
Digital Forensics Awareness & Incident Response (including Memory Analysis) 2 Days
When threats no longer leave traces on hard drives… Are you ready to become an advanced cyber investigator?
Today, Fileless Malware attacks and threats that secretly operate within volatile memory (RAM) are causing significant damage to organizations worldwide. If IT teams or incident responders rely solely on traditional shutdown procedures or hard drive analysis, the most critical evidence stored in RAM may disappear forever!
Duration: 2 Days (09:00 – 16:00)
Training Format: Lecture + Hands-on Workshop
Training Materials Provided: Training Software, Forensic Evidence Images (Forensics Image), Mock Investigation Artifacts, Forensic Duplicator Equipment, Forensic Write Blockers (for demonstration), and Acquisition Report Template Samples
Course Overview
This course focuses on developing practical skills and in-depth understanding of Cyber Incident Response alongside Digital Forensics investigations that follow proper procedures and comply with legal requirements. The curriculum covers all phases from incident preparedness, threat detection and analysis, damage containment and mitigation, through to the collection and analysis of digital evidence from multiple sources.
A key highlight of this course is its in-depth coverage of Memory Analysis, an advanced skill that is increasingly essential today. Modern malware and cyber threats often operate entirely within RAM without leaving traces on hard drives (Fileless Malware). Participants will learn how to capture RAM and utilize industry-leading tools to analyze memory images, detect suspicious processes, identify abnormal network connections, and uncover hidden malware activity.
The course combines theoretical instruction with Hands-on Workshops through realistic scenario-based exercises, enabling participants to gain confidence and apply their skills effectively to prevent, identify, investigate, and respond to cyber threats within their organizations.
Key Course Highlights
- Unlock the Secrets Hidden in RAM: Learn the importance and methodology of identifying volatile data and understanding how attackers exploit memory as an attack vector.
Course Objectives
Participants will be able to:
- Understand Cyber Incident Response Processes: Explain incident response phases and lifecycle frameworks according to international standards.
- Understand the importance of RAM memory in forensic investigations.
- Perform RAM capture from live systems correctly and safely.
- Use tools (such as Volatility) to analyze RAM Images and identify abnormal Processes, Network Connections, DLLs, and Code Injection activities.
- Detect and Analyze Malware (Basic Level): Identify traces of malware activity and malicious behavior within operating systems and memory.
Who Should Attend
- Information Security Analysts (Security Analyst / SOC Analyst)
- Cyber Incident Response Team Members (Incident Response Team)
- Digital Forensics Investigators
- Network and System Administrators
- Cybersecurity Consultants
- IT Managers or Legal Professionals involved in cyber investigations
- Internal Auditors and IT Administrators responsible for handling abnormal system incidents
Benefits
- Practical, Real-World Skills: Participants will gain the essential skills and knowledge required to conduct digital forensic investigations on Windows systems for the prevention, identification, and response to cyber threats within their organizations.
- Forensic Training Dataset: A collection of simulated evidence copies and scenario-based investigation artifacts for hands-on practice and skill development.
- Hands-on Experience with Professional Hardware Demonstrations (Hardware Demo): Participants will observe demonstrations of internationally recognized hardware tools used in digital evidence acquisition, providing a clear understanding of real-world forensic processes, including:
- Forensic Duplicator Demonstration: High-speed bit-by-bit imaging devices widely accepted in the digital forensics community for preserving original evidence integrity.
- Hardware Write Blocker & Accessories Demonstration: Devices that prevent modification of original evidence media, along with supporting accessories to ensure evidence integrity and legal admissibility.
- Understanding Professional Investigation Reports: Participants will learn industry-standard digital forensic reporting formats that are professional, easy to understand, and suitable for legal proceedings.
- Certificate of Completion: An official certificate awarded upon successful completion of the training program.
Participant Prerequisites and Requirements
- Basic knowledge of Windows operating systems
- Basic networking knowledge
- Basic information security knowledge

Training Schedule Day 1
09:00 – 10:30
- Introduction & Welcome
- Forensic Acquisitions Concept & Tools
- Hash Values (Digital Fingerprint)
- Exercise
Training Schedule Day 2
09:00 – 10:30
Section 1 – Memory Forensics
- What is Memory Forensics?
- How is Memory Forensics Different from Hard
- Drive Forensics?
- Why Memory Forensics?
Section 2 – Dealing with Live Systems
- Dealing with Live Systems
- Capturing RAM Memory
- Acquisition Tools
10:45 – 12:00
- Cyber Threats & Economic Crime Thailand
- Define Digital Forensics & Its Importance to Organizations
- Legal Consideration, Evidence Handling & Chain of Custody
- Good Practice Guidelines & The Four Principles of Computer Based Evidence
- Exercise: Identifying Sources of Electronic Devices
10:45 – 12:00
Section 2 – (Continued)
- Acquisition Tools
- Capture RAM Memory
- Memory Locations & Analysis Concepts
- Introduction to Volatility
- Identify Rogue Processes (Basic)
13:00 – 14:30
- Persistent Vs Volatile Data
- Dealing with Live Systems & Servers
- Capturing RAM Memory Concepts & Tools
- Exercise
13:00 – 14:30
Section 3 – Analyzing Processes
- Investigating Process Handles & Registry
- Analyze Process DLLs and Handles
- Memory Artifact Timeline Analysis
- Look for Evidence of Code Injection
- Extract Processes and Objects
- Exercise
14:45 – 16:00
- How to Perform Bulk Forensic Imaging
- Exercise
- Preparing an Incident Response Plan
- Q&A
14:45 – 16:00
Section 4 – Memory Forensics Tools & Case Studies
- Memory Forensics Tools
- Exercise
- Memory Forensic Case Studies

หลักสูตรเทคนิคการสืบสวนสอบสวนการทุจริตทางดิจิทัล หลักสูตร 2 วัน

Digital Fraud Investigation Techniques Course
- ระยะเวลา: 2 วัน (09:00 – 16:00 น.)
- รูปแบบการเรียน: การบรรยาย + เวิร์กชอปเชิงปฏิบัติการ
- อุปกรณ์ที่จัดเตรียมให้: ซอฟต์แวร์สำหรับฝึกอบรม , ชุดข้อมูล (Datasets) และพยานหลักฐานจำลอง (Investigation Artifacts) และ Demo Mobile Device Forensics Accessories
ภาพรวมหลักสูตร
การทุจริตทางดิจิทัล, การโจรกรรมข้อมูล, ภัยคุกคามจากคนใน และการละเมิดทรัพย์สินทางปัญญา ถือเป็นความเสี่ยงที่สำคัญที่สุดประการหนึ่งที่องค์กรสมัยใหม่ต้องเผชิญ การสืบสวนเหตุการณ์เหล่านี้อย่างมีประสิทธิภาพจำเป็นต้องมีระเบียบวิธีทางนิติวิทยาศาสตร์ที่เป็นระบบ การจัดการพยานหลักฐานที่เหมาะสม และความรู้ด้านข้อกำหนดทางกฎหมายเพื่อให้พยานหลักฐานเป็นที่ยอมรับในชั้นศาล
หลักสูตรเทคนิคการสืบสวนสอบสวนการทุจริตทางดิจิทัลนี้ มุ่งเน้นให้ผู้เข้าอบรมได้รับความรู้เชิงปฏิบัติและทักษะที่จำเป็นในการระบุ เก็บรวมรวม วิเคราะห์ และรายงานพยานหลักฐานดิจิทัลที่เกี่ยวข้องกับการทุจริตและการรั่วไหลของข้อมูล
เนื้อหาหลักสูตรเป็นการผสมผสานระหว่างพื้นฐานทางทฤษฎี กรณีศึกษาจากเหตุการณ์จริง และการฝึกปฏิบัติโดยใช้ชุดข้อมูลและหลักฐานจำลองที่พบได้บ่อยในการสืบสวนจริง โดยระเบียบวิธีฝึกอบรมอ้างอิงตามแนวทางปฏิบัติที่ดีที่สุด (Best Practices) ซึ่งเป็นที่ยอมรับในระดับสากลจากองค์กรต่างๆ เช่น:
- สถาบันมาตรฐานและเทคโนโลยีแห่งชาติ (NIST)
- องค์การระหว่างประเทศว่าด้วยการมาตรฐาน (ISO/IEC)
- Association of Chief Police Officers (ACPO)
วัตถุประสงค์ของหลักสูตร
เมื่อสิ้นสุดการอบรม ผู้เข้าอบรมจะสามารถ:
- เข้าใจพื้นฐานด้านนิติวิทยาศาสตร์ดิจิทัลและการสืบสวนการทุจริต
- ระบุแหล่งพยานหลักฐานดิจิทัลที่อาจเกิดขึ้นได้ในระหว่างการสืบสวน
- ตรวจยึดและรักษาพยานหลักฐานดิจิทัลอย่างถูกต้องตามมาตรฐานนิติวิทยาศาสตร์
- กู้คืนข้อมูลที่ถูกลบหรือถูกซ่อนจากระบบดิจิทัล
- วิเคราะห์ข้อมูลเมทาดาตา (Metadata) ของไฟล์และร่องรอยบนระบบ (System Artifacts)
- ตรวจสอบเทคนิคการต่อต้านนิติวิทยาศาสตร์ (Anti-forensic) ที่ใช้เพื่อซ่อนพยานหลักฐาน
- สืบสวนภัยคุกคามจากคนใน(Insider Threat) และเหตุการณ์ข้อมูลรั่วไหล
- วิเคราะห์ไฟล์เหตุการณ์ (Log files) และลำดับเหตุการณ์ (Event Timeline)
- สืบสวนกรณีการทุจริตในองค์กรและการละเมิดทรัพย์สินทางปัญญา
- ดำเนินการสืบสวนนิติวิทยาศาสตร์บนอุปกรณ์เคลื่อนที่ (Mobile Forensics) เบื้องต้น
- จัดทำรายงานการสืบสวนที่เหมาะสมสำหรับกระบวนการทางกฎหมาย
- นำเสนอพยานหลักฐานดิจิทัลในชั้นศาลในฐานะพยานผู้เชี่ยวชาญ (Expert Witness)
ผู้ที่ควรเข้ารับการอบรม
หลักสูตรนี้ออกแบบมาสำหรับผู้เชี่ยวชาญที่เกี่ยวข้องกับการสืบสวน, ความมั่นคงปลอดภัยไซเบอร์, การกำกับดูแล (Compliance) และการป้องกันการทุจริต ได้แก่:
- ผู้สืบสวนการทุจริต (Fraud Investigators)
- ผู้ตรวจสอบภายใน (Internal Auditors)
- เจ้าหน้าที่กำกับดูแลการปฏิบัติงาน (Compliance Officers)
- นักวิเคราะห์ความมั่นคงปลอดภัยไซเบอร์ (Cybersecurity Analysts)
- นักนิติวิทยาศาสตร์ดิจิทัล (Digital Forensics Investigators)
- เจ้าหน้าที่บังคับใช้กฎหมาย (Law Enforcement Officers)
- นักกฎหมายที่เกี่ยวข้องกับคดีอาชญากรรมทางไซเบอร์
- บุคลากรด้านความปลอดภัยไอที (IT Security Personnel)
- ผู้เชี่ยวชาญด้านการบริหารจัดการความเสี่ยง (Risk Management Professionals)
คุณสมบัติและสิ่งที่ต้องเตรียมของผู้เข้าอบรม
- ทักษะพื้นฐานในการใช้งานคอมพิวเตอร์
- ความเข้าใจพื้นฐานเกี่ยวกับระบบไอทีหรือความมั่นคงปลอดภัยไซเบอร์ (แนะนำแต่ไม่บังคับ)
- คอมพิวเตอร์โน้ตบุ๊ก (ไม่บังคับ หากมีการจัดเตรียมอุปกรณ์ในแล็บให้)
- มีความสนใจในการสืบสวนดิจิทัลหรือการตรวจจับการทุจริต
หัวข้อการเรียนรู้ (Course Modules)
- บทนำสู่นิติวิทยาศาสตร์ดิจิทัล (Introduction to Digital Forensics)
- การระบุและตรวจยึดอุปกรณ์ดิจิทัลอย่างถูกต้อง (Identification & Seizure of Digital Equipment)
- ความสมบูรณ์และการรับฟังพยานหลักฐานดิจิทัลตามกฎหมาย (Legal Admissibility of Digital Evidence)
- การกู้คืนและการวิเคราะห์ข้อมูลพยานหลักฐาน (Data Recovery & Analysis)
- เทคนิคการตรวจสอบการต่อต้านนิติวิทยาศาสตร์ (Anti-Forensics Techniques)
- การตรวจสอบข้อมูลเมทาดาตา (Metadata Examination)
- การวิเคราะห์ไฟล์เหตุการณ์ (Log File Analysis)
- การสืบสวนภัยคุกคามจากคนในและการรั่วไหลของข้อมูล (Insider Threat & Data Leak Investigation)
- การสืบสวนการทุจริตในองค์กร การเงิน และการละเมิดทรัพย์สินทางปัญญา (Corporate & Financial Fraud & Intellectual property infringement)
- การสืบสวนนิติวิทยาศาสตร์บนอุปกรณ์เคลื่อนที่ (Mobile Forensics Investigation)
- กระบวนการเบิกความและนำเสนอพยานหลักฐานในชั้นศาล (Testifying in Court)
- เทคนิคการเขียนรายงานผลการสืบสวนสอบสวน (Investigation Report Writing)
📅 ตารางการอบรม Day 1: Technical Core & Evidence Foundations
วัตถุประสงค์: เน้นการเก็บกู้และวิเคราะห์ร่องรอยดิจิทัลพื้นฐานตามหลักการ Forensic
| เวลา | หัวข้อหลัก | รายละเอียดและมาตรฐานที่เกี่ยวข้อง |
| 09:00 – 10:30 | บทนำสู่นิติวิทยาศาสตร์ดิจิทัล (Introduction to Digital Forensics) | มาตรฐาน ACPO (4 Principles), ISO/IEC 27037 * กฎการรักษาความถูกต้องของหลักฐาน (Chain of Custody) การระบุและตรวจยึดอุปกรณ์ดิจิทัลอย่างถูกต้อง (Identification & Seizure of Digital Equipment) ความสมบูรณ์และการรับฟังพยานหลักฐานดิจิทัลตามกฎหมาย (Legal Admissibility of Digital Evidence) |
| 10:45 – 12:00 | Data Recovery & Analysis | * การกู้คืนไฟล์ที่ถูกลบ (File Carving) และการตรวจสอบ File Signature * การทำ Disk Imaging และการตรวจสอบ Integrity (Hashing) |
| 13:00 – 14:30 | Anti-forensics Detection | การตรวจหาการใช้เครื่องมือลบทำลายหลักฐาน (Wiping), การซ่อนข้อมูล (Steganography) และการทำ Timestomping , Encryption , File obfuscation |
| 14:45 – 16:00 | Metadata (การตรวจสอบข้อมูลเมทาดาตา) Log File Analysis (การวิเคราะห์ไฟล์เหตุการณ์) | การวิเคราะห์ Metadata ของไฟล์เอกสาร และการไล่ Timeline จาก Event Logs และ Registry เพื่อระบุพฤติกรรมผู้ใช้ |
📅 ตารางการอบรม Day 2: Advanced Fraud & Practical Workshop
วัตถุประสงค์: ประยุกต์ใช้เครื่องมือกับคดีทุจริตในองค์กรและสรุปผลการสืบสวน
| เวลา | หัวข้อหลัก | รายละเอียดและมาตรฐานที่เกี่ยวข้อง |
| 09:00 – 10:30 | การสืบสวนภัยคุกคามจากคนในและการรั่วไหลของข้อมูล (Insider Threat & Data Leak Investigation) | การตรวจสอบการรั่วไหลของข้อมูล และการติดตามพฤติกรรมพนักงานที่มีความเสี่ยง |
| 10:45 – 12:00 | Corporate & Financial Fraud & Intellectual property infringement | เทคนิคการสืบสวนการยักยอกเงิน และการละเมิดทรัพย์สินทางปัญญาช่องทางดิจิทัล |
| 13:00 – 14:30 | การสืบสวนนิติวิทยาศาสตร์บนอุปกรณ์เคลื่อนที่ (Mobile Forensics Investigation) | * การเก็บหลักฐานจากสมาร์ทโฟน การวิเคราะห์ข้อมูล แอปแชท และพิกัดตำแหน่ง (GPS) |
| 14:45 – 16:00 | Testifying in Court (กระบวนการเบิกความและนำเสนอพยานหลักฐานในชั้นศาล) Hands-on Workshop & Investigation Report Writing (เทคนิคการเขียนรายงานผลการสืบสวนสอบสวน) | Lab: จำลองคดี “ไฟล์ลับหายไปและการรั่วไหลของข้อมูล” * การเขียนรายงานสรุปผล (Forensic Report) ให้ผู้บริหารและฝ่ายกฎหมาย |

หลักสูตร Computer Forensics Exam Mastery: 1-Day Intensive Bootcamp (พร้อม Voucher สอบ)
หากคุณกำลังมองหาคอร์ส อบรม Computer Forensics ที่กระชับ ตรงประเด็น และเน้นผลลัพธ์ในการสอบใบรับรอง หลักสูตร “Computer Forensics Exam Mastery: 1-Day Intensive Bootcamp” คือคำตอบสำหรับคุณ
นี่คือหลักสูตรที่ออกแบบมาเพื่อ “เตรียมความพร้อมก้าวสู่ความเป็นมืออาชีพด้าน Digital Forensics” พร้อม Voucher สำหรับการสอบ เพื่อให้คุณพร้อมทั้งความรู้และโอกาสในการคว้าใบรับรอง
? เป้าหมายของหลักสูตร
- เข้าใจกระบวนการ เพื่อให้ผู้เรียนเข้าใจกระบวนการทางกฎหมายและเทคนิค Digital Forensics ที่ออกสอบบ่อย
- วิเคราะห์เป็น เพื่อฝึกฝนการวิเคราะห์โจทย์
- มั่นใจก่อนสอบ เพื่อทบทวนเนื้อหาและสร้างความมั่นใจ
? จุดเด่น
- Expert Instructor: สอนโดยผู้เชี่ยวชาญที่มีประสบการณ์จริงด้าน Digital Forensics และได้รับการรับรองทักษะการสอน
- Exam-Focused: เนื้อหาถูกออกแบบมาเพื่อการสอบโดยเฉพาะ ไม่เสียเวลากับทฤษฎีที่ไม่จำเป็น
- Cheat Sheet Included: แจกสรุป Keyword และ Path สำคัญที่ต้องจำ ช่วยลดเวลาในการอ่านหนังสือเอง
กลุ่มเป้าหมายของหลักสูตร ” Computer Forensics Exam Mastery: 1-Day Intensive Bootcamp ” ดังนี้:
- The Auditors และ Compliance Officers
- IT Managers และ ผู้เชี่ยวชาญด้านความปลอดภัย IT (Security Experts)
- นักสืบสวนทางนิติวิทยาศาสตร์ดิจิทัล (Digital Forensic Investigators)
- เจ้าหน้าที่บังคับใช้กฎหมาย
- ผู้ที่กำลังเตรียมสอบใบรับรอง (Certification Seekers)
? กำหนดการอบรม (Detailed Schedule)
09:00 – 12:00: High-Yield Theory Summary
ช่วงเช้าเน้นปูพื้นฐานและสรุปหัวข้อที่ออกสอบบ่อย (High-Frequency Topics)
09:00 – 10:00: Legal & Process Foundation
- The Four Principles: สรุปหลักการ 4 ข้อของพยานหลักฐานดิจิทัล (ACPO Guidelines)
- Evidence Handling: ขั้นตอนที่ถูกต้องในการเก็บหลักฐาน (Seizing) และการทำ Chain of Custody
- Admissibility: ปัจจัยสำคัญที่ศาลใช้พิจารณาความน่าเชื่อถือของพยานหลักฐาน
10:00 – 10:15: พักเบรก Morning Break
10:15 – 11:15: Technical Forensics Deep-Dive
- Acquisition Techniques: เจาะลึกความต่างระหว่าง Static vs. Live Acquisition (Bit-stream image vs. Backup)
- Windows Artifacts Mastery: ชี้เป้า “จุดตาย” ที่ต้องรู้ใน Registry, Link Files และ Shellbags
- Event Logs & USB: เทคนิคการแกะรอยการเข้าถึงระบบและการเชื่อมต่ออุปกรณ์ภายนอก
11:15 – 12:00: Specialized Areas Briefing
- Network & Web Forensics: การวิเคราะห์ Log (Log Analysis)
- Email & Mobile Forensics: ลำดับขั้นตอนการสืบสวน (Investigation Flow)
13:00 – 16:00: Exam Drill & Strategy
ช่วงบ่ายเปลี่ยนความรู้เป็นคะแนน ด้วยการฝึกทำโจทย์เสมือนจริง
13:00 – 14:30: Domain-Based Practice (Set 1)
- ฝึกทำโจทย์แยกตามหัวข้อ (Legal, Windows, Network, Cloud)
- วิเคราะห์โจทย์ เจาะลึก ให้ดูว่า “คำถามนี้ถามหาอะไร”
14:30 – 14:45: พักเบรก Afternoon Break
14:45 – 15:45: Final Mock Exam (Full Speed)
- จำลองการสอบจริงพร้อมเทคนิคการตัดตัวเลือก (Elimination Technique)
15:45 – 16:00: Q&A and Exam Readiness Tips
- ถาม-ตอบ และเคล็ดลับเตรียมตัวก่อนเข้าห้องสอบ
ข้อมูลการสมัคร (Enrollment Info)
- วันและเวลา: 9.00-16.00
- สถานที่: Onsite อาคาร Bangkok Business Center (สุขุมวิท 63 หรือซอยเอกมัย) or In house Training สำหรับองค์กร
- ราคา: 16,500 บาท (ยังไม่รวม VAT) ราคานี้รวม Voucher สอบ + LMS เรียบร้อยแล้ว
- ช่องทางลงทะเบียน LINE ID: orionforensics หรือ https://line.me/ti/p/gXyoCB99cG
- ช่องทางลงทะเบียน Email:

หมายเหตุ
- ทุกหลักสูตรสามารถจัดในรูปแบบ ( In-House) อบรมในองค์กรได้ โปรดติดต่อ Email:

- สิทธิประโยชน์ทางภาษี: ค่าใช้จ่ายจากการอบรมสามารถนำไปลดหย่อนภาษีได้ 200% (พระราชบัญญัติส่งเสริมการพัฒนาฝีมือแรงงาน พ.ศ. 2545)
- หลักสูตรภาคปฏิบัติผู้เข้าอบรมต้องเตรียมคอมพิวเตอร์มาเอง
- ในกรณีอบรม ณ ห้องอบรมบริษัทลูกค้า ค่าอบรมจะไม่รวมค่าอาหารกลางวัน และอาหารว่าง 2 มื้อ
- หลักสูตรอาจมีการเปลี่ยนแปลงวันเวลาจัดอบรมตามความสะดวกของลูกค้า


In House Training (การฝึกอบรมและสัมมนานอกสถานที่)
อบรมในรูปแบบ IN-HOUSE กับ Orion Forensics
ขั้นต่ำ 10 ท่าน เริ่มต้นเพียง 30,000 บาท
บริการจัดอบรมในรูปแบบ In-House Training ให้กับองค์กร โดยมีหลักสูตรการอบรมด้าน Digital Forensics ลูกค้าองค์กรทั้งภาครัฐและเอกชน สนใจรับบริการอบรม In-House รวมไปถึงการ Customize หลักสูตร Training ที่เหมาะสม กับความต้องการขององค์กร












หมายเหตุ
- ทุกหลักสูตรสามารถจัดในรูปแบบ In-House ได้ โปรดติดต่อ Email:

- ค่าใช้จ่ายจากการอบรมสามารถนำไปลดหย่อนภาษีได้ 200% (พระราชบัญญัติส่งเสริมการพัฒนาฝีมือแรงงาน พ.ศ. 2545)
- หลักสูตรภาคปฏิบัติผู้เข้าอบรมต้องเตรียมคอมพิวเตอร์มาเอง และค่าผู้ช่วยวิทยการ 1500 บาทต่อ 1 วัน
- ในกรณีอบรม ณ ห้องอบรมบริษัทลูกค้า ค่าอบรมจะไม่รวมค่าอาหารกลางวัน และอาหารว่าง 2 มื้อ
- หลักสูตรอาจมีการเปลี่ยนแปลงวันเวลาจัดอบรมตามความสะดวกของลูกค้า

Managing PDPA Risks to Minimize Business Impact
Personal data protection is more than just legal compliance—it’s about trust and organizational security.
If you want to truly understand the PDPA and learn how to manage data privacy risks systematically, this course is for you.
We invite executives and professionals to join us and gain practical strategies to prevent problems before they happen.
Objective:
To equip participants with the knowledge and skills to identify and manage PDPA-related risks that may affect business operations, and to apply appropriate preventive measures within their organizations.
What to Prepare:
- Note-taking materials
- Basic information about your organization’s operations
- Sample data management processes currently in use (if available)
Who Should Attend:
- Executives and department heads responsible for personal data
- IT and Security personnel
- HR and Legal staff
- SME business owners seeking PDPA compliance understanding
- Anyone interested in personal data protection
Time: 09:00 AM to 16:00 PM
Course Cost: 6,000 Baht (Not include vat) Included Manual ,Coffee Break & Lunch
Course Location: Bangkok Business Center Building (Sukhumvit 63 or Soi Eakkamai )
Training Topics:
- Understanding the PDPA and its business implications
- Identifying and assessing risks within the organization
- Best practices for managing personal data correctly
- Preparing for and responding to data breach incidents
- Tools and techniques for effective PDPA risk management
- Case-based analysis: Applying PDPA in participants’ organizations
Orion Forensics Training Calendar Year 2025 | ||||||
PDPA Risks to Minimize Business Impact | ||||||
June | July | Aug | Sept | Oct | Nov | Dec |
Close | Close | 18 | Full | 17 | 17 | Close |
| Register | Register | Register | ||||
| Early Bird !! | Early Bird !! | Early Bird !! | ||||
| Register and pay before the 30 July 2025 | Register and pay before the 30 Aug 2025 | Register and pay before the 30 Oct 2025 | ||||
| 1 Pax 6,000 Baht (10% Discount) | 1 Pax 6,000 Baht (10% Discount) | 1 Pax 6,000 Baht (10% Discount) | ||||
| Saving of 600 Baht | Saving of 600 Baht | Saving of 600 Baht | ||||
| 2 Pax from same company 5,100 Baht (15% Discount) per person. | 2 Pax from same company 5,100 Baht (15% Discount) per person. | 2 Pax from same company 5,100 Baht (15% Discount) per person. | ||||
| Total Saving 900 Baht | ||||||
| **Register after 30 July 2025 Normal rate. | **Register after 30 Aug 2025 Normal rate. | **Register after 30 Oct 2025 Normal rate. | ||||
| **Price excludes vat | **Price excludes vat | **Price excludes vat | ||||
For more information & In-House Training Email : ![]()
Cancellation Policy
- Payment is due upon registration
- Delegates who cancel after registration, or who don’t attend, are liable to pay the full course fee and no refunds can be given
- We reserve the right to postpone or cancel a training course at any time.
- If a training course is cancelled by us, we will inform all registered delegates on the course as soon as possible. Upon the cancellation of a course, we will offer to each delegate a full refund for the cost of the course or alternative dates for the course.
- We will not be held liable for any expenses, either direct or indirect, or for loss of time, earnings or business, incurred as a result of a postponed or cancelled course.

Computer forensics Investigations Course 2 Day (Intensive Course)
Course Level:
The course is aimed at people who are responsible for digital forensic investigations or are wishing to become digital forensic investigators, To be used as a guideline for organizing short-term, intensive training for individuals who will be appointed as digital forensics officers. including: IT security professionals and law enforcement officers.
In-House Training :
- In-House Training or Public Training
- Daily Rate Charge.
- Maximum candidate in the class 12 or more please discuss with Digital Forensics Team directly.
Who should attended: IT Technicians ,IT Security ,Digital forensic investigators, law enforcement officers
Course Location: Bangkok Business Center Building (Sukhumvit 63 or Soi Eakkamai )
Time: 09:00 AM to 16:00 PM
Course Cost: 15,000 Baht (Not include vat) Included Manual ,Coffee Break & Lunch
Day 1 – Computer Forensics
- The needs for Computer Forensics
- Principles of Computer Forensics and Digital/Electronic Evidence
- Crime scene, Digital/Electronic Evidence and Chain of Custody
- Capturing the Data Image and Volatile Data
- Extracting Information from Captured Data
- Breaking Password and Encryption
- Using Computer Forensics Tools
- Investigation and Interrogation
- Digital/Electronic Evidence Analysis and Synthesis
Day 2: Computer Forensics
- Testify in Court, Admissibility requirements
- How to prepare a forensic Report
- Different between Computer Forensics and Network/Internet Forensics
- Network/Internet Forensics
- How to collect network traffic logs
- Using Network/Internet Forensics Tools and Workshop
COURSE REQUIREMENTS
In preparation for the course, participants should download and install the following tools:
- Ram Capture tools
- FTK Imager
- Kali Linux
- Wire shark
- OSINT
Laptop requirements:
OS: Windows 10
CPU: Core i3 or better
RAM: 4GB
For more information or In-House Training please contact Orion Forensics Email : ![]()
Orion Forensics Training Calendar Year 2026 | ||||||
Computer forensics Investigations Course 2 Day (Intensive Course) | ||||||
Jan | Mar | June | Aug | Sep | Nov | Dec |
22-23 | Close | Close | Close | Close | Close | Close |
| Register | ||||||
| Early Bird !! | ||||||
| Register and pay before the 31 Dec 2025 | ||||||
| 1 Pax 15,000 Baht (10% Discount) | ||||||
| Saving of 1,500 Baht | ||||||
| 2 Pax from same company 12,750 Baht (15% Discount) per person. | ||||||
| Total Saving 2.250 Baht | ||||||
| **Register after 31 Dec 2025 Normal rate. | ||||||
| **Price excludes vat | ||||||
Cancellation Policy
- Payment is due upon registration
- Delegates who cancel after registration, or who don’t attend, are liable to pay the full course fee and no refunds can be given
- We reserve the right to postpone or cancel a training course at any time.
- If a training course is cancelled by us, we will inform all registered delegates on the course as soon as possible. Upon the cancellation of a course, we will offer to each delegate a full refund for the cost of the course or alternative dates for the course.
- We will not be held liable for any expenses, either direct or indirect, or for loss of time, earnings or business, incurred as a result of a postponed or cancelled course.
Training atmosphere photos

Open Source Intelligence(OSINT) 101 Course
Participants after completing this course It provides individuals and organizations with the skills, knowledge, and ability to search for information online. efficiently Resulting in better decision making. Risk management and cost reduction as well as preparation Adapt to changing situations In order to deal with new threats that may occur and able to reliably verify information, participants can leverage OSINT digital tools and a variety of techniques to gather information from a variety of sources. on the internet and are aware of the risks from false information and online dangers
Course Level: The course is meticulously crafted to equip you with the most crucial skills, tools, and methodologies required to initiate or enhance your investigative capabilities, while simultaneously ensuring your personal safety. This comprehensive course leverages freely accessible open-source tools to facilitate the investigation of individuals and organizations. Throughout the course, actionable information will be disseminated to students, encompassing intelligence analysts, law enforcement personnel, cyber threat intelligence professionals, investigators, and any other individuals seeking to refine their OSINT expertise.
Who should attended: Anyone that wants to learn OSINT, security professionals, investigators, people interested in security.
Benefits : Participants after completing this course It provides individuals and organizations with the skills, knowledge, and ability to search for information online. efficiently Resulting in better decision making. Risk management and cost reduction as well as preparation Adapt to changing situations In order to deal with new threats that may occur and able to reliably verify information, participants can leverage OSINT digital tools and a variety of techniques to gather information from a variety of sources. on the internet and are aware of the risks from false information and online dangers
Course Location: Bangkok Business Center Building (Sukhumvit 63 or Soi Eakkamai )
Time: 09:00 AM to 16:00 PM
Course Cost: 6,950 Baht (Not include vat) Included Manual ,Coffee Break & Lunch
Course conten
- Introduction to OSINT
- What information to look
- How OSINT can benefit your organization
- Passive VS Active OSINT
- Preparing the environment
- OSINT Information Sources and Collection Techniques
- Advanced Search Techniques In Search engines
- Search engines
- Image OSINT & Metadata
- GPS OSINTs
- Email OSINT
- Username OSINT
- Website OSINT
- Archived & Webpage capture
- OSINT to Detect Data Leaks and Breaches
- Advanced OSINT Techniques
- Dark Web
- OSINT Report
Orion Forensics Training Calendar Year 2025 | ||||||
Open Source Intelligence (OSINT) 101 Course | ||||||
Jan | Mar | June | Aug | Sep | Nov | Dec |
7 | Full | Close | Close | Close | Full | 29 |
| Register | Register | |||||
| Early Bird !! | Early Bird !! | |||||
| Register and pay before the 31 Dec 2024 | Register and pay before the 30 NOV 2025 | |||||
| 1 Pax 6,950 Baht (10% Discount) | 1 Pax 6,950 Baht (10% Discount) | |||||
| Saving of 695 Baht | Saving of 695 Baht | |||||
| 2 Pax from same company 5,907.5 Baht (15% Discount) per person. | 2 Pax from same company 5,907.5 Baht (15% Discount) per person. | |||||
| Total Saving 1042.5 Baht | Total Saving 1042.5 Baht | |||||
| **Register after 30 Dec 2024 Normal rate. | **Register after 30 NOV 2025 Normal rate. | |||||
| **Price excludes vat | **Price excludes vat | |||||
Cancellation Policy
- Payment is due upon registration
- Delegates who cancel after registration, or who don’t attend, are liable to pay the full course fee and no refunds can be given
- We reserve the right to postpone or cancel a training course at any time.
- If a training course is cancelled by us, we will inform all registered delegates on the course as soon as possible. Upon the cancellation of a course, we will offer to each delegate a full refund for the cost of the course or alternative dates for the course.
- We will not be held liable for any expenses, either direct or indirect, or for loss of time, earnings or business, incurred as a result of a postponed or cancelled course.

[Hands-on Workshop] Memory Forensics 101 COURSE (1 DAY)
Memory forensics is a branch of digital forensics that involves the analysis of a computer’s volatile memory (RAM) to extract valuable information and gain insights into the activities that occurred on a system. This is particularly useful for investigating security incidents, analyzing malware, and understanding the behavior of malicious software.
Course Level: This course is intended for Student ,memory analysts , incident responders, digital forensics analysts, law enforcement officers, or anyone who wants to develop the skills necessary . inspired by college or university study, or for the advancement of your career to the basic of memory forensics.
Who should attended: IT Technicians ,IT Security ,Digital forensic Technician,Incident Response Teams
Course Location: Bangkok Business Center Building (Sukhumvit 63 or Soi Eakkamai )
Time: 09:00 AM to 16:00 PM
Course Cost: 6,950 Baht (Not include vat) Included Manual ,Coffee Break & Lunch
Course content
- What is Memory Forensics?
- How is Memory Forensics Different from Hard
Drive Forensics? - Why Memory Forensics?
- Dealing with Live Systems
- Capturing RAM Memory
- Acquisition Tools
- Memory Locations
- Memory Analysis
- Analyzing Processes in Memory Using
Volatility
- Identify Rogue Processes
- INVESTIGATING PROCESS HANDLES &
REGISTRY - Analyze Process DLLs and Handles
- Memory Artifact Timelining
- Look for Evidence of Code Injection
- Extract Processes, and Objects
- Memory analysis Tools
- MEMORY FORENSIC CASE STUDIES
Orion Forensics Training Calendar Year 2026 | ||||||
Memory Forensics 101 COURSE (1 DAY) | ||||||
June | July | Aug | Sept | Oct | Nov | Dec |
Close | Close | Close | Close | 16-17 | Close | Close |
| Register | ||||||
| Early Bird !! | ||||||
| Register and pay before the 30 Sep 2026 | ||||||
| 1 Pax 6,950 Baht (10% Discount) | ||||||
| Saving of 695 Baht | ||||||
| 2 Pax from same company 5,907.5 Baht (15% Discount) per person. | ||||||
| Total Saving 1042.5 Baht | ||||||
| **Register after 30 Sep 2026 Normal rate. | ||||||
| **Price excludes vat | ||||||
For more information & In-House Training Email : ![]()
Cancellation Policy
- Payment is due upon registration
- Delegates who cancel after registration, or who don’t attend, are liable to pay the full course fee and no refunds can be given
- We reserve the right to postpone or cancel a training course at any time.
- If a training course is cancelled by us, we will inform all registered delegates on the course as soon as possible. Upon the cancellation of a course, we will offer to each delegate a full refund for the cost of the course or alternative dates for the course.
- We will not be held liable for any expenses, either direct or indirect, or for loss of time, earnings or business, incurred as a result of a postponed or cancelled course.

Windows Forensics Analysis Course 2 Day
The course is aimed at people who are responsible for digital forensic investigations or are wishing to become digital forensic investigators, including: IT security professionals and law enforcement officers.
Read More
[Hands-on Workshop] Digital Forensic Data Acquisition Course (1 DAY)
A one-day training course for digital forensic technicians who wish to learn how to use Digital forensic data acquisition refers to the process of collecting and extracting digital data from various storage and communication devices, including computer hard drives, mobile devices, cloud storage, and network storage. The purpose of digital forensic data acquisition is to gather digital evidence that can be used in criminal investigations or legal proceedings.
Course Level: The course is aimed at IT Technicians who wish to learn how to use basic forensic techniques data acquisition refers to the process of collecting and extracting digital data from various storage. No previous experience is required.
Who should attended: IT Technicians
Course Location: Bangkok Business Center Building (Sukhumvit 63 or Soi Eakkamai )
Time: 09:00 AM to 16:00 PM
Course Cost: 6,950 Baht (Not include vat) Included Manual ,Coffee Break & Lunch
Course content
- Identification & Seizure of Digital Equipment
- Evidence Handling & Chain of Custody
- Identifying Electronic Sources of Evidence
- Seizure of Electronic Devices
- Forensic Acquisitions
- Source Integrity
- Forensic Image
- Forensic Clone
- FTK Imager
- Hash Values(Digital fingerprint)
- Advance Acquisitions Techniques
- Acquisition of Network Share
- Remote Network Acquisition Tools
- Processing Data Centers with RAID Systems
- Dealing with Live Systems
- Capturing RAM Memory
- How to Create a USB Bootable Drive
Cancellation Policy
- Payment is due upon registration
- Delegates who cancel after registration, or who don’t attend, are liable to pay the full course fee and no refunds can be given
- We reserve the right to postpone or cancel a training course at any time.
- If a training course is cancelled by us, we will inform all registered delegates on the course as soon as possible. Upon the cancellation of a course, we will offer to each delegate a full refund for the cost of the course or alternative dates for the course.
- We will not be held liable for any expenses, either direct or indirect, or for loss of time, earnings or business, incurred as a result of a postponed or cancelled course.




