Skip to content
CBT Nuggets
DemoBook a Demo

Digital Forensics and Computer Examiner Training

This digital forensics training teaches you how to collect, preserve, and analyze digital evidence with confidence. You’ll master skills in digital forensics and incident response, from recovering artifacts in memory and unallocated space to analyzing network traffic and hidden data. Explore tools like hex editors, registry analyzers, and steganography software to uncover what others miss. Whether you’re training to become a digital forensics examiner, advancing as a digital forensic analyst, or building computer examiner training into your team’s skill set, this course gives you the legal, ethical, and technical know-how to succeed. You’ll learn proper chain of custody, expert witness testimony, and lab setup for professional investigations.

Updated December 2024

15Skills
124Videos
12hTotal

Who This Course Is For

This training is considered professional-level digital forensics training, which means it was designed for digital forensic investigators. This digital forensics skills course is designed for digital forensic investigators with three to five years of experience with cybersecurity.

Skills Your Team Will Gain

  • Recover artifacts from memory dumps, unallocated space and hidden streams
  • Use hex editors, registry tools and steganography software to find hidden data
  • Analyze network traffic and wireless signals to trace intrusions
  • Preserve evidence and maintain chain of custody under legal guidelines
  • Set up forensic labs using virtualization, imaging and open‑source tools
  • Communicate findings clearly through reports and expert testimony

Course Curriculum

One skill is free to watch — no signup needed. The other 14 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Metasploit Framework

Erik ChoronDuration: 49m14 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Premium skill.Digital Forensics Introduction46m · 14 videos
  • Premium skill.Chain of Custody46m · 15 videos
  • Premium skill.Software Loadout50m · 11 videos
  • Premium skill.Installing and Configuring Kali52m · 14 videos
  • Premium skill.Monitoring with Kali57m · 15 videos
  • Metasploit FrameworkFree49m · 14 videos
  • Premium skill.Looking at the Files45m · 10 videos
  • Premium skill.File Steganography45m · 12 videos
  • Premium skill.Digital Artifacts within Windows47m · 12 videos
  • Premium skill.Unallocated Artifacts within Windows1h 1m · 17 videos
  • Premium skill.Examining Unallocated Data46m · 13 videos
  • Premium skill.Examining Volatile Memory49m · 13 videos
  • Premium skill.Learning About Our System with Volatility45m · 13 videos
  • Premium skill.Analyze RAM while Learning Volatility52m · 16 videos
  • Premium skill.Federal Rules of Evidence49m · 16 videos
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security incidents create both technical and legal risk when evidence is collected inconsistently or reported without a defensible process. IT Directors can assign this professional-level course to digital forensic investigators, incident response staff, or senior security practitioners with roughly 3–5 years of cybersecurity experience who need a shared workflow for collecting, preserving, analyzing, and reporting digital evidence.

The course is about 12 hours and 20 minutes per learner, making it realistic for a focused upskilling sprint or phased rollout across an investigations team. It covers chain of custody, Kali setup and monitoring, Windows artifacts, unallocated data, volatile memory analysis with Volatility, steganography, and Federal Rules of Evidence. For change management, Team Leads should align learners on internal evidence-handling procedures before applying these skills in live investigations. CBT Nuggets Playlists and Team Reporting help Training Managers assign the course, monitor progress, and verify completion across the team.

Team Impact

How this training helps your team succeed

IT teams complete this training to make forensic investigations more consistent, defensible, and useful during security incidents or legal review. The course connects evidence handling with practical examination tasks across systems, files, memory, and network behavior.

  • Reduce investigation risk: Teams learn chain of custody concepts and Federal Rules of Evidence considerations that support defensible evidence handling.
  • Improve incident reconstruction: Investigators examine Windows artifacts, unallocated data, files, and volatile memory to better understand what happened on a system.
  • Strengthen response readiness: Practitioners work through Kali setup, monitoring, and Metasploit-related concepts so they can recognize and investigate security activity more effectively.
  • Find hidden or deleted evidence: Teams study file steganography and unallocated artifacts, helping investigators look beyond active files when reviewing compromised systems.

After completion

Capabilities your team walks away with

Knowledge

  • Core digital forensics concepts, including evidence collection, preservation, analysis, and reporting
  • Chain of custody requirements and why documentation matters during investigations
  • How Windows artifacts, unallocated space, and volatile memory can support incident analysis
  • How file steganography can hide data during an investigation
  • Federal Rules of Evidence concepts relevant to digital evidence handling

Ability

  • Follow a more consistent workflow for handling and documenting digital evidence
  • Install and configure Kali for investigation-related monitoring tasks
  • Examine files, Windows artifacts, unallocated data, and RAM for forensic clues
  • Use Volatility concepts to learn about a system and analyze memory captures
  • Communicate findings in a way that supports technical review and legal or compliance stakeholders

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

Kali Linux Revealed (PEN-103)

Master Kali Linux, earn your KLCP certification, and prepare for the the PEN-103 exam. This associate-level Kali Linux Certified Professional course dives deep into penetration testing, perfect for cybersecurity pros like pentesters and network secur...

~6h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$169one time

No subscription

One year of access to Digital Forensics

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

What is digital forensics and computer examination?

Digital forensics and computer examination both deal with investigating and analyzing electronic devices and digital data while searching for evidence of crimes or for private purposes. Digital forensics is mostly about using specialized techniques for recovering, analyzing and then preserving electronic information. Computer examination is more focused on scrutinizing hardware and devices. Both involve identifying and examining digital artifacts like files, logs, and metadata and trying to reconstruct events and establish a timeline of activities.

How do I become a digital forensic examiner?

Becoming a digital forensic examiner is not an easy path, but it is possible. Like many jobs in IT, it's very difficult to get an entry-level job without experience, but it's nearly impossible to get entry-level experience without a job. The mandatory step in becoming a digital forensic examiner is learning hands-on and applicable skills of the job and getting realistic experience with using them from a course like this.

Can you do digital forensics without a degree?

It is possible to do digital forensics without a degree, but there's no denying that a bachelors or masters degree in computer sciences is helpful. Some digital forensics positions require a degree – and it'll be hard to persuade them otherwise. But plenty of positions accept certifications, first-hand experience, and portfolios of projects as ways for a candidate to prove their familiarity with the tools and processes of digital forensic examination.

Is it worth it to learn digital forensics and computer examination?

Yes, learning digital forensics and computer examination is worthwhile, even if you don't plan to pursue it as your career. The skills you'll learn from this course provide a valuable understanding of cybersecurity, data integrity, and investigative techniques. Our world is increasingly digital, understanding digital forensics gives you the ability to protect information while detecting cyber threats. Plus, forensics is fundamentally about analysis and problem-solving, deeply valuable professional skills.

What digital forensics and computer examiner certifications are there?

There are a number of different certifications that you can earn to help your chances of landing a digital forensics or computer examiner position. The skills in this course cover many of the objectives outlined in the Basic Computer Forensic Examiner (BCFE) & Certified Forensic Computer Examiner (CFCE) certifications from IACIS. Advanced Check Point certifications like the CCSM cover a deep familiarity with their hardware and investigative skills. The Fortinet family of certifications explore increasingly deep levels of familiarity with advanced cybersecurity hardware. And CompTIA's CySA+, CASP+ and PenTest+ all include skills that are essential for digital forensics examiners.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.