysis-101/Ready to start? Choose your module below or browse the full course catalogue.