Learn Computer Stuff
Home / Cybersecurity / Digital Forensics & Incident Response
Cybersecurity

Digital Forensics & Incident Response

You work out what happened after a breach, in enough detail that it stands up later.

No degree needed Hard, and unusually consequential — your findings may end up in a legal process.


Read this first

Practise only on data and systems you own or are authorised to examine. Forensic work touches personal data by nature, and in a real engagement your handling of evidence can decide whether it is admissible. Follow your organisation's process, and never examine a colleague's machine on your own initiative.

Can I actually do this?

Open without a degree, but essentially always entered from a SOC or security analyst role. You need to have watched alerts before you can reconstruct an intrusion from them. The foundational government guidance below is free, and reading it early is not wasted.

Who it suits. People who are methodical under pressure and can resist concluding before the evidence supports it.

Runway. Years. This is a step up from SOC work, not a first job.

Coming from another job?

Coming from a SOC? That is the route. What you add is reconstructing the whole event rather than closing the ticket. SOC Analyst Security Analyst Systems Administrator

Also advertised as

  • DFIR Analyst
  • Incident Responder
  • Forensic Analyst
  • Threat Response Engineer

The route

Four stations, in order. Each one is a thing you finish before the next matters.

  1. Station one

    Learn it free

    Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.

    NIST SP 800-86 — integrating forensic techniques into incident response

    Free to learn · no certificate

    The foundational free government guidance on doing this properly — evidence handling, order of volatility, process. Free from NIST.

    NIST Cybersecurity Framework

    Free to learn · no certificate

    The Respond and Recover functions are the frame your work sits inside. Free.

    OWASP Cheat Sheet Series

    Free to learn · no certificate

    The logging and monitoring sheets tell you what evidence should have existed. Usually the first finding is that it did not. Free.

    See the full catalog in the explorer →

  2. Station two

    Attest strategically

    The well-known forensics certifications in this field are among the most expensive on this site — training plus exam commonly runs into thousands. We are not naming one because we have not verified current pricing to this project's standard, and because employers in this field frequently fund them. Do not self-fund one as a way in. Get into a SOC first and let the employer pay.

    Nothing here is worth paying for

    No credential needed

    The well-known forensics certifications in this field are among the most expensive on this site — training plus exam commonly runs into thousands. We are not naming one because we have not verified current pricing to this project's standard, and because employers in this field frequently fund them. Do not self-fund one as a way in. Get into a SOC first and let the employer pay.

  3. Station three

    Prove it

    A certificate says you passed a test. These say you can do the job.

    A timeline you reconstructed

    From logs or a disk image in a lab, build what happened and when. The timeline is the deliverable of this job.

    A chain of custody you maintained

    Show that you handled evidence in a way that would survive challenge. This is what separates forensics from curiosity.

    A report written for non-technical readers

    Your findings usually go to lawyers, executives or regulators. Practise that register.

  4. Station four

    Get hired

    Search these exact titles

    • DFIR
    • incident responder
    • digital forensics analyst
    • incident response engineer

    Who hires for this. Incident response consultancies, large in-house security teams, law enforcement, and insurers.

    Hiring leans on incidents you have personally worked, which is why the role resists entry straight from study. That is our reading of the field, not a verified hiring statistic.

    On salary

    We don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.


Where this route continues

· How we verify