A Clear Starting Point

Digital evidence may appear in files, folders, devices, communication records, timestamps, user information, and activity records. At the beginning, it can be difficult to understand which details matter and how they should be recorded.
The Free Kit introduces a five-stage review route:
Identify → Preserve → Examine → Document → Report
Each stage is explained through short lessons, diagrams, worksheets, comparison tables, and fictional investigation scenarios. Learners are encouraged to record what a source directly shows before considering what the surrounding information may indicate.

What Is Included
The Free Kit contains a complete introductory course arranged into structured modules and workshops. Topics include:
- The purpose and scope of Digital Forensics
- Common forms of digital evidence
- Investigation questions and review boundaries
- Evidence preservation and source context
- Evidence registers and handling logs
- Files, folders, and metadata
- Timestamp comparison and event sequencing
- Multi-source evidence review
- Observation and interpretation
- Basic forensic reporting
- Practical worksheets and review activities
- A fictional capstone investigation
- Course glossary and self-assessment
The course materials are available as a downloadable PDF and can be studied offline. Learners can work through the sections in order or revisit completed modules when reviewing later activities.
What You Will Practise
During the course, learners practise organizing evidence references, preparing investigation notes, comparing file details, arranging events into a timeline, and documenting unclear or incomplete information.
The exercises also introduce the difference between a direct observation and an interpretation. For example, a timestamp may describe a recorded file detail, but additional evidence may be needed before connecting that detail to a user or event.
This distinction supports careful analytical writing and helps learners avoid conclusions that are not supported by the reviewed records.
Study at Your Own Pace
There is no fixed completion schedule. Learners can divide the course into shorter study sessions, complete the activities gradually, and keep their worksheets together as a personal case folder.
A practical study method is to read one module, complete the paired activity, and then review how the new information connects with earlier notes. This approach helps maintain consistent terminology and evidence references throughout the course.
Certificate of Completion
The Free Kit includes a certificate of completion. It provides a clear record that the learner has worked through the introductory Digital Forensics materials and course activities.