Course companion

Cybercrime Investigation & Digital Evidence

How digital evidence is acquired, preserved and analysed, and how an investigation holds up once the findings reach a court.


Download Syllabus

What You'll Learn

Three pillars, evidence in hand every week

Evidence

Digital Evidence Analysis

Acquiring, preserving and analysing evidence from disks, memory, phones and network captures, without altering what you are examining.

Law

Legal & Regulatory Compliance

Chain of custody, admissibility and the professional standards that decide whether a finding survives cross-examination.

Tooling

Forensic Tools & Techniques

Hands-on work with the open-source toolchain used for memory analysis, network forensics, carving and malware reverse engineering.

Course textbook cover

Cybercrime Investigation & Digital Evidence

Required course material · by Dr. ElMouatez Karbab

Get the Book

Your Instructor

Dr. ElMouatez Karbab

Researcher in AI and cybersecurity, with close to two decades spent in academia and in industry. His published work covers machine learning for threat detection and automated security response.

Course Schedule

Weekly topics, readings, labs and evidence sets

1 Week 01 — Welcome, and Defining Cybercrime in the 2026 Landscape
4 Week 04 — Legal and Regulatory Frameworks II
6 Week 06 — File System and Operating System Forensics