NDG Online · Foundational course

Digital Forensics Essentials

From evidence to courtroom. The digital evidence course built for the justice system.

No technical background required.

Download the course overview (PDF)
22–26 hours 12 modules Browser-based labs No technical background

Digital evidence is in nearly every case. Are you ready for it?

Phones, cameras, smart speakers, and GPS data now sit at the center of investigations and trials. Digital Forensics Essentials (DFE-101) gives the people who encounter, handle, adjudicate, or prosecute these cases the practical literacy to work with digital evidence confidently, using plain language, real-world case studies, and hands-on labs. It is the foundational cornerstone of NDG's digital forensics curriculum.

Who it's for

Built for the people who work with digital evidence

  Law enforcement

Patrol officers, first responders, detectives, and investigators who encounter devices at the scene.

  Prosecutors and attorneys

Cyber crime prosecutors, assistant DAs, federal prosecutors, and defense attorneys handling digital evidence.

  Judges and magistrates

Judicial officers who rule on warrants, admissibility, and the weight of digital evidence.

  Forensic paralegals

Paralegals and litigation staff who prepare, organize, and manage digital evidence.

  Legal tech and eDiscovery

Legal technology consultants and eDiscovery attorneys who need fluency in digital evidence.

  Investigators and new practitioners

Insurance and fraud investigators, plus learners entering digital forensics.

No prior technical or forensics experience required, just basic computer literacy.

Evidence domains

The evidence you'll work with

Modern investigations turn on the devices people carry, drive, and live with. In DFE-101 you examine the evidence domains that show up in real cases, in a safe browser-based virtual lab.

A smartphone in an evidence bag, a smart speaker, a video doorbell, a GPS unit, and a body camera laid out on a steel lab table, each with an evidence label

Mobile devices

Call logs, messages, photos, app data, and location history from smartphones and tablets.

Video evidence

CCTV, body cameras, dashcams, and doorbell footage: metadata, timestamps, and authentication.

IoT and smart devices

Smart speakers, video doorbells, and home automation logs, and where that data actually lives.

Vehicle and location

License plate readers, GPS tracking, and cell-site location data, including the law that governs them.

A dedicated module covers AI and emerging technology: AI-assisted analysis, deepfake detection, and the reliability of AI-generated evidence.

What you'll do

From the crime scene to the courtroom

DFE-101 follows digital evidence through its entire life cycle, so you understand not just what the evidence is, but how it holds up when it matters most.

  •   Identify digital evidence across mobile, video, IoT, and location domains
  •   Apply the legal frameworks that govern collection (Fourth Amendment, ECPA, SCA, and Carpenter)
  •   Follow first-responder protocols so evidence isn't lost or excluded
  •   Draft warrant language for phones, cloud accounts, IoT devices, and location data
  •   Recognize how evidence is authenticated and challenged under Daubert and Frye
  •   Examine evidence with foundational forensic tools in a guided environment

  Tools you'll use

You work in a real forensic workstation that runs in your browser. Nothing to install.

Autopsy running in the browser-based lab, showing thumbnails of photo evidence recovered from a simulated mobile device case
  •   Autopsy: disk image and device analysis
  •   ExifTool: metadata extraction
  •   MediaInfo: video and audio analysis
  •   SQLite Browser: mobile app databases

All evidence is fictional and synthetic. Labs run fully sandboxed, with no real case data.

Curriculum

What's inside: 12 modules, 22–26 hours

Each module pairs plain-language instruction with guided and applied lab exercises and a quiz. The course finishes with an end-to-end case simulation.

1 Introduction to digital forensics
2 The digital evidence landscape
3 Legal frameworks for digital evidence
4 First responder protocols
5 Mobile device evidence
6 Video evidence
7 IoT and smart device evidence
8 Vehicle tracking and location data
9 Drafting warrants for digital evidence
10 AI and emerging technology in digital forensics
11 Digital evidence in the courtroom
12 Comprehensive review and case simulation
DFE-101 coursebook in the browser: chapter navigation beside a plain-language introduction that opens with a real case
Inside a module. The coursebook as you see it in the browser, from Module 01.
Certification alignment

How DFE-101 maps to certifications and frameworks

DFE-101 maps to foundational objectives from digital-forensics certifications including IACIS CFCE, ISFCE CCE, GIAC GCFE, and EC-Council CHFI, and to CompTIA Security+. It also aligns with the NICE Framework, NIST SP 800-86, SWGDE standards, and DOJ electronic-evidence guidance.

IACIS CFCE ISFCE CCE GIAC GCFE EC-Council CHFI CompTIA Security+ NICE / NIST 800-86

Maps to foundational objectives. This course is not a certification exam or a guarantee of certification.

FAQ

Common questions

Do I need a technical or forensics background?

No. DFE-101 is a foundational course written in plain language for justice-system professionals. You need only basic computer literacy: opening files, using a web browser, and navigating a desktop.

What digital evidence does the course cover?

Mobile devices, video (CCTV, body cameras, dashcams, and doorbells), IoT and smart-home devices, and vehicle and location data (license plate readers, GPS, and cell-site location). A dedicated module covers AI and deepfake evidence.

Which certifications does DFE-101 map to?

It maps to foundational objectives from IACIS CFCE, ISFCE CCE, GIAC GCFE, and EC-Council CHFI, and to CompTIA Security+. It also aligns with the NICE Framework, NIST SP 800-86, SWGDE standards, and DOJ electronic-evidence guidance.

How long does the course take, and what tools will I use?

About 22 to 26 hours across 12 modules. You work with Autopsy, ExifTool, MediaInfo, and SQLite Browser in a forensic workstation that runs in your browser, with nothing to install and no real case data.

Can I bring DFE-101 to my agency, department, or team?

Yes. You can teach it in a class or buy access for a team. Use the 'Teach this in a class' option to set up a class, or contact us about team and bulk options.

The platform

Delivered on NDG Online

NDG Online runs the lab environment right in your browser, with no installs and no hardware. Network Development Group has built lab-based IT training for educational institutions, government, and industry since 1999. DFE-101 uses NDG's "practice as you read" approach: coursebook, labs, and assessments together.

About NDG Online
Platform features
The forensic workstation desktop running in the browser, with Autopsy, Lab Files, and Terminal icons
  • Readable, plain-language coursebook
  • Guided and applied lab exercises
  • Quizzes and a final case simulation
  • Practice-as-you-read approach

Ready to start? Get Digital Forensics Essentials.

Training a team or a department? We have options for that too.

Digital Forensics Essentials (DFE-101) Foundational · 12 modules · 22–26 hours