CSA, Certified SOC Analyst
Detection and investigation are two halves of the same job; most DFIR practitioners hold both.
View courseWhen an incident is over, someone has to establish what actually happened, prove it with evidence that holds up, and document it for legal, regulatory or insurance scrutiny. The Computer Hacking Forensic Investigator programme trains you for that role across 40 hours of investigative technique.
Forensics is the most procedurally strict discipline in security. Chain of custody, write-blocking, hashing and documentation are not bureaucracy. They are the difference between an investigation that stands up and one that is thrown out. The course treats process with the same seriousness as technique.
CHFI-trained professionals work in Digital Forensics, DFIR, Incident Investigation, e-Discovery and internal fraud investigation roles.
Every module pairs instruction with lab work. You practise the technique in the same session you learn it.
| 01. Digital forensics process and legal framework Evidence admissibility, the Indian legal context, and the investigator's obligations. |
| 02. Chain of custody and evidence handling Acquisition, write-blocking, hashing and documentation that survives challenge. |
| 03. Disk and file system forensics Recovering deleted data, understanding artefacts, and reconstructing user activity. |
| 04. Windows and Linux artefact analysis Registry, event logs, prefetch, shell history and the traces attackers forget. |
| 05. Memory forensics Capturing and analysing volatile evidence before it disappears. |
| 06. Network forensics Reconstructing activity from packet captures and flow records. |
| 07. Malware analysis fundamentals Safe handling, static and behavioural triage of suspicious binaries. |
| 08. Anti-forensics and evidence tampering Recognising deliberate obstruction and what can still be recovered. |
| 09. Investigation reporting and expert testimony Writing findings for readers who are not technical and may be adversarial. |
Batch dates vary; the sequence does not. Weekday, weekend and evening formats cover the same blocks.
| Block | Hours | Focus |
|---|---|---|
| Sessions 1-2 | 8 hrs | Forensic process, legality and evidence handling Admissibility, the investigator's obligations, chain of custody, acquisition, write-blocking and hashing. |
| Sessions 3-4 | 8 hrs | Disk and file system forensics Recovering deleted data, interpreting artefacts and reconstructing user activity from storage. |
| Sessions 5-6 | 8 hrs | Windows and Linux artefact analysis Registry, event logs, prefetch, shell history, the traces attackers routinely fail to clear. |
| Sessions 7-8 | 8 hrs | Memory, network and malware forensics Capturing volatile evidence, reconstructing activity from packet data, and safe malware triage. |
| Sessions 9-10 | 8 hrs | Anti-forensics, reporting and testimony Recognising deliberate obstruction, and writing findings for readers who may be non-technical and adversarial. |
| Tool | Used for |
|---|---|
| FTK Imager | Forensic acquisition and image verification |
| Autopsy / Sleuth Kit | Disk and file system examination |
| Volatility | Memory image analysis |
| Registry and artefact viewers | Windows host activity reconstruction |
| Wireshark | Network evidence reconstruction |
| Hashing and integrity tooling | Evidence verification and chain of custody |
| Exam code | 312-49, Computer Hacking Forensic Investigator |
| Current version | CHFI v11 |
| Format | Multiple choice, proctored |
| Question count and duration | Confirm current specification at enrolment |
| Certification validity | 3 years, renewable via EC-Council ECE credits |
Detection and investigation are two halves of the same job; most DFIR practitioners hold both.
View courseKnowing how intrusions are executed makes you faster at reconstructing them after the fact.
View courseTwo groups: SOC and incident response practitioners specialising into DFIR, and professionals in audit, compliance, legal or internal investigations who need to handle digital evidence correctly. A security fundamentals background is expected.
Yes. Regulatory reporting requirements, cyber insurance claims and internal fraud investigations all generate demand for people who can establish what happened and prove it. The specialism is smaller than SOC work but competition for roles is correspondingly lower.
The programme addresses evidence admissibility and the investigator's professional obligations, including how the Information Technology Act frames electronic evidence. It is training in forensic practice, not legal advice, case-specific questions belong with a qualified lawyer.
40 hours, available at our Marathahalli centre in Bengaluru and online, with weekend batches for working professionals.
Core cyber security fundamentals spanning endpoints, networks, web security, IAM, SOC and governance.
View courseBeginner-to-job-ready programme with live labs, SOC operations, ethical hacking and compliance coverage.
View courseEthical hacking fundamentals covering reconnaissance, exploitation, reporting, tooling and attacker methodology.
View courseSOC-focused training on SIEM fundamentals, alert triage, incident workflows and security operations.
View courseAdvanced offensive security: simulate real attacks to identify and prove exploitable weaknesses.
View courseSpeak to a counsellor about batch dates, fees and whether this course fits your current background. No obligation, no sales pressure.