Digital Evidence Acquisition and Rapid Triage
This digital forensics training in Toronto starts where every investigation starts: getting the evidence without breaking it. You practise dead-box imaging, live triage on running systems, write blocking, hashing and verification.
Classes run live in Eastern Time and suit people entering digital forensics and incident response (DFIR) work. You make acquisition decisions under time pressure, then document them so a reviewer, a regulator or opposing counsel can follow exactly what you did.
- Duration
- 6 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Create forensically sound disk images from powered-off systems and verify them by hash
- Decide when live acquisition is justified and capture volatile data in the right order
- Apply hardware and software write blocking correctly and prove it was in place
- Collect memory from Windows and Linux hosts without corrupting the target
- Document chain of custody from first contact through to secure storage
- Triage a suspect endpoint in under an hour and say what deserves deeper analysis
- Recognize when an acquisition method will fail and choose a defensible alternative
Course outline
6 modules
- What makes an acquisition defensible
- Chain of custody from first contact to storage
- Documentation that survives later challenge
- Scoping a collection request with legal and HR
- Canadian privacy considerations under PIPEDA
What you need before you start
- Comfort with Windows and basic command line use
- A computer with at least 16 GB of RAM and 100 GB of free disk space
- Virtualisation software such as VirtualBox or VMware installed
- A stable internet connection for the live sessions
Who this course is for
- IT staff asked to preserve evidence after a security incident
- New forensic analysts and junior incident responders
- Audit, HR and legal support staff who handle device collections
- SOC analysts who must collect evidence before escalating
- Investigators moving into digital evidence work
Where this leads
Prepares you for
CHFI
Awarded by EC-Council
The material maps to the acquisition and evidence handling domains of the Computer Hacking Forensic Investigator programme. We prepare you for that content, but the CHFI credential is granted by EC-Council once you sit their exam, never by this academy.
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



