Forensics is not primarily about tools. It is about doing things in an order you can defend afterwards. This course covers the forensic process end to end: identification, preservation, acquisition, analysis, and reporting. You will learn write blocking and imaging with dd, FTK Imager, and Guymager, verify integrity with hashing, and maintain a chain of custody that stands up to challenge. File systems get proper coverage, because knowing how NTFS, ext4, and APFS allocate and delete determines what you can recover. Volatile against non-volatile evidence, order of volatility, and live acquisition trade-offs are covered directly. You will complete a full examination of a prepared disk image and produce a written report.