Cyber Knowledge · Domain syllabus
Digital Forensics & Incident Response (DFIR)
Evidence handling, disk/memory/network forensics, timeline reconstruction, and the incident response lifecycle from detection to lessons learned.
Under construction
This domain syllabus has not been written yet. Start with the CTI syllabus, which is live, while this page is built out.
Coming soon
The full zero-to-hero syllabus for Digital Forensics & Incident Response (DFIR) — terminology, frameworks, tools, and a recommended learning order — is being written next. Check back soon, or follow the CTI domain as a model for how each syllabus page will be structured.