Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Entry-level

Digital Evidence Acquisition and Rapid Triage

This digital forensics training in Toronto starts where every investigation starts: getting the evidence without breaking it. You practise dead-box imaging, live triage on running systems, write blocking, hashing and verification.

Classes run live in Eastern Time and suit people entering digital forensics and incident response (DFIR) work. You make acquisition decisions under time pressure, then document them so a reviewer, a regulator or opposing counsel can follow exactly what you did.

Duration
6 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
Digital Evidence Acquisition and Rapid Triage

What you will be able to do

  • Create forensically sound disk images from powered-off systems and verify them by hash
  • Decide when live acquisition is justified and capture volatile data in the right order
  • Apply hardware and software write blocking correctly and prove it was in place
  • Collect memory from Windows and Linux hosts without corrupting the target
  • Document chain of custody from first contact through to secure storage
  • Triage a suspect endpoint in under an hour and say what deserves deeper analysis
  • Recognize when an acquisition method will fail and choose a defensible alternative

Course outline

6 modules

  • What makes an acquisition defensible
  • Chain of custody from first contact to storage
  • Documentation that survives later challenge
  • Scoping a collection request with legal and HR
  • Canadian privacy considerations under PIPEDA

What you need before you start

  • Comfort with Windows and basic command line use
  • A computer with at least 16 GB of RAM and 100 GB of free disk space
  • Virtualisation software such as VirtualBox or VMware installed
  • A stable internet connection for the live sessions

Who this course is for

  • IT staff asked to preserve evidence after a security incident
  • New forensic analysts and junior incident responders
  • Audit, HR and legal support staff who handle device collections
  • SOC analysts who must collect evidence before escalating
  • Investigators moving into digital evidence work

Where this leads

Prepares you for

CHFI

Awarded by EC-Council

The material maps to the acquisition and evidence handling domains of the Computer Hacking Forensic Investigator programme. We prepare you for that content, but the CHFI credential is granted by EC-Council once you sit their exam, never by this academy.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.