Computer Forensics Fundamentals | Online Course Skip to main content
Online Courses › Computer Forensics Fundamentals
10 Hours, Online Self-Paced

Computer Forensics Fundamentals

Windows, macOS, and Linux forensic acquisition and analysis, including memory forensics, Windows Registry, event logs, cloud storage artifacts, and anti-forensics detection. Designed for practitioners who handle real evidence, write real reports, and testify in real cases. 15 modules, 36 lessons, module quizzes, and a final assessment.

🌐 Developed by Eric L. Waldrep, U.S. State Dept. ATA Cyber Mentor · MCFE Certified · 19+ Years Active Casework
$497
per seat · agency licensing available
Duration10 hrs
FormatOnline Self-Paced
Modules15 modules
Lessons36 lessons
Tools (educational)Autopsy, FTK, X-Ways, AXIOM
CPE Credits10 CPEs
CertificateYes
✅ You're enrolled. Go to Course →

No account needed. Checkout takes an email address and your access is set up right after payment.

🛡️ 30-Day Look Guarantee
Or take the full curriculum
This course alone is $497. All-Access is $2,997 for all four courses ($4,488 purchased separately): 86 CPE hours and four verifiable certificates. For 90 days after you enroll here, your tuition credits in full toward All-Access. View All-Access →
Request Group Pricing Government PO / Net-30

Procurement pack, W-9 and rate card on request. Download the Training Procurement Pack (PDF).

Secure checkout via Stripe. Instant access after payment confirmation. Government PO and net-30 billing available by request.

Free Download · PDF

Not ready to enroll? Get the full syllabus.

Every module and lesson in Computer Forensics Fundamentals, plus pricing, CPE, and certificate details. Enter your email and download the PDF instantly. No spam, no sales calls.

Prefer to talk? Call (251) 216-1164 or request group / agency pricing above.

What You'll Learn

Establish legal authority before any examination: consent, warrants, and corporate authorization
Perform forensically sound dead-box and live acquisitions with write blockers and hash verification
Analyze Windows NTFS artifacts: MFT, $UsnJrnl, MACE timestamps, and deleted file recovery
Recover volatile evidence from memory images using Volatility 3 and interpret process, network, and credential artifacts
Parse Windows Registry hives to surface execution artifacts: Shimcache, AmCache, Prefetch, SRUM, and UserAssist
Analyze Windows Event Logs and correlate key Event IDs for logon activity, privilege escalation, and persistence
Identify cloud storage sync artifacts and detect anti-forensics activity including secure deletion and timestomping
Extract and interpret browser history, email artifacts, and user activity from Windows and macOS
Identify USB connection artifacts and connect device usage to specific users via registry and LNK files
Build defensible event timelines from multiple artifact sources without timestamp interpretation errors
Operate Autopsy, FTK, X-Ways, and Magnet AXIOM workflows and cross-validate critical findings across tools
Write court-ready forensic reports that separate findings from opinions and withstand cross-examination

Built for Practitioners

Not an academic overview. This course is designed for professionals who will use this knowledge in real cases, real courts, and real investigations.

🚔
Law Enforcement
⚖️
Attorneys & Paralegals
🏛️
Government Agencies
🪖
Military & Intelligence
🏢
Corporate Security
🔍
Private Investigators
🧪
Forensic Examiners
📋
Compliance Teams

15 Modules  ·  36 Lessons  ·  Final Assessment

01Computer Forensics Foundations
  • What Computer Forensics Is
  • Civil, Criminal, Corporate & Legal Use Cases
  • Digital Evidence Concepts
  • Forensic Soundness
  • Common Mistakes
✓ Module Quiz
02Legal Authority, Ethics & Scope
  • Consent, Warrants & Court Orders
  • Corporate Authorization & Private-Sector Scope
  • Scope Control & Documentation Requirements
03Evidence Handling & Chain of Custody
  • Evidence Intake & Labeling
  • Storage, Hashing & Chain-of-Custody Records
04Acquisition Fundamentals
  • Live vs. Dead-Box Acquisition
  • Imaging Concepts & Validation
  • Write Blockers & Image Formats
05File System Artifacts
  • Windows File System Artifacts (NTFS, MFT, $UsnJrnl, MACE)
  • macOS File System Artifacts
  • Linux File Systems
  • File Carving Techniques
06Memory Forensics
  • Volatile Memory Concepts & Acquisition
  • Volatility Analysis
07Windows Registry Forensics
  • Registry Architecture & Hive Structure
  • Key Registry Artifacts
  • Execution Artifacts (Prefetch, Shimcache, AmCache, SRUM)
08Windows Event Logs
  • Event Log Architecture & EVTX Format
  • Key Event IDs (Logon, Account Management, Privilege, Persistence)
09Browser, Email & User Activity
  • Browser Artifacts (Chrome, Firefox, Edge)
  • Email Artifacts (PST, OST, headers)
10Cloud Storage & Anti-Forensics
  • Cloud Storage Sync Artifacts (OneDrive, Dropbox, Google Drive)
  • Anti-Forensics Detection (Secure Deletion, Timestomping, Log Clearing)
11USB & External Device Activity
  • USB Connection Artifacts & User Attribution
12Timeline Reconstruction
  • Building a Defensible Timeline
13Analysis Workflow & Tool Validation
  • Autopsy Workflow
  • FTK & X-Ways; Cross-Tool Validation
  • Magnet AXIOM Workflow
14Reporting & Court Readiness
  • Forensic Report Structure
  • Expert Witness Testimony Preparation
15Final Assessment
  • Course Review & Key Takeaways
★ Final Knowledge Quiz  ·  Certificate of Completion

What Your Seat Includes

1
The Computer Forensics Curriculum. 15 modules and 36 lessons across Windows, macOS, and Linux: acquisition, file systems, memory, registry, event logs, cloud artifacts, anti-forensics, and court-ready reporting.
2
The Examiner Reference Library. 14 downloadable references, checklists, and forms, including evidence intake and chain-of-custody forms, an acquisition decision matrix, and artifact references you will use on the bench.
3
Module knowledge checks and the final assessment. A check for every module, then a final assessment that gates the certificate.
4
The Certificate of Completion. 10 CPE hours and a public verification URL for your training file.
5
12 months of access. All curriculum updates during your window included.
The live classroom courses covering this material run $2,295 to $3,295 per seat on our published training calendar. Your seat, self-paced: $497.

Developed by the Practitioner Who Built It

Eric L. Waldrep
Eric L. Waldrep
Director of Training, The Waldrep Company  |  U.S. State Dept. ATA Cyber Mentor  |  MCFE Certified

Eric Waldrep has been in law enforcement for 27 years and active digital forensics for 19+ years. He has testified as an expert in federal and state courts. Selected by the U.S. State Department's Antiterrorism Assistance (ATA) program as a Cyber Mentor, training allied nation law enforcement in digital forensics. Every module in this course comes directly from real casework, not textbook scenarios.

MCFE Certified
State Dept. ATA Cyber Mentor
19 years forensics
27 years law enforcement

Certificate of Completion

🎓
Certificate of Completion, The Waldrep Company

Students who complete all 15 modules and the final assessment receive a Certificate of Completion from The Waldrep Company, issued in the student's name and signed by Eric L. Waldrep. The certificate includes course title, completion date, and course duration.

Note: This is a Certificate of Completion from The Waldrep Company. It does not constitute a third-party forensic certification such as MCFE or CCPA.

Frequently Asked Questions

What access do I get after purchasing?
Immediate access to all 15 modules and 36 lessons after Stripe payment confirmation. Access is tied to your student account and available on any device.
How does this online course compare to the live 3-day cohort?
The online course covers the same topics, the same practitioner-authored content, and earns 10 CPE credits. It runs 10 hours of focused, self-paced instruction. The live 3-day cohort runs 24 hours and adds instructor-guided hands-on lab work, group exercises, and real-time Q&A. Choose the online format for concept mastery on your schedule; choose the live cohort if you want guided lab time and live instruction.
Do I need forensic tools installed to take this course?
No tool installation is required to complete the course. The course covers Autopsy, FTK, X-Ways, and Magnet AXIOM workflows through detailed written instruction and concept-based lessons. Autopsy is free and open-source if you wish to follow along.
Can my agency purchase seats via purchase order?
Yes. Government purchase orders and net-30 invoicing are accepted. Contact us at (251) 216-1164 or submit an inquiry to arrange PO-based enrollment.
Do you offer group pricing?
Yes. Agency pricing is 25% off at 5 or more seats. Contact us to arrange group enrollment and invoicing.
Is a refund available?
Two guarantees, in plain language. The 30-Day Look: enroll, open every module, download the templates, and if within 30 days you decide the course is not right for your work, email info@thewaldrepcompany.com for a full refund. One condition, for the integrity of the credential: a refund revokes any certificate issued for this course and removes it from the public verification registry. The Pass Commitment: complete every lesson and module quiz inside your 12-month window and attempt the final exam, and if you cannot pass, we extend your access at no charge and point you to exactly what to restudy until you do. What we do not guarantee: that any court will qualify you as an expert witness, that any specific agency will accept this training for a particular purpose, or any case outcome. Nobody can honestly guarantee those things, and you should be careful with anyone who does. See the full refund policy.

This course is provided for educational purposes only. References to commercial forensic products (including but not limited to Autopsy, FTK®, X-Ways®, and Magnet AXIOM®) are made solely to illustrate concepts, methodologies, and publicly documented workflows that practitioners may encounter in the field.

Discussion of any specific tool is not intended as, and shall not be construed as: (i) an endorsement, recommendation, or comparative evaluation of one product over another; (ii) operational training, certification, or qualification in the use of that product; (iii) an authoritative statement of any vendor's current capabilities, features, version behavior, or pricing; or (iv) the disclosure of confidential, proprietary, or non-public information. This course is not a substitute for the vendor-provided training and certification required to operate any specific tool.

All tool references rely exclusively on information made publicly available by the respective vendors or in published literature. All trademarks, product names, and registered marks are the property of their respective owners and are used herein for identification and educational purposes only. The Waldrep Company is not affiliated with, sponsored by, or endorsed by any of the tool vendors mentioned in this course.

Certificate Disclaimer. The Certificate of Completion issued by The Waldrep Company evidences that the holder completed the course curriculum and passed the required assessments. It is not a license, an accreditation, a government or POST certification, vendor certification, or a guarantee that any specific court will qualify the holder as an expert witness under Daubert, Kumho, Frye, or any state analogue. Whether a witness is qualified in a specific matter is a determination reserved to the trial court in that matter. See our Terms of Service for full details.

Ready to Get Started?

Enroll online now, request group pricing, or contact us to discuss government PO billing and custom on-site delivery.

Request Group Pricing

Government PO · Net-30 billing · 25% off 5 or more seats · Custom on-site delivery · (251) 216-1164

Free syllabus