The Rigorous Pursuit logo The Rigorous Pursuit

Digital Forensics As an Academic Discipline.

We teach the analysis of digital evidence to a UKGCHQ-NI NCSC standards. Not theory. Not case studies. The actual methodology.

TACTICAL NOTE

Do not mistake this for a course. It is a constraint. The curriculum is a set of non-negotiable parameters for understanding a specific type of evidence.


Every hour is accounted for. Every method is documented. The outcome is not a certificate; it is a verified capability.

"Formal education certifies compliance. We certify comprehension."

Method over theory. Evidence over anecdote.

Process is the product. The work product is the credential.

UKGCHQ-NI NCSC alignment is a floor, not a ceiling.

What We Are Not

Bite-Sized Linear formats that decompose complexity into unrecognisable fragments. We teach integrated systems.
A Learning Platform We are a closed network. The curriculum is the environment. The interface is a console.
For Beginners We assume foundational knowledge. The work begins at the analyst's desk, not the classroom door.
A Community Connection is for the network we build. Peer review is mandatory. Conversation is work.

The Syllabus Snapshot

A six-module traversal. Hover over each for temporal investment.

01. Chain of Custody

Weeks 1-3
12 Hours/Week
Forensic copy & hashing protocols.

02. File System Analysis

Weeks 4-7
14 Hours/Week
NTFS, Ext4, APFS metadata parsing.

03. Memory Forensics

Weeks 8-10
15 Hours/Week
Volatility framework & live acquisition.

04. Network Artefacts

Weeks 11-13
10 Hours/Week
PCAP analysis & router log interpretation.

05. Cloud & Mobile

Weeks 14-16
12 Hours/Week
iOS/Android, AWS/ Azure artefact acquisition.

06. Final Assessment

Week 17
20 Hours/Week
Timed forensic report on a provided disk image.

Evidence Portfolio

Hex dump analysis visual

Case 001: RAM Acquisition

Module 3 Portfolio. Identified clandestine decryption process from memory artefacts prior to disk access.

EVIDENCE: 0x0F5B | ANALYSIS TIME: 18 hours
Hand-drawn forensic flowchart

Case 004: Timeline Construction

Module 2 & 4 Synthesis. Corroborated system event logs with network packet timestamps to establish alibi invalidation.

EVIDENCE: 0x12A1 | ANALYSIS TIME: 24 hours
Scripting interface

Case 009: Custom Parser

Module 6 Deliverable. Python script to parse proprietary app database file, reconstructing deleted chat messages.

EVIDENCE: Script Output | ANALYSIS TIME: 32 hours
Handwritten analysis notes

Case 012: Statistical Anomaly

Module 1 & 5. Hash collision probability analysis for a 1TB disk image, validating forensic integrity.

EVIDENCE: 0x7F4C | ANALYSIS TIME: 8 hours
Network connection graph

Case 015: Command & Control

Module 4 & 6. Mapping malware C2 traffic through corporate firewall logs, isolating the patient zero.

EVIDENCE: 0x9B2A | ANALYSIS TIME: 15 hours

The Gate

Admission is not granted. It is earned through demonstration of baseline competency. The application is the first test.


Intake: Two cohorts per year. January start (Term 1). September start (Term 2). No exceptions.

Requirement: Submit a completed CTF challenge (provided upon request). Your solution is the application. Not a form. Not a CV.

Process: 1. Request challenge. 2. Solve within 72 hours. 3. Submit forensic report of your solution. 4. Peer review panel assessment (48h).

Current Status

Next cohort opens for challenge requests: 14 January 2026.

Cohort 01 is at capacity. Cohort 02 is open.

Contact Inquiry

For formal application requests and challenge documents, use the dedicated channel.

Request Challenge Document

Responses handled within 2 working days.

Contact

The Rigorous Pursuit
123 Oxford Street, London, W1D 1BS
+44 20 7946 0958
[email protected]
Mon-Fri: 09:00 - 18:00

Legal