This specialist-level course is for experienced forensic investigators who want to acquire the knowledge and skills to navigate, identify, capture and examine data from Linux-based systems.


Linux is an increasingly popular operating system. This two-day course will provide you with a practical understanding from a forensic perspective of how to deal with a Linux system, and requires no previous Linux knowledge. You will develop a core understanding of the file system data structures and key files so that they can be confident in capturing potential digital evidence. Throughout the course you will apply this knowledge in hands-on exercises to demonstrate and reinforce understanding, using both a Linux environment and Windows based forensic software.

Read more


Completion of the 7Safe CFIP course is highly recommended. Alternatively you will need an understanding of digital forensic principles and practices. No Linux experience is necessary.

Who Should Attend?

  • Forensic practitioners

  • Systems administrators

  • Cyber investigators who want to extend their experience from Window-based systems to the Linux environment.

Read more

Delegates will learn how to


Upon completion of the course you will have used a Linux System to:

  • Become familiar with both Linux GUI and command line environments.
  • Demonstrate how Linux can be used for forensic imaging.
  • Capture RAM and basic volatile data from a live Linux system. (Note: This is not network identification or network traffic capture)

and Windows based forensic software and an image of a Linux system to:

  • Examine ext3 and ext4 file system structures
  • Identify core system information
  • Explore system log files for artefacts including; boots, logins and device connection
  • Examine user artefacts including; recent activity, thumbnails and printing.


On this course, you will:

  • Understand the data structures associated with the ‘ext’ file systems
  • Learn effective techniques to extract data from a Linux environment
  • Develop confidence when identifying and capturing Linux system artefacts
  • Improve your ability to respond effectively to a wider range of forensic incidents
Read more



  1. What is Linux? Overview of flavours (distributions)
  2. Key differences between Linux and Windows forensics
  3. Linux concepts, privileges and permissions
  4. Linux disk layouts and key directories
  5. Navigating a Linux system and commonly used command line utilities
  6. Understanding devices and disk mounting
  7. Data collection from and using Linux systems
  8. Capturing volatile data including RAM
  9. Built-in forensic applications i.e dd for imaging and disk wiping
  10. Overview of file system compatibility, ext2, 3 and 4
  11. Ext file systems How disks are mapped and data stored
  12. Problems associated with recovering data from ext file systems
  13. System information from a forensic image
  14. Log files, where to find them and nature of content
  15. Devices connected and disks mounted
  16. User accounts – identification, passwords and permissions
  17. Introduction to memory analysis
  18. User system navigation, execution and printing
  19. Linux in Business - FTP servers, databases, mail, web-servers
  20. Capturing and process for log file examination using Linux

Read more

Why choose QA

Frequently asked questions

See all of our FAQs

How can I create an account on myQA.com?

There are a number of ways to create an account. If you are a self-funder, simply select the "Create account" option on the login page.

If you have been booked onto a course by your company, you will receive a confirmation email. From this email, select "Sign into myQA" and you will be taken to the "Create account" page. Complete all of the details and select "Create account".

If you have the booking number you can also go here and select the "I have a booking number" option. Enter the booking reference and your surname. If the details match, you will be taken to the "Create account" page from where you can enter your details and confirm your account.

Find more answers to frequently asked questions in our FAQs: Bookings & Cancellations page.

How do QA’s virtual classroom courses work?

Our virtual classroom courses allow you to access award-winning classroom training, without leaving your home or office. Our learning professionals are specially trained on how to interact with remote attendees and our remote labs ensure all participants can take part in hands-on exercises wherever they are.

We use the WebEx video conferencing platform by Cisco. Before you book, check that you meet the WebEx system requirements and run a test meeting (more details in the link below) to ensure the software is compatible with your firewall settings. If it doesn’t work, try adjusting your settings or contact your IT department about permitting the website.

Learn more about our Virtual Classrooms.

How do QA’s online courses work?

QA online courses, also commonly known as distance learning courses or elearning courses, take the form of interactive software designed for individual learning, but you will also have access to full support from our subject-matter experts for the duration of your course. When you book a QA online learning course you will receive immediate access to it through our e-learning platform and you can start to learn straight away, from any compatible device. Access to the online learning platform is valid for one year from the booking date.

All courses are built around case studies and presented in an engaging format, which includes storytelling elements, video, audio and humour. Every case study is supported by sample documents and a collection of Knowledge Nuggets that provide more in-depth detail on the wider processes.

Learn more about QA’s online courses.

When will I receive my joining instructions?

Joining instructions for QA courses are sent two weeks prior to the course start date, or immediately if the booking is confirmed within this timeframe. For course bookings made via QA but delivered by a third-party supplier, joining instructions are sent to attendees prior to the training course, but timescales vary depending on each supplier’s terms. Read more FAQs.

When will I receive my certificate?

Certificates of Achievement are issued at the end the course, either as a hard copy or via email. Read more here.

Contact Us

Please contact us for more information