Case 001: RAM Acquisition
Module 3 Portfolio. Identified clandestine decryption process from memory artefacts prior to disk access.
We teach the analysis of digital evidence to a UKGCHQ-NI NCSC standards. Not theory. Not case studies. The actual methodology.
Do not mistake this for a course. It is a constraint. The curriculum is a set of non-negotiable parameters for understanding a specific type of evidence.
Every hour is accounted for. Every method is documented. The outcome is not a certificate; it is a verified capability.
"Formal education certifies compliance. We certify comprehension."
Method over theory. Evidence over anecdote.
Process is the product. The work product is the credential.
UKGCHQ-NI NCSC alignment is a floor, not a ceiling.
A six-module traversal. Hover over each for temporal investment.
Weeks 1-3
12 Hours/Week
Forensic copy & hashing protocols.
Weeks 4-7
14 Hours/Week
NTFS, Ext4, APFS metadata parsing.
Weeks 8-10
15 Hours/Week
Volatility framework & live acquisition.
Weeks 11-13
10 Hours/Week
PCAP analysis & router log interpretation.
Weeks 14-16
12 Hours/Week
iOS/Android, AWS/ Azure artefact acquisition.
Week 17
20 Hours/Week
Timed forensic report on a provided disk image.
Module 3 Portfolio. Identified clandestine decryption process from memory artefacts prior to disk access.
Module 2 & 4 Synthesis. Corroborated system event logs with network packet timestamps to establish alibi invalidation.
Module 6 Deliverable. Python script to parse proprietary app database file, reconstructing deleted chat messages.
Module 1 & 5. Hash collision probability analysis for a 1TB disk image, validating forensic integrity.
Module 4 & 6. Mapping malware C2 traffic through corporate firewall logs, isolating the patient zero.
Admission is not granted. It is earned through demonstration of baseline competency. The application is the first test.
Intake: Two cohorts per year. January start (Term 1). September start (Term 2). No exceptions.
Requirement: Submit a completed CTF challenge (provided upon request). Your solution is the application. Not a form. Not a CV.
Process: 1. Request challenge. 2. Solve within 72 hours. 3. Submit forensic report of your solution. 4. Peer review panel assessment (48h).
Current Status
Next cohort opens for challenge requests: 14 January 2026.
Cohort 01 is at capacity. Cohort 02 is open.
For formal application requests and challenge documents, use the dedicated channel.
Request Challenge DocumentResponses handled within 2 working days.