
EC-Council Computer Hacking Forensic Investigator
The EC-Council Computer Hacking Forensic Investigator (CHFI) certification validates your ability to conduct effective digital forensics investigations and bring your organization to a state of forensic readiness. This hands-on program immerses you in over 68 labs covering cloud, mobile, IoT, and malware forensics, preparing you to acquire, preserve, and analyze digital evidence that stands up in court. Earning CHFI demonstrates the methodological expertise needed to prosecute cybercriminals and limit organizational liability.
752 practice questions · Updated 2026-07-30
CHFI Curriculum
Every domain, objective, and concept the CHFI exam measures.
- Definition and Scope of Computer Forensics
- Evolution of Computer Forensics
- Need for Computer Forensics
- Cybercrime and Digital Evidence
- Computer Forensics vs. Other Disciplines
- Challenges in Computer Forensics
- Legal and Ethical Considerations
- Future Directions in Computer Forensics
- Forensic Investigation Process Overview
- First Response and Scene Preservation
- Evidence Identification and Collection
- Evidence Preservation and Chain of Custody
- Evidence Examination and Analysis
- Documentation and Reporting
- Case Presentation and Testimony
- Hard Disk Architecture
- CHS and LBA Addressing
- File System Fundamentals
- Common File Systems
- File System Metadata
- Data Storage and Deletion
- Disk Partitioning
- Data Acquisition Fundamentals
- Acquisition Types
- Bit-stream Imaging
- Logical vs Physical Acquisition
- Sparse Acquisition
- Acquisition Tools
- Write Blockers
- Verification and Hashing
- Chain of Custody
- Duplication vs Imaging
- Handling Large Data Sets
- Acquisition from RAID
- Remote Acquisition
- Troubleshooting Acquisition
- Identify anti-forensics techniques
- Detect data hiding
- Detect artifact wiping
- Detect trail obfuscation
- Apply countermeasures
- Use forensic tools for anti-forensics detection
- Windows File System Fundamentals
- Windows Registry Analysis
- Windows Artifact Analysis
- Windows Event Log Analysis
- Windows Account and Login Forensics
- Windows Recycle Bin Forensics
- Windows Shortcut (LNK) File Analysis
- Windows Volume Shadow Copy Forensics
- Windows Memory Forensics Basics
- Windows Timeline and Superfetch Analysis
- Windows Search and Indexing Forensics
- Windows Thumbnail Cache Forensics
- Windows Network Forensics
- Windows Application and Program Execution Forensics
- Windows Deleted File Recovery
- Windows Timestamp Analysis
- Windows User Activity and Privacy Artifacts
- Windows Forensic Tool Usage
- Linux File System Structure
- Linux File System Forensics
- Linux Log Analysis
- Linux User and Group Management
- Linux Process and Service Analysis
- Linux Network Forensics
- Mac File System Structure
- Mac File System Forensics
- Mac Log Analysis
- Mac User and Application Artifacts
- Mac System and Security Artifacts
- Mac Network and Process Forensics
- Network Forensic Fundamentals
- Network Evidence Sources
- Network Traffic Capture Techniques
- Packet Analysis
- Network Log Analysis
- Network Flow Analysis
- Network Time Synchronization
- Network Forensic Tools
- Network Attack Reconstruction
- Network Evidence Preservation
- Network Forensic Reporting
- Malware Analysis Fundamentals
- Static Malware Analysis
- Dynamic Malware Analysis
- Malware Code Analysis
- Malware Reverse Engineering
- Malware Persistence Mechanisms
- Malware Network Behavior Analysis
- Malware Evasion Techniques
- Malware Artifact Extraction
- Malware Analysis Tools
- Malware Reporting and Documentation
- Web Attack Investigation Fundamentals
- Identifying Web Attack Signatures
- Analyzing Web Server Logs
- Correlating Network and Application Data
- Recovering Web Attack Artifacts
- Examining Web Application Code
- Tracing Attack Origin and Attribution
- Documenting Web Attack Findings
- Dark Web Fundamentals
- Tor Network Architecture
- Accessing the Dark Web Safely
- Dark Web Marketplaces and Forums
- Cryptocurrency in Dark Web Transactions
- Dark Web Evidence Acquisition
- Dark Web Investigation Techniques
- Legal and Ethical Considerations
- Cloud Forensics Fundamentals
- Cloud Service Models and Forensics
- Cloud Deployment Models and Forensics
- Legal and Jurisdictional Issues in Cloud Forensics
- Cloud Evidence Acquisition
- Cloud Data Collection Techniques
- Cloud Forensic Tools
- Challenges in Cloud Forensics
- Cloud Forensic Process and Procedures
- Email Header Analysis
- Email Tracing and Tracking
- Email Client Artifacts
- Webmail Forensics
- Email Server Logs and Artifacts
- Email Spoofing and Forgery Detection
- Social Media Profile Investigation
- Social Media Artifact Recovery
- Social Media Metadata Analysis
- Social Media Platform-Specific Forensics
- Legal and Ethical Considerations in Social Media Forensics
- Mobile Forensics Fundamentals
- Mobile Device Evidence Types
- Mobile Forensics Process
- Mobile Device Identification
- Mobile Data Acquisition Methods
- Mobile Forensics Tools
- Mobile Evidence Handling and Preservation
- Mobile Operating System Forensics
- Mobile App Forensics
- Mobile Network and SIM Forensics
- Mobile Cloud and Backup Forensics
- Mobile Malware and Security Analysis
- Mobile Forensics Reporting and Testimony
- IoT Forensics Fundamentals
- IoT Device Identification and Classification
- IoT Data Acquisition
- IoT Evidence Sources
- IoT Forensic Process and Chain of Custody
- IoT Network Forensics
- IoT Cloud and Edge Forensics
- IoT Mobile App Forensics
- IoT Malware and Security Incident Analysis
- IoT Forensic Tools and Techniques
- IoT Legal and Privacy Considerations
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CHFI, so none is invented.