Course and programme enquiriesforensics@siftcon.africa

Practitioner-led digital course · Africa

Digital Forensics & Incident ResponseFoundations

Learn to make good first-response decisions, protect digital evidence, rebuild incident activity and report clear findings through a five-day guided investigation.

Duration5 days
LevelFoundation
FormatInstructor-led lab
Class sizeUp to 18

Learning outcomes

What participants will be able to do.

The course builds good judgement and repeatable methods, not only tool demonstrations.

  1. 01

    Plan a first response that protects digital files and records.

  2. 02

    Identify and prioritise relevant digital evidence sources.

  3. 03

    Use safe methods to collect, check and examine digital evidence.

  4. 04

    Build a confirmed incident timeline and explain what the evidence cannot show.

  5. 05

    Communicate findings clearly to technical and non-technical decision-makers.

Five-day pathway

One investigation. Increasing complexity.

Each module continues the same guided case. This helps learners connect technical actions to the full incident response.

Day 01First response & evidence integrity
  • Incident roles, authority and decision boundaries
  • Evidence identification and preservation priorities
  • Chain of custody and contemporaneous records
  • Live-system considerations and common first-response errors
Day 02Acquisition & forensic readiness
  • Forensically sound collection principles
  • Disk, memory, log, email and cloud evidence sources
  • Hashing, verification and working-copy discipline
  • Building an evidence inventory and examination plan
Day 03File and record examination
  • User, file-system and application records
  • Browser, communication and persistence indicators
  • Log correlation and source reliability
  • Separating observations, inferences and conclusions
Day 04Timeline & incident reconstruction
  • Building and testing a working chronology
  • Confirming activity across several sources
  • Identifying gaps, contradictions and alternative explanations
  • Scoping impact and follow-on collection requirements
Day 05Findings, reporting & response
  • Writing clear technical findings supported by evidence
  • Executive briefings and incident decision support
  • Priority fixes and lessons learned
  • Capstone case presentation and practitioner feedback
An analytics screen representing the course investigation lab.

Final learning lab

A case that evolves as the evidence changes.

Learners respond to an insider threat and data theft case. New evidence arrives during the week. They must update their ideas, explain what they collected and brief a simulated incident team.

Alert→Preserve→Examine→Brief

Designed for

Professionals learning to respond with evidence.

Best suited to

  • Cybersecurity and SOC practitioners
  • Digital forensic and investigation teams
  • Internal audit and technology-risk professionals
  • Incident coordinators and technical managers

Recommended preparation

  • Basic familiarity with operating systems and networks
  • Comfort working with technical records and logs
  • No prior forensic certification required
  • A laptop capable of running the supplied lab environment
01

Knowledge checks

Short daily checks reinforce principles and expose gaps early.

02

Practical work

Participants produce an evidence plan, timeline and finding set.

03

Capstone briefing

The case concludes with a concise technical and executive briefing.

04

Completion record

Participants receive a SIFTCON Academy certificate of completion.

Course questions

Before you book a group.

Can the programme be delivered in-house?

Yes. We can run a private group course and adapt it to your roles, policies and technology.

Is this an accredited certification?

No. Learners receive a SIFTCON Academy certificate of completion.

Can leaders attend selected modules?

Yes. We can add a short leadership briefing or table-top exercise without requiring leaders to attend the full technical course.

Bring the course to your team

Shape the scenario around your real response environment.

Talk to the Academy
Talk to the AcademyWhatsApp us
WhatsApp