
AI-Powered Digital Forensics
Learn to use AI and large language models as investigative tools – and to recognise how criminals misuse them – with hands-on work on LLMs, RAG systems, AI agents and the EU AI Act.
e-DiFTA 2027 · Prague · 22–26 February 2027
AI, mobile, memory, OSINT, Windows 11, drone, database and host-based network forensics. Each course runs for the full week; choose one per participant.
Filter by course provider and open a course for the full programme, prerequisites and instructors.

Learn to use AI and large language models as investigative tools – and to recognise how criminals misuse them – with hands-on work on LLMs, RAG systems, AI agents and the EU AI Act.

Hands-on intermediate course in advanced Android and iOS analysis: OS internals, encryption, manual SQLite and plist parsing, cloud artefacts and validating what your tools report.

Acquire and analyse RAM from live machines: live forensics and incident response, memory imaging, Windows artefacts from memory, password recovery and in-depth work with the Volatility framework.

Practical open-source intelligence for investigators: a secure OSINT environment, advanced search, SOCMINT, breach data, metadata, image verification, geolocation, the dark web and evidential reporting.

Expert-level Windows 11 forensics over five days: BitLocker, WSL and Sandbox, Registry and user activity, Helium apps, OneDrive, Chromium browsers and SQLite exploitation.

A 36-hour advanced course on extracting and analysing data from drones (UAS), their controllers and mobile apps – DJI, ArduPilot, PX4 and FPV – using non-destructive, court-ready workflows.

Deep-dive database forensics: SQLite internals and deleted-record recovery (freeblocks, freelists, WAL and journals), SQL querying, Chromium SNSS, LevelDB, Realm and binary plists across Windows, Mac, Android and iOS.

Investigate network intrusions and ransomware using host-based evidence: traffic artefacts, live triage, memory analysis, Windows event logs and Registry persistence, and attack timelines.
No. All eight courses run in parallel from Monday to Friday, so each participant attends one course for the full week.
Four courses are delivered by INsig2 (AI-Powered Digital Forensics, Mobile Forensics Deep Dive, Mastering RAM and Volatile Data, Applied OSINT for Digital Investigators) and four by Spyder Forensics (AWFE, ADFA, AADF and HBNF). The event is organised together with WINDIFE.
Yes. Every participant who passes the course receives an official e-DiFTA certificate confirming successful completion of the class and recognising the training hours completed.
Mastering RAM and Volatile Data ends with a knowledge evaluation based on a real case scenario, and Advanced Drone Forensic Analysis (ADFA) ends with a student knowledge assessment.
Five days of hands-on training, an official certificate of successful completion recognising the training hours, a buffet lunch and morning and afternoon coffee breaks every day. Spyder Forensics courses also include a student manual and lab exercises.
Seats are allocated on a “first paid – first confirmed” basis. Register for one course per participant and pay the invoice by bank transfer by 25 December 2026.