Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026
A practical guide to the PECB Certified Digital Forensics Examiner (CDFE) — the 5-day, hands-on digital forensics certification for incident responders, security analysts, and investigators in Australia. Covers the curriculum, the 3-hour exam across five domains, the experience requirements, and real AUD cost.
The PECB Certified Digital Forensics Examiner (CDFE) is a 5-day, hands-on digital forensics certification, priced at $1,499 + GST through Aegentra, that proves you can acquire, analyse, and preserve legally admissible digital evidence across Windows, macOS, Linux, mobile, and memory.
CDFE is a 5-day, hands-on digital forensics certification from PECB. It builds the expertise to conduct digital forensic investigations and obtain legally admissible digital evidence — acquiring, analysing, and preserving evidence to industry best practice, on a defensible chain of custody. The course runs on hands-on labs across file-system forensics, memory forensics, network analysis, and advanced malware analysis, using the tools examiners actually use: Wireshark and Zeek for network traffic, Ghidra for reverse engineering, and YARA for threat-hunting rules. By the end you can recover deleted data, detect tampering, reverse engineer Windows PE and Linux ELF binaries, and defend the integrity of digital evidence in court. View the full course details.
Forensic capability is now on the critical path of almost every serious Australian incident. Under the Notifiable Data Breaches scheme, the breach assessment itself is a forensic exercise — what was accessed, when, by whom, and whether serious harm is likely must be answered from logs, disk, and memory before notifying the OAIC. The SOCI Act requires critical-infrastructure operators to report significant cyber incidents to ASD and the ACSC within 12 hours, and other reportable incidents within 72 hours, on forensically defensible timelines. Employment disputes, IP theft, fraud, and cybercrime prosecutions turn on whether evidence was acquired and preserved properly — evidence handled badly is evidence excluded. And cyber insurers increasingly expect a forensically sound investigation before paying a claim, while legal-hold and eDiscovery obligations require preserved, verifiable artefacts long after the incident closes. Forensics is the evidentiary backbone of the response work in our incident response certification guide.
Digital forensics analysts and investigators, IT security professionals and incident responders, legal professionals involved in cybercrime cases, corporate security officers and compliance managers, information security team members, and cyber intelligence analysts. There is no prerequisite to attend, though a background in IT security, incident response, or computer forensics helps with the reverse-engineering and memory-analysis labs.
Day 1 covers the foundations of digital forensics, forensic tools and techniques, network analysis with Wireshark, and the basics of malware analysis. Day 2 covers file-system forensics, memory forensics, reverse engineering of Windows PE and Linux ELF binaries, and x86 fundamentals. Day 3 covers advanced malware analysis, Zeek for network analysis, Ghidra, and YARA rule development for threat hunting — skills that also feed the intelligence work in our cyber threat analyst certification guide. Day 4 covers dark web forensics, interactive behaviour analysis, advanced memory and file-system techniques, Zeek scripting and automation, and patch analysis with Ghidra. Day 5 is the certification exam.
The CDFE exam is a 3-hour exam combining multiple-choice and scenario-based questions across five competency domains: network traffic and protocol analysis; memory acquisition and forensics; file-system and disk forensics; malware analysis and reverse engineering; and threat hunting, automation, and correlation. The pass mark is 70% and the exam is remotely proctored, so you can sit it from anywhere in Australia. The exam voucher and one free resit within 12 months are included in the price.
Passing the exam is step one. The full PECB Certified Digital Forensics Examiner credential also requires two years of professional experience (one year in computer forensics), 200 hours of experience in digital forensics, and signing the PECB Code of Ethics. You can sit the exam first and apply once you meet the thresholds. PECB is accredited by UKAS, IAS and COFRAC under ISO/IEC 17024, so the credential is recognised in Australia and internationally.
Through Aegentra, an official PECB authorised training partner, CDFE is $1,499 + GST. The price includes 300+ pages of official course materials, hands-on forensics labs and exercises, the official PECB exam voucher, one free resit within 12 months, 31 CPD credits, and 12 months access via myPECB. Delivery is self-paced online, or instructor-led for enterprise teams.
CDFE maps to roles where the evidence is the deliverable: digital forensics analyst, forensic examiner, DFIR consultant, incident responder, eDiscovery and litigation-support specialist, and cybercrime investigator. It pairs naturally with incident-response and threat-analysis credentials to cover the full detect, respond, and prove lifecycle. Browse the whole Aegentra Academy catalogue or enrol in Certified Digital Forensics Examiner.