On September 2, 2026, Orion Forensics Lab conducted the training program Digital Forensics – Unlocking the Secrets at Orion Investigations Co., Ltd., Sukhumvit 63, Bangkok. The program was designed to enhance knowledge and practical skills in Digital Forensics for legal professionals and individuals interested in digital investigation processes.

Training Highlights | Digital Forensics – Unlocking the Secrets Training 02/09/2026
Training Highlights: Digital Forensics – Unlocking the Secrets
Morning Session: Proper Preservation of Digital Evidence
Participants learned and observed demonstrations of a Forensic Duplicator, a critical tool used to preserve the integrity of digital evidence. The session also included demonstrations of data acquisition techniques from NVMe SSD storage devices in accordance with digital forensic standards, ensuring that acquired data can be properly presented as evidence in legal proceedings.

Afternoon Session: Mobile Forensics and Mobile Device Data Acquisition
During the afternoon session, participants learned techniques and procedures for acquiring data from mobile phones and portable devices through Mobile Forensics. Demonstrations included the use of specialized tools for Mobile Forensics Data Acquisition as well as supporting equipment commonly used in digital forensic investigations.
- Faraday Bags
- Connection & Acquisition Tools
- SIM Card Readers and Adapters
- Protective Gloves and Precision Screwdriver Kits
- Chain of Custody Documentation Forms
- Sample Digital Forensic Examination Reports


Enhancing Knowledge of Digital Evidence
This training program focused on providing participants with a comprehensive understanding of the principles, procedures, and best practices for collecting, analyzing, and preserving digital evidence from various devices, including smartphones, tablets, and electronic storage media. The goal was to ensure that information could be properly utilized as Digital Evidence in accordance with both legal and technical standards.
In addition, participants exchanged experiences with Digital Forensics professionals and attendees from the legal sector. Lawyers shared practical insights into courtroom proceedings, online evidence collection, and the use of GPS Data, IP Addresses, Metadata, and Event Logs. Discussions also covered website fraud investigations and the use of Social Media Evidence within the justice system.

Thank You to All Participants
Orion Forensics Lab would like to express its sincere appreciation to all participants for their interest and active participation throughout the training program. We hope that the knowledge, techniques, and experience gained during this course will be effectively applied in digital investigations, litigation support, and the management of digital evidence in accordance with international best practices.
Orion Forensics Lab – Unlocking the Secrets of Digital Evidence 🔍📱💻⚖️

Forensic Techniques for Auditors Workshop | Orion Investigations
On July 9, 2026, Orion Investigations Co., Ltd. was honored to serve as the instructor for the Hands-on Workshop: Forensic Techniques for Auditors course.
![]()
This training was designed for information systems auditors, or IT Auditors, who want to strengthen their knowledge of Digital Forensics, Computer Forensics, Electronic Evidence, and the examination of digital evidence in the context of audit work and software compliance.
Overview of the Forensic Techniques for Auditors Training
The Forensic Techniques for Auditors course is a one-day training program that combines both theoretical and practical sessions. The course helps participants understand the principles of digital evidence examination, from evidence collection and data preservation to the analysis of computer usage traces and the preparation of information to support audit and litigation processes.
In addition to Digital Forensics content, participants also observed real-world workflows in both Onsite Audit and Lab Analysis formats, along with examples of digital evidence duplication reports and online investigation case samples.
Who Should Attend This Course
- Information systems auditors or IT Auditors
- Internal Audit and Compliance teams
- Software Asset Management and Software Compliance personnel
- Legal teams involved with electronic evidence
- Organizations that want to develop internal Digital Forensics capabilities
Hands-on Workshop Topics Practiced by Participants
Participants gained hands-on experience in key topics related to digital investigation and digital evidence examination, including:
- Collecting and preserving electronic evidence in accordance with digital forensic principles
- Examining installed software and the history of program usage on computers
- Identifying traces of computer usage and user activity
- Analyzing Windows Registry, Event Logs, and various Digital Artifacts
- Examining USB Storage connection history and user activity
- Collecting evidence that can properly support legal proceedings
Key Takeaways from the Training
- Understanding the principles of Digital Forensics and digital evidence examination
- Learning legal considerations related to electronic evidence
- Being able to examine installed software and software usage history on computers
- Learning how to preserve evidence integrity for use in judicial or investigative processes
- Developing investigative and analytical skills related to software copyright infringement cases
Demonstration of Forensic Duplicator and Digital Forensics Software
One of the highlights of this training was that participants were able to experience and observe the use of real hardware-based tools, or Physical Hardware Experience, especially the use of a Forensic Duplicator for creating digital evidence copies in accordance with forensic principles.
Using a digital evidence duplication device helps preserve the integrity of the original data, reduces the risk of data alteration, and improves the reliability of the examination process when the results need to be used for decision-making or legal procedures.
The training also included a demonstration of Digital Forensics Software used to analyze data, user activity traces, and various Digital Artifacts relevant to internal corporate investigations.
Real-world Experience from IT Audit and Software Compliance Work
During the course, participants exchanged experiences from real working situations, including common challenges in software audits, evidence collection, and analysis of data from user computers.
The instructor shared direct experience from more than 20 years of work in software copyright infringement investigations and IT Audit. This helped participants understand the technical perspective, audit process perspective, and important precautions when handling digital evidence in real-world environments.
Summary of Digital Forensics Training for Auditors
The Hands-on Workshop: Forensic Techniques for Auditors helped participants gain a clearer understanding of the role of Digital Forensics in audit work, from evidence preservation and the examination of computer usage traces to user activity analysis and the systematic preparation of information that can support internal corporate audits.
Orion Investigations would like to thank all participants for their interest, experience sharing, and active participation throughout the training.
Frequently Asked Questions About Digital Forensics Training
Why is Digital Forensics important for IT Audit?
Digital Forensics helps auditors collect, analyze, and examine digital evidence in a systematic manner. This strengthens the reliability of audit work and enables information to be used more effectively for decision-making or legal action.
What is a Forensic Duplicator?
A Forensic Duplicator is a device used to duplicate data from storage media such as hard disks or storage devices. Its purpose is to preserve the original data and reduce the risk of evidence alteration during the examination process.
Is this course suitable for participants without a Digital Forensics background?
This course is suitable for information systems auditors, audit and compliance professionals, and personnel involved in the examination of digital evidence. The content covers both foundational concepts and hands-on practical exercises.
How can organizations apply the knowledge from this course?
Organizations can apply the knowledge to support Internal Audit, Software Compliance, computer incident review, and the preparation of digital evidence in accordance with digital forensic principles.
Follow the Next Training Program with Orion Investigations
Organizations, auditors, and teams interested in developing Digital Forensics skills to support audit work, software compliance, and digital evidence examination can follow the next training schedule from Orion Investigations soon.
Hashtags: #DigitalForensics #ITAudit #ComputerForensics #ElectronicEvidence #SoftwareCompliance #SoftwareAudit #DigitalEvidence #ForensicTechniques #AuditorTraining #HandsOnWorkshop #DigitalForensicsTraining #ITAuditor #ComputerCrime #SoftwareCopyright #CyberInvestigation







Think Reporting a Fake Page Is the End? Brand Damage May Have Just Begun
Many organizations still misunderstand the problem. When they find a fake page, fake website, or content using their brand without authorization, they assume that pressing “Report” on the platform is the end of the issue.
In reality, reporting may only be the beginning.
News reports in Thailand have stated that Thai police and Meta have expanded their cooperation to tackle online scam networks, moving beyond online gambling pages to other forms of scams such as investment fraud and fake job schemes, with faster detection and takedown measures.
The key point is that these problems do not happen once and simply disappear. Bad actors can quickly create new pages, change account names, move to new URLs, or shift to other platforms.
The Problem Is Not Just “Fake Pages” — It Is Brand Trust
For businesses, fake pages and fake websites are not merely technical issues. They are risks to customer trust, corporate reputation, trademarks, and brand image.
Sources on social media takedown explain that removing content from social media may involve several types of abuse, such as
- brand impersonation accounts
- counterfeit promotions
- unauthorized use of trademarks
- copyright infringement, scam ads, fake giveaway campaigns, and phishing links
Meta also provides tools for brands to search for and report issues involving counterfeit content, trademark infringement, copyright infringement, scams, and impersonation across Facebook and Instagram.
On the website side, reports on website impersonation also point out that fake websites may use logos, product images, brand colors, company descriptions, or contact details that resemble the real business in order to mislead customers.
Why One Report Is Not Enough
Reporting content to a platform is a necessary step, but it should not be treated as the entire process. Organizations still need to answer several important questions, such as:
- Has the content actually been removed?
- Has the same page or website reappeared under a new name or URL?
- Is there enough evidence for further action?
- Have customers, partners, or the public already been affected?
- Is the brand being reused on other platforms?
Without evidence collection and continuous follow-up, an organization may only see that “one page has been removed” while missing the bigger picture: brand damage may still be continuing elsewhere.

How Online Monitoring and Takedown Helps Close This Gap
Orion Online Monitoring and Takedown Service is designed to help organizations monitor the internet for content that infringes intellectual property rights, submit takedown requests to website owners or host platforms, and continue monitoring whether the content has been handled in response to those requests.
The service can also support further investigation and legal enforcement in cases where website owners do not comply with takedown requests, with additional work scopes discussed and agreed as appropriate.
Conclusion
Reporting a fake page may help start the takedown process, but it does not guarantee that brand damage will end.
For organizations that need to protect their reputation, trademarks, and online trust, the required response is not just reporting. It is detection, evidence collection, takedown requests, follow-up, and ongoing monitoring for the reappearance of infringing content.

Training Windows Forensics & Analysis at Orion Investigations (Head Office) on 04-05 June 2026
ภาพบรรยากาศ Orion Forensics Lab จัดอบรมในหัวข้อ หลักสูตร Windows Forensics & Analysis 💻🔐 รอบวันที่ 4-5 มิถุนายน 2569 ณ โอไร้อัน อินเว็สทิเกชั่น จำกัด (สำนักงานใหญ่) กรุงเทพมหานคร
เน้นการปฏิบัติจริง: สาธิตเครื่องมือและการวิเคราะห์หลักฐานดิจิทัล ให้กับเจ้าหน้าที่ Cyber Security , IR ในการอบรมครั้งนี้ได้นำเครื่องสำหรับการทำสำเนาหลักฐานดิจิทัล Forensic Duplicator และ Digital Forensics Software มาสาธิตในหลักสูตรนี้ด้วย
ไฮไลท์หลักสูตร 2 วันเต็ม:
ความสำคัญของการบรรยายคือการเน้นการวิเคราะห์หลักฐานดิจิทัล, ตัวอย่างรายงานการวิเคราะห์หลักฐานดิจิทัล และการสาธิตการใช้งานอุปกรณ์จริง ทีมงานผู้เชี่ยวชาญจาก Orion Forensics Lab
ผู้บรรยายโดย คุณสมิทธ์ ณ นคร (Hi-Tech leader) และ คุณธวัชชัย ยิ้มเยื้อน (Forensics Investigation) พร้อมทีมงานอบรม
ได้นำเสนอเทคโนโลยีที่ทันสมัยในการเก็บหลักฐานในสภานที่เกิดเหตุ(onsite) ได้แก่
- การใช้งานอุปกรณ์ทำสำเนาหลักฐาน (Forensic Duplicator) เพื่อคงสภาพความสมบูรณ์ของข้อมูล
- การทำสำเนาหลักฐานกรณีที่มีจำนวนเครื่องคอมพิวเตอร์หลายเครื่องพร้อมๆ กัน
- การฝึกปฎิบัติเชิงเทคนิคในการสืบค้นข้อมูล เพื่อรวบรวมพยานหลักฐานอิเล็กทรอนิกส์
- การเชื่อมโยงพยานหลักฐานอิเล็กทรอนิกส์กับพฤติกรรมของผู้ต้องสงสัย
- การแก้ปัญหาการทำสำเนาหลักฐานในสถานที่เกิดเหตุ(onsite)
- ความเสี่ยงที่ทำให้พยานหลักฐานขาดความน่าเชื่อถือ
- เอกสารที่ใช้สำหรับการทำสำเนาหลักฐานในสถานที่เกิดเหตุ(onsite)
- การแลกเปลี่ยนความรู้จากประสบการณ์การทำเคสจริง (Case Studies and first response)
- ฝึกวิเคราะห์สถานการณ์จริง! เรียนรู้วิธีรับมือเมื่อข้อมูลบริษัทถูกขโมย (Theft of Company Data) ตัวอย่างปัญหาที่พบในทางปฎิบัติ
- การใช้เครื่องมือที่ปลอดภัยและได้มาตรฐานที่น่าเชื่อถือ ควบคู่ไปกับแนวทางปฏิบัติที่ดีที่สุด
- แนวทางในการตอบคำถามทางเทคนิคในชั้นศาล








Computer Forensics Training for Officers under the Computer Crime Act – Digital Evidence & Cyber Investigation Workshop
Hands-On Digital Forensics Training & Real-World Application
- Physical Hardware Experience: Participants interacted directly with professional-grade forensic equipment.
- Forensic Duplicator Demonstration: Ensuring data integrity through forensically sound duplication processes.
- Mobile Forensics Hardware: Specialized tools for data extraction from smartphones, including both visible and hidden data within mobile systems.
- Mobile Forensics Accessories: Use of equipment such as Faraday Bags, which block signals to prevent remote data wiping during evidence transportation.
- Case Studies from Real Investigations: Knowledge sharing based on real-world forensic cases, providing insights into practical challenges and investigative techniques.
This training reinforces the importance of Digital Evidence Preservation, Cybercrime Investigation, and Forensic Readiness, equipping officers with essential skills for modern law enforcement and cybersecurity operations.






Digital Forensics Awareness & Incident Response (including Memory Analysis) 2 Days
Digital Forensics Awareness & Incident Response (including Memory Analysis) 2 Days
When threats no longer leave traces on hard drives… Are you ready to become an advanced cyber investigator?
Today, Fileless Malware attacks and threats that secretly operate within volatile memory (RAM) are causing significant damage to organizations worldwide. If IT teams or incident responders rely solely on traditional shutdown procedures or hard drive analysis, the most critical evidence stored in RAM may disappear forever!
Duration: 2 Days (09:00 – 16:00)
Training Format: Lecture + Hands-on Workshop
Training Materials Provided: Training Software, Forensic Evidence Images (Forensics Image), Mock Investigation Artifacts, Forensic Duplicator Equipment, Forensic Write Blockers (for demonstration), and Acquisition Report Template Samples
Course Overview
This course focuses on developing practical skills and in-depth understanding of Cyber Incident Response alongside Digital Forensics investigations that follow proper procedures and comply with legal requirements. The curriculum covers all phases from incident preparedness, threat detection and analysis, damage containment and mitigation, through to the collection and analysis of digital evidence from multiple sources.
A key highlight of this course is its in-depth coverage of Memory Analysis, an advanced skill that is increasingly essential today. Modern malware and cyber threats often operate entirely within RAM without leaving traces on hard drives (Fileless Malware). Participants will learn how to capture RAM and utilize industry-leading tools to analyze memory images, detect suspicious processes, identify abnormal network connections, and uncover hidden malware activity.
The course combines theoretical instruction with Hands-on Workshops through realistic scenario-based exercises, enabling participants to gain confidence and apply their skills effectively to prevent, identify, investigate, and respond to cyber threats within their organizations.
Key Course Highlights
- Unlock the Secrets Hidden in RAM: Learn the importance and methodology of identifying volatile data and understanding how attackers exploit memory as an attack vector.
Course Objectives
Participants will be able to:
- Understand Cyber Incident Response Processes: Explain incident response phases and lifecycle frameworks according to international standards.
- Understand the importance of RAM memory in forensic investigations.
- Perform RAM capture from live systems correctly and safely.
- Use tools (such as Volatility) to analyze RAM Images and identify abnormal Processes, Network Connections, DLLs, and Code Injection activities.
- Detect and Analyze Malware (Basic Level): Identify traces of malware activity and malicious behavior within operating systems and memory.
Who Should Attend
- Information Security Analysts (Security Analyst / SOC Analyst)
- Cyber Incident Response Team Members (Incident Response Team)
- Digital Forensics Investigators
- Network and System Administrators
- Cybersecurity Consultants
- IT Managers or Legal Professionals involved in cyber investigations
- Internal Auditors and IT Administrators responsible for handling abnormal system incidents
Benefits
- Practical, Real-World Skills: Participants will gain the essential skills and knowledge required to conduct digital forensic investigations on Windows systems for the prevention, identification, and response to cyber threats within their organizations.
- Forensic Training Dataset: A collection of simulated evidence copies and scenario-based investigation artifacts for hands-on practice and skill development.
- Hands-on Experience with Professional Hardware Demonstrations (Hardware Demo): Participants will observe demonstrations of internationally recognized hardware tools used in digital evidence acquisition, providing a clear understanding of real-world forensic processes, including:
- Forensic Duplicator Demonstration: High-speed bit-by-bit imaging devices widely accepted in the digital forensics community for preserving original evidence integrity.
- Hardware Write Blocker & Accessories Demonstration: Devices that prevent modification of original evidence media, along with supporting accessories to ensure evidence integrity and legal admissibility.
- Understanding Professional Investigation Reports: Participants will learn industry-standard digital forensic reporting formats that are professional, easy to understand, and suitable for legal proceedings.
- Certificate of Completion: An official certificate awarded upon successful completion of the training program.
Participant Prerequisites and Requirements
- Basic knowledge of Windows operating systems
- Basic networking knowledge
- Basic information security knowledge

Training Schedule Day 1
09:00 – 10:30
- Introduction & Welcome
- Forensic Acquisitions Concept & Tools
- Hash Values (Digital Fingerprint)
- Exercise
Training Schedule Day 2
09:00 – 10:30
Section 1 – Memory Forensics
- What is Memory Forensics?
- How is Memory Forensics Different from Hard
- Drive Forensics?
- Why Memory Forensics?
Section 2 – Dealing with Live Systems
- Dealing with Live Systems
- Capturing RAM Memory
- Acquisition Tools
10:45 – 12:00
- Cyber Threats & Economic Crime Thailand
- Define Digital Forensics & Its Importance to Organizations
- Legal Consideration, Evidence Handling & Chain of Custody
- Good Practice Guidelines & The Four Principles of Computer Based Evidence
- Exercise: Identifying Sources of Electronic Devices
10:45 – 12:00
Section 2 – (Continued)
- Acquisition Tools
- Capture RAM Memory
- Memory Locations & Analysis Concepts
- Introduction to Volatility
- Identify Rogue Processes (Basic)
13:00 – 14:30
- Persistent Vs Volatile Data
- Dealing with Live Systems & Servers
- Capturing RAM Memory Concepts & Tools
- Exercise
13:00 – 14:30
Section 3 – Analyzing Processes
- Investigating Process Handles & Registry
- Analyze Process DLLs and Handles
- Memory Artifact Timeline Analysis
- Look for Evidence of Code Injection
- Extract Processes and Objects
- Exercise
14:45 – 16:00
- How to Perform Bulk Forensic Imaging
- Exercise
- Preparing an Incident Response Plan
- Q&A
14:45 – 16:00
Section 4 – Memory Forensics Tools & Case Studies
- Memory Forensics Tools
- Exercise
- Memory Forensic Case Studies

อบรมหลักสูตร Digital Forensics – Unlocking the Secrets วันที่ 19 มีนาคม 2569
ภาพบรรยากาศ Orion Forensics Lab ร่วมกับ เขตอุตสาหกรรมซอฟต์แวร์ประเทศไทย (Software Park Thailand) ในการจัดอบรมในหัวข้อ “การอบรมหลักสูตร Digital Forensics – Unlocking the Secrets” เมื่อวันที่ 19 มีนาคม 2569 เวลา 09.00-16.00 น. ณ อาคารซอฟต์แวร์พาร์ค ถ.แจ้งวัฒนะ จ.นนทบุรี
ในการอบรมครั้งนี้ได้นำเครื่องสำหรับการสืบค้นข้อมูลดิจิทัลจากอุปกรณ์มือถือ Mobile Forensics และ อุปกรณ์เสริมในงานพิสูจน์หลักฐานดิจิทัลบนอุปกรณ์พกพา (Mobile Forensics Accessories) เช่น
- ถุงฟาราเดย์ (Faraday Bags)
- อุปกรณ์เชื่อมต่อและดึงข้อมูล (Connection & Acquisition)
- อะแดปเตอร์ซิมการ์ด (SIM Card Readers/Adapters) สำหรับอ่านข้อมูลจากซิมการ์ด
- ถุงมือ (Gloves) และ ชุดไขควง
- ตัวอย่างการบันทึกข้อมูลการเก็บหลักฐาน
- ตัวอย่างรายงาน
มาสาธิตในหลักสูตรนี้ด้วย
การเข้าร่วมการอบรมนี้จะช่วยให้ผู้เข้าอบรมมีความรู้ ความเข้าใจเรื่องนิติวิทยาศาสตร์ทางดิจิทัล (Digital Forensics) ในด้านต่างๆ อาทิ ทักษะ, เทคนิคและสาธิตการใช้เครื่องมือ Mobile Forensics Data Acquisition, กระบวนการเก็บรวบรวมข้อมูลพยานหลักฐานดิจิทัลจากอุปกรณ์พกพา(เช่น สมาร์ทโฟน แท็บเล็ต) เพื่อรวบรวมและรักษาข้อมูลอิเล็กทรอนิกส์ เพื่อใช้เป็นหลักฐานทางดิจิทัล (Digital Evidence)







หลักสูตรเทคนิคการสืบสวนสอบสวนการทุจริตทางดิจิทัล หลักสูตร 2 วัน

Digital Fraud Investigation Techniques Course
- ระยะเวลา: 2 วัน (09:00 – 16:00 น.)
- รูปแบบการเรียน: การบรรยาย + เวิร์กชอปเชิงปฏิบัติการ
- อุปกรณ์ที่จัดเตรียมให้: ซอฟต์แวร์สำหรับฝึกอบรม , ชุดข้อมูล (Datasets) และพยานหลักฐานจำลอง (Investigation Artifacts) และ Demo Mobile Device Forensics Accessories
ภาพรวมหลักสูตร
การทุจริตทางดิจิทัล, การโจรกรรมข้อมูล, ภัยคุกคามจากคนใน และการละเมิดทรัพย์สินทางปัญญา ถือเป็นความเสี่ยงที่สำคัญที่สุดประการหนึ่งที่องค์กรสมัยใหม่ต้องเผชิญ การสืบสวนเหตุการณ์เหล่านี้อย่างมีประสิทธิภาพจำเป็นต้องมีระเบียบวิธีทางนิติวิทยาศาสตร์ที่เป็นระบบ การจัดการพยานหลักฐานที่เหมาะสม และความรู้ด้านข้อกำหนดทางกฎหมายเพื่อให้พยานหลักฐานเป็นที่ยอมรับในชั้นศาล
หลักสูตรเทคนิคการสืบสวนสอบสวนการทุจริตทางดิจิทัลนี้ มุ่งเน้นให้ผู้เข้าอบรมได้รับความรู้เชิงปฏิบัติและทักษะที่จำเป็นในการระบุ เก็บรวมรวม วิเคราะห์ และรายงานพยานหลักฐานดิจิทัลที่เกี่ยวข้องกับการทุจริตและการรั่วไหลของข้อมูล
เนื้อหาหลักสูตรเป็นการผสมผสานระหว่างพื้นฐานทางทฤษฎี กรณีศึกษาจากเหตุการณ์จริง และการฝึกปฏิบัติโดยใช้ชุดข้อมูลและหลักฐานจำลองที่พบได้บ่อยในการสืบสวนจริง โดยระเบียบวิธีฝึกอบรมอ้างอิงตามแนวทางปฏิบัติที่ดีที่สุด (Best Practices) ซึ่งเป็นที่ยอมรับในระดับสากลจากองค์กรต่างๆ เช่น:
- สถาบันมาตรฐานและเทคโนโลยีแห่งชาติ (NIST)
- องค์การระหว่างประเทศว่าด้วยการมาตรฐาน (ISO/IEC)
- Association of Chief Police Officers (ACPO)
วัตถุประสงค์ของหลักสูตร
เมื่อสิ้นสุดการอบรม ผู้เข้าอบรมจะสามารถ:
- เข้าใจพื้นฐานด้านนิติวิทยาศาสตร์ดิจิทัลและการสืบสวนการทุจริต
- ระบุแหล่งพยานหลักฐานดิจิทัลที่อาจเกิดขึ้นได้ในระหว่างการสืบสวน
- ตรวจยึดและรักษาพยานหลักฐานดิจิทัลอย่างถูกต้องตามมาตรฐานนิติวิทยาศาสตร์
- กู้คืนข้อมูลที่ถูกลบหรือถูกซ่อนจากระบบดิจิทัล
- วิเคราะห์ข้อมูลเมทาดาตา (Metadata) ของไฟล์และร่องรอยบนระบบ (System Artifacts)
- ตรวจสอบเทคนิคการต่อต้านนิติวิทยาศาสตร์ (Anti-forensic) ที่ใช้เพื่อซ่อนพยานหลักฐาน
- สืบสวนภัยคุกคามจากคนใน(Insider Threat) และเหตุการณ์ข้อมูลรั่วไหล
- วิเคราะห์ไฟล์เหตุการณ์ (Log files) และลำดับเหตุการณ์ (Event Timeline)
- สืบสวนกรณีการทุจริตในองค์กรและการละเมิดทรัพย์สินทางปัญญา
- ดำเนินการสืบสวนนิติวิทยาศาสตร์บนอุปกรณ์เคลื่อนที่ (Mobile Forensics) เบื้องต้น
- จัดทำรายงานการสืบสวนที่เหมาะสมสำหรับกระบวนการทางกฎหมาย
- นำเสนอพยานหลักฐานดิจิทัลในชั้นศาลในฐานะพยานผู้เชี่ยวชาญ (Expert Witness)
ผู้ที่ควรเข้ารับการอบรม
หลักสูตรนี้ออกแบบมาสำหรับผู้เชี่ยวชาญที่เกี่ยวข้องกับการสืบสวน, ความมั่นคงปลอดภัยไซเบอร์, การกำกับดูแล (Compliance) และการป้องกันการทุจริต ได้แก่:
- ผู้สืบสวนการทุจริต (Fraud Investigators)
- ผู้ตรวจสอบภายใน (Internal Auditors)
- เจ้าหน้าที่กำกับดูแลการปฏิบัติงาน (Compliance Officers)
- นักวิเคราะห์ความมั่นคงปลอดภัยไซเบอร์ (Cybersecurity Analysts)
- นักนิติวิทยาศาสตร์ดิจิทัล (Digital Forensics Investigators)
- เจ้าหน้าที่บังคับใช้กฎหมาย (Law Enforcement Officers)
- นักกฎหมายที่เกี่ยวข้องกับคดีอาชญากรรมทางไซเบอร์
- บุคลากรด้านความปลอดภัยไอที (IT Security Personnel)
- ผู้เชี่ยวชาญด้านการบริหารจัดการความเสี่ยง (Risk Management Professionals)
คุณสมบัติและสิ่งที่ต้องเตรียมของผู้เข้าอบรม
- ทักษะพื้นฐานในการใช้งานคอมพิวเตอร์
- ความเข้าใจพื้นฐานเกี่ยวกับระบบไอทีหรือความมั่นคงปลอดภัยไซเบอร์ (แนะนำแต่ไม่บังคับ)
- คอมพิวเตอร์โน้ตบุ๊ก (ไม่บังคับ หากมีการจัดเตรียมอุปกรณ์ในแล็บให้)
- มีความสนใจในการสืบสวนดิจิทัลหรือการตรวจจับการทุจริต
หัวข้อการเรียนรู้ (Course Modules)
- บทนำสู่นิติวิทยาศาสตร์ดิจิทัล (Introduction to Digital Forensics)
- การระบุและตรวจยึดอุปกรณ์ดิจิทัลอย่างถูกต้อง (Identification & Seizure of Digital Equipment)
- ความสมบูรณ์และการรับฟังพยานหลักฐานดิจิทัลตามกฎหมาย (Legal Admissibility of Digital Evidence)
- การกู้คืนและการวิเคราะห์ข้อมูลพยานหลักฐาน (Data Recovery & Analysis)
- เทคนิคการตรวจสอบการต่อต้านนิติวิทยาศาสตร์ (Anti-Forensics Techniques)
- การตรวจสอบข้อมูลเมทาดาตา (Metadata Examination)
- การวิเคราะห์ไฟล์เหตุการณ์ (Log File Analysis)
- การสืบสวนภัยคุกคามจากคนในและการรั่วไหลของข้อมูล (Insider Threat & Data Leak Investigation)
- การสืบสวนการทุจริตในองค์กร การเงิน และการละเมิดทรัพย์สินทางปัญญา (Corporate & Financial Fraud & Intellectual property infringement)
- การสืบสวนนิติวิทยาศาสตร์บนอุปกรณ์เคลื่อนที่ (Mobile Forensics Investigation)
- กระบวนการเบิกความและนำเสนอพยานหลักฐานในชั้นศาล (Testifying in Court)
- เทคนิคการเขียนรายงานผลการสืบสวนสอบสวน (Investigation Report Writing)
📅 ตารางการอบรม Day 1: Technical Core & Evidence Foundations
วัตถุประสงค์: เน้นการเก็บกู้และวิเคราะห์ร่องรอยดิจิทัลพื้นฐานตามหลักการ Forensic
| เวลา | หัวข้อหลัก | รายละเอียดและมาตรฐานที่เกี่ยวข้อง |
| 09:00 – 10:30 | บทนำสู่นิติวิทยาศาสตร์ดิจิทัล (Introduction to Digital Forensics) | มาตรฐาน ACPO (4 Principles), ISO/IEC 27037 * กฎการรักษาความถูกต้องของหลักฐาน (Chain of Custody) การระบุและตรวจยึดอุปกรณ์ดิจิทัลอย่างถูกต้อง (Identification & Seizure of Digital Equipment) ความสมบูรณ์และการรับฟังพยานหลักฐานดิจิทัลตามกฎหมาย (Legal Admissibility of Digital Evidence) |
| 10:45 – 12:00 | Data Recovery & Analysis | * การกู้คืนไฟล์ที่ถูกลบ (File Carving) และการตรวจสอบ File Signature * การทำ Disk Imaging และการตรวจสอบ Integrity (Hashing) |
| 13:00 – 14:30 | Anti-forensics Detection | การตรวจหาการใช้เครื่องมือลบทำลายหลักฐาน (Wiping), การซ่อนข้อมูล (Steganography) และการทำ Timestomping , Encryption , File obfuscation |
| 14:45 – 16:00 | Metadata (การตรวจสอบข้อมูลเมทาดาตา) Log File Analysis (การวิเคราะห์ไฟล์เหตุการณ์) | การวิเคราะห์ Metadata ของไฟล์เอกสาร และการไล่ Timeline จาก Event Logs และ Registry เพื่อระบุพฤติกรรมผู้ใช้ |
📅 ตารางการอบรม Day 2: Advanced Fraud & Practical Workshop
วัตถุประสงค์: ประยุกต์ใช้เครื่องมือกับคดีทุจริตในองค์กรและสรุปผลการสืบสวน
| เวลา | หัวข้อหลัก | รายละเอียดและมาตรฐานที่เกี่ยวข้อง |
| 09:00 – 10:30 | การสืบสวนภัยคุกคามจากคนในและการรั่วไหลของข้อมูล (Insider Threat & Data Leak Investigation) | การตรวจสอบการรั่วไหลของข้อมูล และการติดตามพฤติกรรมพนักงานที่มีความเสี่ยง |
| 10:45 – 12:00 | Corporate & Financial Fraud & Intellectual property infringement | เทคนิคการสืบสวนการยักยอกเงิน และการละเมิดทรัพย์สินทางปัญญาช่องทางดิจิทัล |
| 13:00 – 14:30 | การสืบสวนนิติวิทยาศาสตร์บนอุปกรณ์เคลื่อนที่ (Mobile Forensics Investigation) | * การเก็บหลักฐานจากสมาร์ทโฟน การวิเคราะห์ข้อมูล แอปแชท และพิกัดตำแหน่ง (GPS) |
| 14:45 – 16:00 | Testifying in Court (กระบวนการเบิกความและนำเสนอพยานหลักฐานในชั้นศาล) Hands-on Workshop & Investigation Report Writing (เทคนิคการเขียนรายงานผลการสืบสวนสอบสวน) | Lab: จำลองคดี “ไฟล์ลับหายไปและการรั่วไหลของข้อมูล” * การเขียนรายงานสรุปผล (Forensic Report) ให้ผู้บริหารและฝ่ายกฎหมาย |

อบรมหลักสูตร Windows Forensics & Analysis ณ.อาคารซอฟต์แวร์พาร์ค วันที่ 18-19 กุมภาพันธ์ 2569
ภาพบรรยากาศ Orion Forensics Lab ร่วมกับ เขตอุตสาหกรรมซอฟต์แวร์ประเทศไทย (Software Park Thailand) ในการจัดอบรมในหัวข้อ หลักสูตร Windows Forensics & Analysis 💻🔐 รอบวันที่ 18-19 กุมภาพันธ์ 2569 ณ อาคารซอฟต์แวร์พาร์ค ถ.แจ้งวัฒนะ จ.นนทบุรี ในการอบรมครั้งนี้ได้นำเครื่องสำหรับการทำสำเนาหลักฐานดิจิทัล TD2 Forensic Duplicator มาสาธิตในหลักสูตรนี้ด้วย
ก้าวสู่การเป็นนักสืบดิจิทัลมืออาชีพกับหลักสูตร Windows Forensics & Analysis 💻🔐
ในโลกที่ข้อมูลคือหัวใจสำคัญ การรู้วิธี “สืบ” และ “วิเคราะห์” ร่องรอยบน Windows คือทักษะที่ขาดไม่ได้ ไม่ว่าจะเป็นเคสพนักงานขโมยข้อมูล (Data Theft) หรือการตรวจสอบการบุกรุกระบบ
ไฮไลท์หลักสูตร 2 วันเต็ม:
✅ Day 1: Windows Artefacts – ขุดลึกร่องรอยลับในระบบ เช่น Registry, USB Forensics, Jump Lists และร่องรอยการลบไฟล์ใน Recycle Bin ที่คุณอาจไม่เคยรู้
✅ Day 2: Windows Analysis – ฝึกวิเคราะห์สถานการณ์จริง! เรียนรู้วิธีรับมือเมื่อข้อมูลบริษัทถูกขโมย (Theft of Company Data) พร้อมเทคนิค และตัวอย่างรายงาน







New Computer Crime Act Officials Training | Elevating Digital Standards with Orion
เสริมสร้างความเข้มแข็งสู่มาตรฐานดิจิทัลไทย: ก้าวสำคัญของการพัฒนาพนักงานเจ้าหน้าที่ตาม พ.ร.บ. คอมพิวเตอร์ฯ
เมื่อวันที่ 22-23 มกราคม 2569 ที่ผ่านมา ณ โรงแรมมิราเคิล แกรนด์ คอนเวนชั่น กรุงเทพฯ โดยกระทรวงดิจิทัลเพื่อเศรษฐกิจและสังคม (ดีอี) ร่วมกับ บมจ. โทรคมนาคมแห่งชาติ (NT) จัดโครงการอบรมเตรียมความพร้อมสำหรับผู้ที่จะได้รับการแต่งตั้งเป็นพนักงานเจ้าหน้าที่ตามพระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ฯ
ในการอบรมครั้งสำคัญนี้ บริษัท โอไร้อัน อินเว็สทิเกชั่น จำกัด (Orion Investigations) ได้รับเกียรติเชิญเป็นวิทยากรผู้เชี่ยวชาญ บรรยายในหัวข้อ “การพิสูจน์หลักฐานทางคอมพิวเตอร์ (Computer Forensics) 2 วัน” เพื่อยกระดับความรู้ความเข้าใจด้านนิติวิทยาศาสตร์ดิจิทัลให้กับเจ้าหน้าที่
เน้นการปฏิบัติจริง: สาธิตเครื่องมือและการเก็บหลักฐานดิจิทัล
ไฮไลท์สำคัญของการบรรยายคือการเน้นภาคปฏิบัติและการสาธิตการใช้งานอุปกรณ์จริง ทีมงานผู้เชี่ยวชาญจาก Orion Forensics Lab ได้นำเสนอเทคโนโลยีที่ทันสมัยในการสืบสวน ได้แก่
- การใช้งานอุปกรณ์ทำสำเนาหลักฐาน (Forensic Duplicator) เพื่อคงสภาพความสมบูรณ์ของข้อมูล
- เทคนิค Mobile Forensic สำหรับการตรวจสอบข้อมูลจากอุปกรณ์เคลื่อนที่
- การแลกเปลี่ยนความรู้จากประสบการณ์การทำคดีจริง (Case Studies)










