NDG Online · Foundational course (DFE-101)

Digital evidence training for prosecutors

Charge, argue, and defend digital evidence with confidence. No technical background required.

Download the course overview (PDF)
22–26 hours 12 modules Browser-based labs No technical background

For the attorneys who take digital evidence to court

Nearly every case file now includes digital evidence: a phone extraction, doorbell video, location records. DFE-101 gives prosecutors and their teams plain-language command of that evidence, the legal frameworks that govern its collection (Fourth Amendment, ECPA, SCA, and Carpenter), and how it is authenticated and challenged under Daubert and Frye. It is hands-on, built around real-world cases, and assumes no prior forensics experience.

A detective and a prosecutor reviewing digital evidence on a laptop in a briefing room, with a case board behind them
Who it's for

Built for roles like yours

  Prosecutors and ADAs

Know what a phone extraction or location record actually shows, and where it can be challenged.

  Paralegals and litigation staff

Prepare, organize, and manage digital evidence so nothing surprises the trial team.

  DA office investigators

Work mobile, video, IoT, and location evidence and draft warrant language that holds.

No prior technical or forensics experience required, just basic computer literacy.

Evidence domains

The evidence you'll work with

Modern investigations turn on the devices people carry, drive, and live with. In DFE-101 you examine the evidence domains that show up in real cases, in a safe browser-based virtual lab.

A smartphone in an evidence bag, a smart speaker, a video doorbell, a GPS unit, and a body camera laid out on a steel lab table, each with an evidence label

Mobile devices

Call logs, messages, photos, app data, and location history from smartphones and tablets.

Video evidence

CCTV, body cameras, dashcams, and doorbell footage: metadata, timestamps, and authentication.

IoT and smart devices

Smart speakers, video doorbells, and home automation logs, and where that data actually lives.

Vehicle and location

License plate readers, GPS tracking, and cell-site location data, including the law that governs them.

A dedicated module covers AI and emerging technology: AI-assisted analysis, deepfake detection, and the reliability of AI-generated evidence.

What you'll do

From the crime scene to the courtroom

DFE-101 follows digital evidence through its entire life cycle, so you understand not just what the evidence is, but how it holds up when it matters most.

  •   Identify digital evidence across mobile, video, IoT, and location domains
  •   Apply the legal frameworks that govern collection (Fourth Amendment, ECPA, SCA, and Carpenter)
  •   Follow first-responder protocols so evidence isn't lost or excluded
  •   Draft warrant language for phones, cloud accounts, IoT devices, and location data
  •   Recognize how evidence is authenticated and challenged under Daubert and Frye
  •   Examine evidence with foundational forensic tools in a guided environment

  Tools you'll use

You work in a real forensic workstation that runs in your browser. Nothing to install.

Autopsy running in the browser-based lab, showing thumbnails of photo evidence recovered from a simulated mobile device case
  •   Autopsy: disk image and device analysis
  •   ExifTool: metadata extraction
  •   MediaInfo: video and audio analysis
  •   SQLite Browser: mobile app databases

All evidence is fictional and synthetic. Labs run fully sandboxed, with no real case data.

Curriculum

What's inside: 12 modules, 22–26 hours

Each module pairs plain-language instruction with guided and applied lab exercises and a quiz. The course finishes with an end-to-end case simulation.

1 Introduction to digital forensics
2 The digital evidence landscape
3 Legal frameworks for digital evidence
4 First responder protocols
5 Mobile device evidence
6 Video evidence
7 IoT and smart device evidence
8 Vehicle tracking and location data
9 Drafting warrants for digital evidence
10 AI and emerging technology in digital forensics
11 Digital evidence in the courtroom
12 Comprehensive review and case simulation
DFE-101 coursebook in the browser: chapter navigation beside a plain-language introduction that opens with a real case
Inside a module. The coursebook as you see it in the browser, from Module 01.
Certification alignment

How DFE-101 maps to certifications and frameworks

DFE-101 maps to foundational objectives from digital-forensics certifications including IACIS CFCE, ISFCE CCE, GIAC GCFE, and EC-Council CHFI, and to CompTIA Security+. It also aligns with the NICE Framework, NIST SP 800-86, SWGDE standards, and DOJ electronic-evidence guidance.

IACIS CFCE ISFCE CCE GIAC GCFE EC-Council CHFI CompTIA Security+ NICE / NIST 800-86

Maps to foundational objectives. This course is not a certification exam or a guarantee of certification.

FAQ

Common questions

Do I need a technical or forensics background?

No. DFE-101 is a foundational course written in plain language for justice-system professionals. You need only basic computer literacy: opening files, using a web browser, and navigating a desktop.

What digital evidence does the course cover?

Mobile devices, video (CCTV, body cameras, dashcams, and doorbells), IoT and smart-home devices, and vehicle and location data (license plate readers, GPS, and cell-site location). A dedicated module covers AI and deepfake evidence.

Which certifications does DFE-101 map to?

It maps to foundational objectives from IACIS CFCE, ISFCE CCE, GIAC GCFE, and EC-Council CHFI, and to CompTIA Security+. It also aligns with the NICE Framework, NIST SP 800-86, SWGDE standards, and DOJ electronic-evidence guidance.

How long does the course take, and what tools will I use?

About 22 to 26 hours across 12 modules. You work with Autopsy, ExifTool, MediaInfo, and SQLite Browser in a forensic workstation that runs in your browser, with nothing to install and no real case data.

Can I bring DFE-101 to my agency, department, or team?

Yes. You can teach it in a class or buy access for a team. Use the 'Teach this in a class' option to set up a class, or contact us about team and bulk options.

The platform

Delivered on NDG Online

NDG Online runs the lab environment right in your browser, with no installs and no hardware. Network Development Group has built lab-based IT training for educational institutions, government, and industry since 1999. DFE-101 uses NDG's "practice as you read" approach: coursebook, labs, and assessments together.

About NDG Online
Platform features
The forensic workstation desktop running in the browser, with Autopsy, Lab Files, and Terminal icons
  • Readable, plain-language coursebook
  • Guided and applied lab exercises
  • Quizzes and a final case simulation
  • Practice-as-you-read approach

Ready to start? Get Digital Forensics Essentials.

Training a team or a department? We have options for that too.

Digital Forensics Essentials (DFE-101) Foundational · 12 modules · 22–26 hours