| 1. Introduction to Digital Forensics |
Definition; investigation types; forensic lifecycle |
| 2. Legal and Ethical Context |
UK legal framework; ACPO principles; professional conduct |
| 3. Digital Evidence Fundamentals |
Evidence types; volatility; evidential integrity |
| 4. Evidence Handling and Preservation |
Chain of custody; documentation; write protection |
| 5. Hashing and Integrity Verification |
Hash functions; verification; repeatability |
| 6. Forensic Acquisition |
Live and dead acquisition; disk and memory imaging |
| 7. File Systems and Storage Forensics |
File systems; metadata; deleted data |
| 8. Disk Image Analysis |
User activity artefacts; application traces |
| 9. Memory (RAM) Forensics |
Processes; network artefacts; volatile evidence |
| 10. Operating System Artefacts |
Registry; event logs; device history |
| 11. Email Forensics |
Email headers; message content; artefact analysis |
| 12. Timeline Analysis |
Timeline construction; evidence correlation |
| 13. Forensic Reporting |
Report structure; defensible conclusions |
| 14. Professional Presentation |
Evidence presentation; expert witness principles |