Course ID: #N/A

EC-Council Computer Hacking Forensic Investigator (CHFI) v11

Duration: 5 days Dates: 30 November 2026 1 March 2027 14 June 2027 30 August 2027

The EC-Council CHFI course teaches you how to conduct digital forensic investigations methodically – from securing evidence and the chain of custody through acquisition, analysis and reporting to the legal requirements for admissibility in court. In addition to classic storage media and operating system forensics, the current version v11 covers network, malware, cloud, mobile, IoT and dark web forensics. The course prepares you for the CHFI 312-49 exam (the «Computer Hacking Forensic Investigator» certification).

Computer Forensics Today

  • Fundamentals and objectives of computer forensics, types of digital evidence
  • Forensic readiness in organisations
  • Legal frameworks and standards for digital evidence

The Forensic Investigation Process

  • Phases before, during and after an investigation
  • Securing and documenting evidence and maintaining the chain of custody
  • Preparing the investigation report and presenting findings in court

Hard Disks and File Systems

  • Structure of hard disks and SSDs, partitions and boot processes
  • Understanding and analysing file systems on Windows, Linux and macOS

Data Acquisition and Duplication

  • Live and offline acquisition, forensic image formats
  • Verifying data integrity with hash values, write protection during acquisition

Overcoming Anti-Forensics Techniques

  • Recovering deleted files and partitions
  • Detecting and bypassing password protection, encryption, steganography and other obfuscation techniques

Windows Forensics

  • Collecting volatile and non-volatile data, analysing memory
  • Analysing the registry, event logs, browser artefacts and metadata

Linux and Mac Forensics

  • Acquiring and analysing volatile and non-volatile data on Linux
  • Examining forensic artefacts and logs on macOS

Network Forensics

  • Collecting logs, correlating events and reconstructing attacks
  • Analysing network traffic, investigating incidents in wireless networks

Malware Forensics

  • Static and dynamic malware analysis in a controlled environment
  • Tracing malware behaviour on systems and in the network

Investigating Attacks on Web Applications

  • Analysing web server logs
  • Detecting and tracing attacks such as SQL injection, cross-site scripting and directory traversal

Dark Web Forensics

  • How the dark web and Tor work
  • Finding and analysing traces of Tor browser usage on systems

Cloud Forensics

  • Specifics and challenges of forensic investigations in the cloud
  • Investigations in Amazon Web Services (AWS) and Microsoft Azure

Email and Social Media Forensics

  • Analysing email headers and email histories, investigating email crimes
  • Acquiring and analysing evidence from social networks

Mobile Forensics

  • Logically and physically acquiring data from Android and iOS devices
  • Analysing and documenting mobile artefacts

IoT Forensics

  • Architecture and typical attacks on IoT devices
  • Forensic examination of IoT devices and related data sources
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/11/30, 2027/03/01, 2027/06/14, 2027/08/30, flexibel, auf Anfrage

IT security and forensics professionals, incident responders and SOC staff, as well as professionals from law enforcement, government agencies, the military, the legal sector, banks and insurance companies who investigate digital incidents.

Basic knowledge of IT security, computer forensics and incident response is required. Knowledge at the level of Certified Ethical Hacker (CEH) is an advantage.

After the course you will be able to:

  • plan forensic investigations and secure and document evidence so it is admissible in court
  • forensically acquire and analyse storage media, file systems and memory
  • detect anti-forensics techniques and recover deleted data
  • analyse traces on Windows, Linux and macOS systems and in networks
  • investigate malware, web attacks, and email and dark web traces
  • carry out investigations in cloud environments, on mobile devices and on IoT devices

CHF4'540 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation