2340x500_STI_General_Abstract3.jpg

Graduate Certificate Programs: Digital Forensics

This program is pending approval by the Maryland Higher Education Commission (MHEC) and the U.S. Department of Veterans Affairs for VA Education Benefits.

Designed for working InfoSec and IT professionals, the graduate certificate in Digital Forensics is a highly technical program focused on developing your ability to conduct host- and mobile-based forensics investigations and analyze digital evidence in support of investigative and legal processes.

Format Option: A 100% online option is available

Courses: 4

GIAC Certifications: 4

Credits: 12

Duration: 18-24 months

Total Program Cost: $22,800 USD

470x382-cybersecurity-student-8.jpg

Strengthen Your Technical Knowledge and Skills

Gain practical skills you can immediately apply at your job or in a new infosec role.

  • Learn the latest cybersecurity tactics to protect your organization
  • Keep your skills current for career growth and advancement
  • Earn professional GIAC certifications as you complete the program
  • Train on your schedule, to balance work and school
  • Get personalized support from a student advisor 

APPLICATIONS ACCEPTED MONTHLY

SANS.edu Advantage

Because cyber threats are constantly changing, our courses are continually updated for real-world relevance. But that's just the beginning.
STI_Advantage_Icons-07.svg

GIAC Certifications

Earn 4 industry-recognized GIAC cybersecurity certifications.

STI_Advantage_Icons-09.svg

100% Online Option Available

You have the option of completing the program through live or rewindable online courses.

STI_Advantage_Icons-10.svg

World-Class Faculty

Learn the latest skills and techniques from the world's top cybersecurity practitioners.

STI_Advantage_Icons-11.svg

Pathway to a Master’s Degree

All credits earned in this program can transfer into our master’s degree program.

STI_Advantage_Icons-12.svg

SANS.edu Academic Pricing

Get SANS.edu academic pricing on SANS courses and GIAC certifications.

STI_Advantage_Icons-13.svg

Powerful Network

Make connections with some of the most talented students and teachers in the industry.

InfoSec professional attends SANS.edu info session

Join an Online Info Session for Graduate Cybersecurity Programs

  • Explore our 9 highly technical, job-specific graduate certificate programs for working professionals. Thu, February 5 at 2 pm (ET). Register here.
  • Learn more about our cybersecurity master's degree and graduate certificate programs for working professionals. Tue, February 10, 2 pm (ET). Register here.
  • Get tips on crafting a strong application to our cybersecurity master’s degree program and information on the next steps in the admissions process. Thu, February 19, 1 pm (ET). Register here.

Have questions? Some sessions may feature recorded content, but a live Admissions representative will always be available to answer questions and provide personalized guidance.

“I have my master's in computer science, but I completed three graduate certificate programs with SANS so I could truly dive deep into technical areas of cybersecurity and learn from instructors who are leading the industry.” - Jeff Sass, Director of Application Security, Adobe

Learn How To

  • Understand the role of digital forensics in investigative operations
  • Explain how digital forensics supports incident reconstruction, legal processes, and investigative decision-making across host and mobile environments.
  • Collect and preserve digital evidence with integrity
  • Perform evidence acquisition, triage, and preservation while maintaining defensible chain-of-custody and evidentiary standards.
  • Analyze forensic artifacts across platforms
  • Conduct in-depth forensic analysis of Windows systems, mobile devices, and other platforms to establish accurate timelines of user and system activity.
  • Apply and validate forensic tools and methodologies
  • Evaluate forensic tools, validate outputs, and corroborate findings to ensure reliable investigative results.
  • Interpret artifact behavior to establish ground truth
  • Identify and analyze key forensic artifacts to accurately reconstruct events and understand user, system, and adversary actions.

Curriculum | 12 credit hours

In this hands-on program, you’ll progress through 4 advanced graduate courses — including a specialized elective of your choice — to learn the real-world tools and techniques of digital forensics. This is the curriculum order for this program.

Required Core Courses | 9 credit hours

  • SANS Course: FOR498: Digital Acquisition and Rapid Triage
    Certification: GIAC Battlefield Forensics and Acquisition (GBFA)

    3 Credit Hours

    In ISE 6498, you’ll develop essential skills in digital forensics acquisition and rapid triage, learning how to identify, collect, and preserve digital evidence across a wide range of devices and environments—from computers and mobile devices to network and cloud storage—while maintaining forensic soundness. You’ll gain hands-on experience with tools and techniques that enable you to perform quick, effective triage and extract actionable intelligence early in an investigation, helping you accelerate response and decision-making in real-world incidents. This course strengthens foundational capabilities for incident responders, digital forensic analysts, and cybersecurity professionals operating in high-pressure, evidence-driven scenarios.

  • SANS Course: FOR500: Windows Forensic Analysis
    Certification: GIAC Certified Forensic Examiner (GCFE)

    3 Credit Hours

    ISE 6420 Computer Forensic Investigations - Windows focuses on the critical knowledge of the Windows Operating System that every digital forensic analyst needs to investigate computer incidents successfully. Students learn how computer forensic analysts focus on collecting and analyzing data from computer systems to track user-based activity that can be used in internal investigations or civil/criminal litigation. The course covers the methodology of in-depth computer forensic examinations, digital investigative analysis, and media exploitation so each student will have complete qualifications to work as a computer forensic investigator helping to solve and fight crime.

  • SANS Course: FOR585: Smartphone Forensic Analysis In-Depth
    Certification: GIAC Advanced Smartphone Forensics Certification (GASF)

    3 Credit Hours

    The focus of ISE 6450 is on teaching students how to perform forensic examinations on devices such as mobile phones and tablets. Students will add to their forensics skills with this course's focus on the advanced skills of mobile forensics, device file system analysis, mobile application behavior, event artifact analysis and the identification and analysis of mobile device malware. Students will learn how to detect, decode, decrypt, and correctly interpret evidence recovered from mobile devices. The course features a number of hands-on labs that allow students to analyze different datasets from smart devices and leverage the best forensic tools and custom scripts to learn how smartphone data hide and can be easily misinterpreted by forensic tools.

Digital Forensics Electives

Digital Forensics electives allow students to deepen technical specialization, while Incident Response electives provide complementary investigative context.

Students select one of the following.

  • SANS Course: FOR518: Mac and iOS Forensic Analysis and Incident Response
    Certification: GIAC iOS and macOS Examiner (GIME)

    3 Credit Hours

    ISE 6455 provides the techniques and skills necessary to take on any Mac or iOS case without hesitation. The intense hands-on forensic analysis and incident response skills taught in the course will enable students to broaden their capabilities and gain the confidence and knowledge to comfortably analyze any Mac or iOS device. In addition to traditional investigations, the course presents intrusion and incident response scenarios to help analysts learn ways to identify and hunt down attackers that have compromised Apple devices.

  • SANS Course: FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics
    Certification: GIAC Certified Forensic Analyst (GCFA)

    3 Credit Hours

    ISE 6425 teaches the necessary capabilities for forensic analysts and incident responders to identify and counter a wide range of threats within enterprise networks, including economic espionage, hacktivism, and financial crime syndicates. The course shows students how to work as digital forensic analysts and incident response team members to identify, contain, and remediate sophisticated threats-including nation-state sponsored Advanced Persistent Threats and financial crime syndicates. Students work in a hands-on lab developed from a real-world targeted attack on an enterprise network in order to learn how to identify what data might be stolen and by whom, how to contain a threat, and how to manage and counter an attack.

  • SANS Course: FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response
    Certification: GIAC Network Forensic Analyst (GNFA)

    3 Credit Hours

    ISE 6440: Advanced Network Forensics and Analysis focuses on the most critical skills needed to mount efficient and effective post-incident response investigations. Moving beyond the host-focused experiences in ISE 6420 and ISE 6425, ISE 6440 covers the tools, technology, and processes required to integrate network evidence sources into investigations, covering high-level NetFlow analysis, low-level pcap exploration, and ancillary network log examination. Hands-on exercises in FOR 572 cover a wide range of open source and commercial tools, and real-world scenarios help the student learn the underlying techniques and practices to best evaluate the most common types of network-based attacks.

  • SANS Course: FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques
    Certification: GIAC Reverse Engineering Malware Certification (GREM)

    3 Credit Hours

    ISE 6460 teaches students how to examine and reverse engineer malicious programs - spyware, bots, Trojans, etc. - that target or run on Microsoft Windows, within browser environments such as JavaScript or Flash files, or within malicious document files (including Word and PDF). The course builds a strong foundation for reverse-engineering malicious software using a variety of system and network monitoring utilities, a disassembler, a debugger and other tools. The malware analysis process taught in this class helps students understand how incident responders assess the severity and repercussions of a situation that involves malicious software and plan recovery steps. Students also experience how forensics investigators learn to understand key characteristics of malware discovered during the examination, including how to establish indicators of compromise (IOCs) for scoping and containing the incident.

  • SANS Course: SEC497: Practical Open-Source Intelligence (OSINT)
    Certification: GIAC Open Source Intelligence Certification (GOSI)

    3 Credit Hours

    In ISE 6497, you'll learn how to conduct effective, ethical open-source intelligence (OSINT) research using real-world tools and techniques. This hands-on course teaches you how to collect, analyze, and interpret publicly available information while maintaining strong operational security (OPSEC), giving you the skills to uncover critical insights from websites, social media, public records, breach data, and more. Through real-world labs and scenarios, you'll practice essential OSINT methods - from managing research accounts and dissecting digital footprints to analyzing metadata and producing actionable intelligence for investigations, threat assessments, and strategic decision-making. ISE 6497 equips students in cybersecurity, threat intelligence, law enforcement, and investigations with practical OSINT skills you can apply immediately in your work.

  • SANS Course: SEC587: Advanced Open-Source Intelligence (OSINT) Gathering and Analysis
    Certification: GIAC Strategic OSINT Analyst (GSOA)

    3 Credit Hours

    In ISE 6587, you’ll take your OSINT skills to the next level with advanced techniques for gathering, analyzing, and validating intelligence from publicly available sources. This fast-paced, hands-on course builds on foundational OSINT concepts and introduces sophisticated methods—including automation with Python and APIs, Dark Web navigation, cryptocurrency tracing, and advanced image and video analysis—to help you collect and interpret data at scale. You’ll also explore disinformation detection, geopolitical OSINT challenges, and the use of AI tools in investigations, all through real-world labs and scenarios that mirror professional environments. By the end of the course, you’ll be ready to apply advanced OSINT techniques in high-stakes contexts such as threat intelligence, law enforcement, national security, and corporate investigations.

Incident Response Electives

  • SANS Course: FOR509: Enterprise Cloud Forensics and Incident Response
    Certification: GIAC Cloud Forensics Responder (GCFR)

    3 Credit Hours

    In ISE 6442: Enterprise Cloud Forensics and Incident Response, examiners will learn how each of the major cloud service providers (Microsoft Azure, Amazon AWS and Google Cloud Platform) are extending analyst's capabilities with new evidence sources not available in traditional on-premise investigations. Incident response and forensics are primarily about following breadcrumbs left behind by attackers. This class is primarily a log analysis class to help examiners come up to speed quickly with cloud based investigation techniques. Numerous hands-on labs throughout the course will allow you to access evidence generated based on the most common incidents and investigations. You will learn where to pull data from and how to analyze it to find evil.

  • SANS Course: FOR608: Enterprise-Class Incident Response & Threat Hunting
    Certification: GIAC Enterprise Incident Response (GEIR)

    3 Credit Hours

    ISE 6608 focuses on identifying and responding to incidents too large to focus on individual machines. The concepts are similar: gathering, analyzing, and making decisions based on information from hundreds of machines. This requires the ability to automate and the ability to quickly focus on the right information for analysis. By using example tools built to operate at enterprise-class scale, students will learn the techniques to collect focused data for incident response and threat hunting. Students will then dig into analysis methodologies, learning multiple approaches to understand attacker movement and activity across hosts of varying functions and operating systems by using timeline, graphing, structured, and unstructured analysis techniques.

  • SANS Course: FOR577: LINUX Incident Response and Threat Hunting
    Certification: GIAC Linux Incident Responder (GLIR)

    3 Credit Hours

    In ISE 6577, you’ll build advanced skills to detect, investigate, and respond to sophisticated cyber threats on Linux systems, one of the most widely used platforms in enterprise and cloud environments. You’ll learn hands-on techniques for incident response and threat hunting, including how to collect and analyze disk and memory evidence, track attacker behavior from initial breach through lateral movement, and develop actionable threat intelligence using tools like the SIFT Workstation. Through real-world labs and a capstone challenge, you’ll practice rapid triage and timeline analysis, learn to identify stealthy adversaries, and gain confidence responding to complex intrusions. Whether you’re on a digital forensics team, a threat hunting unit, or responsible for protecting Linux infrastructure, this course equips you with practical skills to uncover, contain, and remediate advanced threats effectively.

  • SANS Course: FOR578: Cyber Threat Intelligence
    Certification: GIAC Cyber Threat Intelligence (GCTI)

    3 Credit Hours

    ISE 6445 will equip you, your security team, and your organization in the tactical, operational, and strategic level cyber threat intelligence skills and tradecraft required to better understand the evolving threat landscape and to counter those threats accurately and effectively. This course focuses on structured analysis to establish a solid foundation for any security skillset and to amplify existing skills.

Paller What Does it Cover

Who Should Apply

This certificate is designed for professionals who require deep technical forensic capability, including:

  • Law enforcement digital investigators
  • Government and military forensics personnel
  • Corporate DFIR analysts
  • Cybercrime investigators
  • Consultants performing host, mobile, or network forensics
  • Professionals supporting evidentiary and legal processes

It may also be a strong fit for:

  • Incident responders seeking deeper forensic specialization
  • Threat hunters and intelligence analysts
  • Security engineers supporting investigative workflows

Students can pair Digital Forensics with the Incident Response Graduate Certificate, building broad DFIR expertise without unnecessary course overlap.

Study with the best faculty in cybersecurity

Advancing in Cyber: Real Stories from SANS.edu Graduates

Discover how Jeff Sass, Adobe’s Application Security Director, used SANS.edu graduate certificates and GIAC certifications to switch careers, advance within Adobe, and gain practical cybersecurity expertise he could apply on the job.

470x382-cybersecurity-student-4.jpg

Take Your Next Step

Need more information? We’re happy to answer your questions. Join us for an info session, email info@sans.edu or call 301.241.7665.

Ready to apply? We look forward to learning about you and your career goals.

“I chose the SANS graduate program because the technical content and faculty are unparalleled, and the mix of live and online instruction fit into my work life.” - Joshua Lewis, VP, Threat Intelligence & Incident Response, Umpqua Bank

“After I passed my GCIH certification exam, I got a job offer for twice my current salary. I’m happy where I am, but it’s great to see recruiters going after GIAC certified professionals.” - Agnel D’Silva, IT Administrator, City of Danville, IL

Christopher Haller

SANS.edu Graduate Certificate Student Wins National Cyber League Championship

Christopher Haller beat out more than 6,000 competitors to earn the #1 individual player ranking in the Spring 2022 National Cyber League competition. See why he chose to pursue a graduate certificate at SANS.edu — and learn about his career path from the US Navy to his current role as Principal Security Consultant at Omada Technologies.

Course Delivery Options

Your mind has no borders. Why should your college? Our online and in-person course options are designed to fit your life and how you like to learn.

“You get a lot of personal attention to get through the program because of the student advisors. They are the foundation of the SANS.edu experience.” - Christopher Hurless, Systems Engineer, Northwestern University in Qatar

Join us for a free online info session to learn more.

470x382_-_veteran.jpg

This Program is DoD 8140 Approved

If you're a Department of Defense (DoD) employee or contractor who wants to earn a career-focused cybersecurity degree or certificate, our DoD 8140 approved college programs can open new doors of opportunity.

US Department of Defense 8140 Cyber Workforce Qualification Program
DoD 8140 establishes baseline standards for qualifications that directly support operational needs and workforce readiness. All DoD personnel assigned to positions requiring the performance of cyberspace work are affected by DoD 8140.

  • Service members
  • DoD civilian employees (including non-appropriated fund employees)
  • Contractors
  • Foreign nationals
470x382_STI_Masters_Degree_Tuition.jpg

Tuition

Total program cost: $22,800 USD

Tuition includes the cost of the course, textbooks, and certification tests that serve as mid-term or final exams for courses.

Get the Credit You Deserve
Students who have taken SANS training classes and have active GIAC certifications may be able to waive one course and GIAC certification into the program. See our waiver policy.



Questions?

We're happy to help. Email info@sans.edu or call 301.241.7665.

About the SANS Technology Institute

Founded in 2005, the SANS Technology Institute (SANS.edu) is the independent, regionally-accredited, VA-approved subsidiary of SANS, the world's largest and most trusted provider of cybersecurity training, certification, and research. Offering undergraduate and graduate programs at the cutting edge of cybersecurity, SANS.edu is strengthening the cyber workforce through a career-focused curriculum built on proven SANS courses and industry-recognized GIAC certifications.

The SANS Technology Institute is accredited by The Middle States Commission on Higher Education (1007 North Orange Street, 4th Floor, MB #166, Wilmington, DE 19801 - 267.284.5000), an institutional accrediting agency recognized by the U.S. Secretary of Education and the Council for Higher Education Accreditation.