Secure your place for the October 2026 intake.



EC07 - Forensics

From digital evidence to operational defence in real-world security environments.

Credits

7.5 ECTS

Semester

2 Semester

Delivery

Online

Duration

13 weeks

Language

English

About This Course

This is a second-semester course in the MBA in Advanced Cybersecurity Technologies &
Governance
This course introduces students to digital forensics and modern Security Operations Centre practices as they are applied in real-world environments. It focuses on evidence acquisition and analysis, disk and memory forensics, incident response, SIEM operations, threat intelligence, and detection engineering. Through hands-on exercises and realistic scenarios, students learn how to investigate cyber incidents, support active defence operations, and communicate findings clearly and responsibly.

What You Will Learn


Digital Forensics Foundations

  • Principles of digital evidence collection and analysis
  • Disk, memory, and file system forensics
  • Role of forensics in cyber investigations


SOC Operations & Threat Detection

  • Structure and workflows of Security Operations Centers (SOC)
  • SIEM platforms and detection engineering
  • Threat intelligence frameworks such as MITRE ATT&CK


Advanced Investigation & AI in Security

  • Incident response lifecycle and threat hunting

  • AI and automation in cyber defence

  • Real-world forensic and SOC scenarios

Your 13-Week Journey

Here’s how your learning unfolds

Week 1 – Digital Forensics Foundations

Core principles of digital forensics, evidence lifecycle, and chain of custody.

Week 2 – Data Acquisition and File Analysis

Disk imaging, filesystem structures, metadata, artefacts, and hashing techniques.

Week 3 – Windows Native Artifacts I

Key Windows artefacts including Registry, Event Logs, and Prefetch files.

Week 4 – Windows Native Artifacts II

Advanced analysis of Windows artefacts such as LNK files and Jump Lists.

Week 5 – Web Browser Forensics

Analysis of Chrome and Firefox history, downloads, and user activity.

Week 6 – Advanced Forensic Domains

Forensic challenges in cloud, mobile, IoT, and emerging environments.

Week 7 – Security Operations Centre Fundamentals

SOC structure, analyst roles, workflows, and core security tooling.

Week 8 – SIEM Operations and Alert Handling

Log ingestion, alert triage, and investigation using SIEM platforms.

Week 9 – Incident Response Lifecycle

Incident handling processes and forensic triage image analysis.

Week 10 – Memory Forensics and Malware Analysis

Memory acquisition and analysis for detecting malicious activity.

Week 11 – Threat Intelligence and CTI

Threat intelligence lifecycles, platforms, and adversary profiling.

Week 12 – Threat Hunting and Detection Engineering

Hypothesis-driven hunting, ATT&CK mapping, and detection rule creation.

Week 13 – AI and SOC Automation

Applying AI and automation to alert triage, phishing detection, and SOC workflows.


Empty space, drag to resize

Skills You Will Gain

Digital Forensic Investigation

  • Acquiring and analysing digital evidence
  • Performing memory and disk forensic analysis
  • Maintaining chain-of-custody and legal compliance

Detection & Threat Hunting

  • Developing detection rules (Sigma, YARA)
  • Using SIEM tools for deep investigations
  • Automating workflows with scripting and SOAR

Incident Response Leadership

  • Leading investigations and response operations
  • Coordinating with legal and law enforcement
  • Producing professional forensic reports