

Computer Hacking Forensic Investigator (CHFI v11)
Investigate. Reconstruct. Testify.
CHFI v11 covers digital forensics from disk and memory through mobile, cloud and malware. Macksofy delivers it with industry-standard tools (Autopsy, FTK, Volatility) on real case data — including India-context investigations we've worked on.
What is the CHFI certification?
The Computer Hacking Forensic Investigator (CHFI, EC-Council) certifies your ability to detect and investigate cyberattacks and gather court-admissible digital evidence. As an EC-Council Accredited Training Center, Macksofy delivers CHFI with hands-on forensics labs in India.
Outcomes — concrete, measurable.
Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.
- Conduct forensically sound investigations on disk, memory and networkAnalysis·Foundational60%
- Perform mobile device and cloud forensicsCloud·Practitioner77%
- Produce expert-witness-grade reportsCapability·Specialist94%
- Pass the CHFI v11 (312-49) examCapability·Foundational71%
- Capability2
- Analysis1
- Cloud1
- Digital Forensic Investigator₹7–14 LPA2–4 years
- DFIR Analyst₹10–18 LPA3–5 years
- E-discovery Analyst₹6–11 LPA1–3 years
Is CHFI right for you?
- Law enforcement and government investigators
- Corporate IR and DFIR teams
- E-discovery analysts and legal-tech professionals
What we assume you know
- IT / security background recommended
- Familiarity with Windows + Linux internals
17 modules. 5 days.
Search modules and topics, and switch between Split and Track views to see how every module flows into the next.
Module 01 · Computer Forensics in Today's World
- 01Forensics readiness
- 02Cybercrime types & investigation roles
- 03Indian IT Act 2000 + Section 65B Evidence Act
- 04Forensics lifecycle
Module 02 · Computer Forensics Investigation Process
- 01Pre-investigation, investigation, post-investigation phases
- 02Chain of custody documentation
- 03Evidence collection & preservation
Module 03 · Hard Disks and File Systems
- 01HDD vs SSD architecture
- 02NTFS, FAT, ext, APFS, HFS+
- 03Boot sectors, partition tables
- 04Disk imaging fundamentals
Module 04 · Data Acquisition and Duplication
- 01Live vs static acquisition
- 02FTK Imager, Guymager, dd / dcfldd
- 03Hash verification (MD5, SHA-256)
- 04Hardware write-blockers
Module 05 · Defeating Anti-forensics Techniques
- 01Detecting data hiding (steganography, ADS)
- 02Recovering deleted / wiped files
- 03Encrypted volume analysis
Module 06 · Windows Forensics
- 01Windows Registry artifacts
- 02Event logs, prefetch, ShimCache, AmCache
- 03USB / external device forensics
- 04Browser & email artifact analysis
Module 07 · Linux and Mac Forensics
- 01Linux filesystem artifacts
- 02Bash history, syslog, journald
- 03macOS APFS, plist, FSEvents
Module 08 · Network Forensics
- 01PCAP analysis (Wireshark, NetworkMiner)
- 02Flow data analysis
- 03Detecting C2 traffic
- 04Packet carving
Module 09 · Investigating Web Attacks
- 01Web-server log forensics
- 02SQLi / XSS / file-upload incident analysis
- 03Apache, IIS, Nginx artifact review
Module 10 · Dark Web Forensics
- 01Tor architecture and tracing
- 02Hidden services & marketplaces
- 03Cryptocurrency tracing basics
Module 11 · Database Forensics
- 01MSSQL, MySQL, Oracle artifact analysis
- 02Transaction log examination
- 03Detection of unauthorized access
Module 12 · Cloud Forensics
- 01AWS / Azure / GCP forensic acquisition
- 02CloudTrail, Activity Log, Audit Log analysis
- 03S3 / Blob / GCS evidence collection
Module 13 · Investigating Email Crimes
- 01Email header analysis
- 02Phishing / spoofing / BEC investigation
- 03Server-side log review
Module 14 · Malware Forensics
- 01Static analysis with REMnux & PE-bear
- 02Dynamic analysis with Cuckoo / ANY.RUN
- 03IOC + YARA rule extraction
Module 15 · Mobile Forensics
- 01iOS & Android acquisition (logical, physical, cloud)
- 02Cellebrite UFED, MOBILedit basics
- 03App data + chat application forensics
Module 16 · IoT Forensics
- 01IoT device acquisition methodology
- 02Firmware extraction & analysis
- 03Smart-home, ICS, automotive forensics
Capstone · Court Testimony & Reporting (Macksofy)
- 01Expert-witness report writing
- 02Section 65B certificates
- 03Mock cross-examination practice
The same toolkit our consultants use on real engagements.
Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.
What roles open up after you complete this.
| Role | Salary band | Experience |
|---|---|---|
| Digital Forensic Investigator | ₹7–14 LPA | 2–4 years |
| DFIR Analyst | ₹10–18 LPA | 3–5 years |
| E-discovery Analyst | ₹6–11 LPA | 1–3 years |
We don’t promise jobs. We open doors.
Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.
- 1:1 resume + LinkedIn rewrite with our hiring desk
- Mock interviews with active practitioners
- Direct intros to BFSI, fintech and Big-4 partners
- UAE placement support (Dubai, Abu Dhabi)
Things students ask before enrolling.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements



