Cyber Knowledge · Domain syllabus

Digital Forensics & Incident Response (DFIR)

Evidence handling, disk/memory/network forensics, timeline reconstruction, and the incident response lifecycle from detection to lessons learned.

Under construction

This domain syllabus has not been written yet. Start with the CTI syllabus, which is live, while this page is built out.

Coming soon

The full zero-to-hero syllabus for Digital Forensics & Incident Response (DFIR) — terminology, frameworks, tools, and a recommended learning order — is being written next. Check back soon, or follow the CTI domain as a model for how each syllabus page will be structured.