Skip to content

Instructor-led training

Live Digital Forensics Training

Instructor-led cohorts delivered in-person at your facility or via live virtual classroom. Real-time labs, real instructor feedback, and a cohort of peers - developed by a U.S. State Department ATA Cyber Mentor with 17+ years of active casework.

5-day intensive

The flagship program

UAS / Drone Forensics

The only practitioner-led drone forensics course developed for law enforcement, military intelligence, and government agencies. Originally built for the U.S. State Department ATA program.

UAS evidence is appearing in criminal cases, counterterrorism operations, and civil litigation at an accelerating rate - and most agencies have no protocol for handling it. This 5-day intensive closes that gap. You'll leave with hands-on proficiency in drone evidence acquisition, flight log analysis, operator identification, and court-ready reporting.

Request this course

31 Courses Across 8 Disciplines

Practical, scenario-based training built around real casework, from foundational to advanced. Courses run 2 to 5 days (16 to 40 instructional hours, 856 hours total), and every course can be tailored to your mission and delivered at your facility.

Expert-LedHands-On & Scenario-BasedTailored to Your MissionDelivered On-SiteCertificate of Completion
31 Courses across 8 disciplines
856 Instructional hours
2-5 Day formats (16-40 hrs)

Get the full course catalog

Daily schedules, tools covered, and audience for every course.

Email me the catalog →

Digital Forensics: Foundations & Field Response

The grounding every digital investigator needs, plus the first-responder skills that protect evidence in the critical first minutes.

Forensic Fundamentals

Foundational
4 days · 32 hrs

The essential foundation for anyone who handles digital evidence. Participants build the sound, court-defensible habits (lawful authority, identification, seizure, chain of custody, hashing, and write-blocking) that every advanced discipline relies on.

Key topics: Legal authority & scope • Identifying digital evidence • Lawful seizure & order of volatility • Chain of custody & hashing • Write-blocking & forensic soundness • Examination workflow & reporting

Who should attend: Investigators and new examiners

Request this course →

Introduction to Computer Hardware

Foundational
2 days · 16 hrs

Hardware literacy that prevents costly mistakes in the field. Participants learn to recognize storage technologies, understand how and where data is stored, and connect media correctly through a write-blocker.

Key topics: Core components • HDD vs SSD & flash storage • Interfaces & adapters • How data is stored (sectors, clusters, slack) • Write-blocked connections • Recognizing devices at a scene

Who should attend: Field investigators and new examiners

Request this course →

Identification & Collection of Digital Evidence

Foundational
3 days · 24 hrs

A force multiplier for general field investigators. Trains first responders to recognize, lawfully collect, isolate, and document digital evidence so examiners receive sound, admissible material.

Key topics: First-responder role & do-no-harm • Legal authority & scope • Recognizing evidence sources • Securing & isolating devices • Collection, packaging & labeling • Documentation & chain of custody

Who should attend: General field investigators / first responders

Request this course →

Digital Forensics: Acquisition & Examination

Hands-on imaging, rapid response, and deep examination across the most common evidence types.

Digital Forensic Acquisition Tools

Intermediate
3 days · 24 hrs

Hands-on forensic imaging done right. Participants acquire verified images from a range of media using hardware and software tools, proving integrity at every step.

Key topics: Acquisition principles & image formats • Hardware & software imaging • Verification & hashing • Difficult acquisitions (SSD, HPA/DCO) • Acquisition documentation • Validated capstone

Who should attend: Examiners

Request this course →

Digital Evidence Acquisition & Rapid Response

Intermediate
3 days · 24 hrs

Sound acquisition under time pressure. Covers on-scene triage, volatile and live capture, and the encryption-aware power-state decisions that can make or break a case.

Key topics: Order of volatility • Live & memory capture • On-scene triage methodology • Encryption & power-state decisions • Rapid acquisition • Documentation under pressure

Who should attend: Examiners and responders

Request this course →

Digital Forensic Analysis Tools

Intermediate
4 days · 32 hrs

From image to insight. Participants examine acquired evidence with leading analysis platforms, recovering files, analyzing user activity, building timelines, and producing defensible reports.

Key topics: Examination workflow • File systems & data recovery • File carving • User-activity artifacts • Keyword, hash & filtering • Timeline analysis & reporting

Who should attend: Examiners

Request this course →

Windows Forensics

Advanced
5 days · 40 hrs

Deep Windows artifact analysis. Reconstruct user and system activity from the registry, event logs, and file-system artifacts to answer the questions a case turns on.

Key topics: NTFS & file-system artifacts • The Windows registry • User-activity artifacts • Program-execution artifacts • Event logs & browser artifacts • Timeline reconstruction & testimony

Who should attend: Experienced examiners

Request this course →

Memory Analysis

Advanced
4 days · 32 hrs

What the disk cannot tell you. Acquire and analyze volatile memory to surface running processes, network connections, injected code, and malware indicators.

Key topics: Memory acquisition • Processes & loaded modules • Network & handle artifacts • Code injection & malware indicators • Strings, keys & credentials • Correlating memory with disk

Who should attend: Advanced examiners

Request this course →

Digital Video Recovery & Analysis

Intermediate
3 days · 24 hrs

Make video evidence count. Recover, authenticate, and present footage from DVR/CCTV, body and dash cameras, and cloud sources using defensible, reproducible methods.

Key topics: Containers & codecs • DVR/CCTV acquisition • Recovering deleted video • Authentication & integrity • Defensible enhancement • Presentation & reporting

Who should attend: Investigators and examiners

Request this course →

UAS / Drone Forensics

Advanced
5 days · 40 hrs

Investigate the drone. Recover and analyze data from unmanned aircraft systems (UAS) and their controllers (flight logs, telemetry, media, and operator identity) to reconstruct missions and attribute activity. A 5-day intensive.

Key topics: UAS components & data sources • Seizing UAS, controllers & batteries • Flight log & telemetry recovery • Onboard & SD-card media • Controller & mobile-app artifacts • Geolocation, flight reconstruction & operator attribution

Who should attend: Examiners and investigators handling drone incidents

Request this course →

Mobile Device Forensics

Phones are the case. Lawful, sound recovery from the highest-volume evidence source, from fundamentals to advanced extractions.

Fundamentals of Mobile Device Forensics

Intermediate
4 days · 32 hrs

Lawfully seize, acquire, and analyze mobile devices to recover communications, location, and application data in a sound, defensible manner.

Key topics: Mobile evidence & lawful seizure • Isolation & power management • Acquisition types • Extraction with mobile suites • Decoding communications & app data • Location & reporting

Who should attend: Examiners and investigators

Request this course →

Advanced Mobile Device Forensics

Advanced
5 days · 40 hrs

The hard extractions. Full file-system and physical methods, locked and encrypted devices, manual SQLite and application decoding, and cloud acquisition.

Key topics: Advanced acquisition methods • Locked & encrypted devices • SQLite & app database decoding • Encrypted messaging artifacts • Cloud & account acquisition • Validation & anti-forensics

Who should attend: Experienced mobile examiners

Request this course →

Online & Open-Source Investigations

Find it, verify it, preserve it, across the open web, social media, and the dark web, safely and lawfully.

Online Investigations

Foundational
3 days · 24 hrs

Plan and run lawful, secure open-source investigations with sound attribution management and court-ready evidence capture.

Key topics: Internet fundamentals for investigators • Managed attribution & OPSEC • Advanced search & discovery • Evaluating & verifying information • Capturing & preserving web evidence • Geolocation & media analysis

Who should attend: Investigators and analysts

Request this course →

Online Investigations: Social Media

Intermediate
3 days · 24 hrs

Turn social media into evidence. Identify and attribute accounts, analyze activity and networks, and lawfully collect and preserve social-media evidence.

Key topics: The social-media landscape • Account identification & attribution • Profile & network analysis • Lawful collection & preservation • Covert engagement & OPSEC • Analysis & reporting

Who should attend: Investigators and analysts

Request this course →

Online Investigations: Dark Web

Intermediate
3 days · 24 hrs

Operate safely in anonymized spaces. Access and investigate dark-web sources, recognize illicit-marketplace indicators, and develop attribution leads while protecting the investigator.

Key topics: Anonymity networks explained • Safe access & OPSEC • Marketplaces, forums & indicators • Searching & mapping hidden services • Collecting & preserving evidence • De-anonymization leads

Who should attend: Investigators

Request this course →

Cryptocurrency Investigations

From first principles to on-chain tracing and the scams hitting communities now.

Cryptocurrency Introduction

Foundational
2 days · 16 hrs

Demystify cryptocurrency for investigators. Understand blockchains, wallets, and transactions well enough to recognize, preserve, and act on crypto evidence.

Key topics: Blockchain basics • Wallets, keys & addresses • Reading transactions • Exchanges, on/off ramps & compliance • Recognizing & seizing crypto evidence

Who should attend: Investigators new to cryptocurrency

Request this course →

Cryptocurrency: Tracing

Intermediate
3 days · 24 hrs

Follow the money on-chain. Trace transactions across wallets and services using industry tracing tools, cluster addresses, and convert leads into lawful action.

Key topics: Tracing fundamentals • Address clustering & attribution • Using a tracing platform • Following funds through services • Obfuscation: mixers, bridges & privacy coins • Reporting & visualization

Who should attend: Financial-crime investigators

Request this course →

Cryptocurrency: Fraud & Scams

Intermediate
2 days · 16 hrs

Respond to the scams hitting your community. Recognize crypto fraud typologies and red flags, capture evidence quickly, and support victims.

Key topics: Scam typologies • Red flags & indicators • Initial response & evidence capture • Victim engagement • Hand-off to tracing & disruption

Who should attend: Investigators and fraud units

Request this course →

Emerging Threats & Technology

Stay ahead of artificial intelligence and cyber-enabled threats.

Artificial Intelligence in Crime & Policing

Awareness
2 days · 16 hrs

A balanced, practical look at AI-enabled threats (deepfakes and synthetic media), the responsible investigative use of AI, and the governance and bias issues leaders must manage.

Key topics: AI foundations for investigators • AI-enabled threats • AI as an investigative aid • Detecting synthetic media • Governance, bias & accountability

Who should attend: Investigators, analysts, supervisors

Request this course →

Cyber-Enabled Terrorism & Emerging Threats

Foundational
2 days · 16 hrs

How threat actors use technology: online radicalization and recruitment, digital financing, operational use of technology, and how investigators detect and disrupt it.

Key topics: The cyber-enabled threat landscape • Online radicalization & recruitment • Digital-age financing • Planning, coordination & attack use • Detection, disruption & coordination

Who should attend: Counterterrorism investigators and analysts

Request this course →

Courtroom, eDiscovery & Expert Testimony

Equip examiners, investigators, and the courtroom to handle digital evidence, from eDiscovery to the witness stand.

eDiscovery & ESI Essentials

Foundational
1 day · 8 hrs

A practical introduction to electronic discovery, from legal hold to production. Participants learn how electronically stored information (ESI) is identified, preserved, collected, processed, reviewed, and produced defensibly, and how investigators, IT, and counsel work together. A 1-day workshop.

Key topics: ESI & FRCP Rule 34 • Litigation holds & Rule 37(e) • Defensible collection vs self-collection • Metadata, processing & TAR • Privilege & Rule 502 clawback • Production formats & proportionality

Who should attend: Investigators, examiners, litigation-support staff, and counsel

Request this course →

Expert Witness Preparation

Advanced
2 days · 16 hrs

Become a credible, effective expert witness. Participants learn to write defensible reports, qualify as an expert, present technical findings clearly, and hold up under cross-examination, with courtroom simulation and feedback. A 2-day course.

Key topics: FRE 702/703/705 & the Daubert trilogy • Writing the defensible report • Qualification & voir dire • Direct examination for juries • Surviving cross-examination • Full moot-court simulation

Who should attend: Examiners, analysts, and investigators who testify

Request this course →

Cyber Judicial Workshop

Judiciary
2 days · 16 hrs

Digital evidence for the bench. A peer workshop helping judges evaluate admissibility, authentication, reliability, and chain of custody for digital evidence, with practical ruling scenarios.

Key topics: Digital evidence for the bench • Legal framework • Authentication, reliability & chain of custody • Common challenges & pitfalls • Ruling scenarios

Who should attend: Judges and judicial officers

Request this course →

Cyber Prosecution Workshop

Prosecutors
2 days · 16 hrs

Win the digital case. Equips prosecutors to frame charges, work with examiners, lay foundation, qualify experts, and present digital exhibits effectively.

Key topics: Digital evidence & the charging decision • Working with examiners & reports • Foundation, authentication & admissibility • Qualifying & examining the expert • Presenting digital exhibits

Who should attend: Prosecutors

Request this course →

Investigative Tradecraft & Counterterrorism

The investigator and leader skills that move a case from information to conviction, and build a capable, accountable organization.

Identifying & Developing Investigative Information

Intermediate
5 days · 40 hrs

From raw information to actionable leads. Build, evaluate, and analyze information from human, open, and record sources, including link analysis and lead development.

Key topics: The investigative information cycle • Sources & source development • Information evaluation • Link & association analysis • Developing leads & hypotheses • Protecting information & sources

Who should attend: Investigators and analysts

Request this course →

Investigative Information Management

Intermediate
5 days · 40 hrs

Never lose a lead. Disciplined registration, case-file construction, secure storage, retrieval, deconfliction, and lawful sharing of investigative information.

Key topics: Registration & logging • Case-file construction & standards • Storage, security & access control • Retrieval, cross-matching & deconfliction • Records, retention & disposal • Lawful sharing

Who should attend: Investigators and records personnel

Request this course →

Investigating Terrorist Incidents

Intermediate
5 days · 40 hrs

Run the major-incident investigation. Secure and document the scene, manage evidence, and drive the investigation from response to case-building with a structured methodology.

Key topics: Incident types & dynamics • Scene security & documentation • Evidence identification & management • Witness & victim management • Investigative planning • Forensic & inter-agency integration

Who should attend: Investigators

Request this course →

Interviewing Terrorist Suspects

Intermediate
5 days · 40 hrs

Lawful, effective, evidence-based interviewing. A rapport-based, rights-compliant program built on the proven PEACE model, with recorded role-play practice.

Key topics: Principles of ethical interviewing • Legal framework & rights • Interview planning • Rapport, communication & questioning • Account development & probing • Recorded interview practical

Who should attend: Investigators

Request this course →

Combating Domestic & Transnational Terrorism

Intermediate
5 days · 40 hrs

Understand and disrupt the network. Analyze terrorist organizations (structure, financing, and networks) and apply rights-based investigative and disruption strategies.

Key topics: Threat, ideologies & context • Organizational structures • Radicalization & recruitment • Terrorist financing • Network & link analysis • Investigative & disruption strategies

Who should attend: Counterterrorism investigators and analysts

Request this course →

Management of Terrorist Investigations

Advanced
5 days · 40 hrs

Lead the complex investigation. Command structure, strategy and decision logging, tasking, information flow, resources, and inter-agency coordination.

Key topics: Command, control & structure • Investigative strategy & decision logging • Tasking & action management • Information & intelligence flow • Resource & personnel management • Risk, review & lessons learned

Who should attend: Investigation managers and team leaders

Request this course →

Police Leaders' Role in Combating Terrorism

Executive
5 days · 40 hrs

Strategy for senior leaders. A seminar on building counterterrorism capability, prevention and community partnerships, rights-based accountability, and crisis leadership.

Key topics: The strategic threat picture • The leader's role • Building & sustaining capability • Prevention, partnerships & trust • Oversight, integrity & accountability • Crisis leadership & communications

Who should attend: Senior police leaders

Request this course →

Bring a Cohort to Your Team

Live cohorts are scheduled on request for agencies, units, and firms, delivered in-person at your facility or via live virtual classroom. Seats are capped to keep the instruction hands-on.

Built for Practitioners

Not academic overviews. These courses are designed for professionals who handle real evidence, write real reports, and testify in real cases.

Director of Training

Director of Training

Eric Waldrep has been in law enforcement for 27+ years and active digital forensics for 17+ years. He has examined 200+ cases in federal and state courts with a 100% expert witness qualification rate. Selected by the U.S. State Department's Antiterrorism Assistance (ATA) program as a Cyber Mentor - training allied-nation law enforcement in digital forensics. Every course in the Balkan Cyber catalog was developed by Eric directly from real casework, ensuring operational relevance you won't find in off-the-shelf curricula.

Ready to Build Your Team's Capability?

Request a cohort for your team or custom on-site training for your agency or firm. Group rates and government invoicing available.

Request a cohort

Government PO and net-30 billing accepted · Group rates for 6+ seats · Custom on-site delivery available

Get the Course Syllabus

Enter your name and email and we'll send you the full syllabus, including the daily schedule and tools covered.

No spam. We may follow up about training opportunities.