Practitioner-led digital course · Africa
Digital Forensics & Incident ResponseFoundations
Learn to make good first-response decisions, protect digital evidence, rebuild incident activity and report clear findings through a five-day guided investigation.
Learning outcomes
What participants will be able to do.
The course builds good judgement and repeatable methods, not only tool demonstrations.
- 01
Plan a first response that protects digital files and records.
- 02
Identify and prioritise relevant digital evidence sources.
- 03
Use safe methods to collect, check and examine digital evidence.
- 04
Build a confirmed incident timeline and explain what the evidence cannot show.
- 05
Communicate findings clearly to technical and non-technical decision-makers.
Five-day pathway
One investigation. Increasing complexity.
Each module continues the same guided case. This helps learners connect technical actions to the full incident response.
Day 01First response & evidence integrity+
- Incident roles, authority and decision boundaries
- Evidence identification and preservation priorities
- Chain of custody and contemporaneous records
- Live-system considerations and common first-response errors
Day 02Acquisition & forensic readiness+
- Forensically sound collection principles
- Disk, memory, log, email and cloud evidence sources
- Hashing, verification and working-copy discipline
- Building an evidence inventory and examination plan
Day 03File and record examination+
- User, file-system and application records
- Browser, communication and persistence indicators
- Log correlation and source reliability
- Separating observations, inferences and conclusions
Day 04Timeline & incident reconstruction+
- Building and testing a working chronology
- Confirming activity across several sources
- Identifying gaps, contradictions and alternative explanations
- Scoping impact and follow-on collection requirements
Day 05Findings, reporting & response+
- Writing clear technical findings supported by evidence
- Executive briefings and incident decision support
- Priority fixes and lessons learned
- Capstone case presentation and practitioner feedback

Final learning lab
A case that evolves as the evidence changes.
Learners respond to an insider threat and data theft case. New evidence arrives during the week. They must update their ideas, explain what they collected and brief a simulated incident team.
Designed for
Professionals learning to respond with evidence.
Best suited to
- Cybersecurity and SOC practitioners
- Digital forensic and investigation teams
- Internal audit and technology-risk professionals
- Incident coordinators and technical managers
Recommended preparation
- Basic familiarity with operating systems and networks
- Comfort working with technical records and logs
- No prior forensic certification required
- A laptop capable of running the supplied lab environment
Knowledge checks
Short daily checks reinforce principles and expose gaps early.
Practical work
Participants produce an evidence plan, timeline and finding set.
Capstone briefing
The case concludes with a concise technical and executive briefing.
Completion record
Participants receive a SIFTCON Academy certificate of completion.
Course questions
Before you book a group.
Can the programme be delivered in-house?
Yes. We can run a private group course and adapt it to your roles, policies and technology.
Is this an accredited certification?
No. Learners receive a SIFTCON Academy certificate of completion.
Can leaders attend selected modules?
Yes. We can add a short leadership briefing or table-top exercise without requiring leaders to attend the full technical course.
Bring the course to your team
