| |
Aug 06, 2026
|
|
|
|
|
CFI 2082 - Cyber Forensics Credits: 3 Hours/Week: Lecture 2 Lab 2 Course Description: This course provides an in-depth study of commonly used forensic tools in corporate and law enforcement environments. This course also reviews and solidifies important concepts in forensic methodology and artifacts. MnTC Goals None
Prerequisite(s): CFI 1081 with a grade of C or higher OR instructor consent Corequisite(s): None Recommendation: None
Major Content
-
Acquisition of a hard disk
-
Write-blocking technologies
-
The basics of acquiring a forensically sound copy of data from a removable disk
-
Acquisition using a forensically sound Linux operating system
-
Drive-to-drive acquisition
-
Network crossover-cable acquisition
-
Previewing computer systems
-
Verification of an evidence file
-
Analysis Techniques
-
File types
-
Creation of keywords and searching
-
Basic bookmarking
-
Signature analysis
-
Hash analysis
-
Installing external viewers
-
Detailed copy/UnErase options
-
Restoring evidence
-
Timeline view
-
Single files
-
Logical evidence files
-
Examination methods concerning flash cards & similar devices
-
Compound files
-
Mounting and searching of compound files
-
Documenting data contained within these compound files
-
Pitfalls of not examining compound files properly
-
Conditions and queries
-
Uses
-
Creating an index
-
Querying an index
-
Forensic Concepts and Methodology
-
Creating Forensic case file
-
Safeguarding and preserving evidential data
-
Archiving and reopening an archived case
-
External processing
-
Virtual File System (VFS) Module
-
Physical Disk Emulator (PDE) Module
-
Virus scanning
-
Dynamic mounting of compound files
-
Running a target system within a virtual environment
-
Principles of attempting to recover data lost through the partitioning or formatting process
-
Partition recovery
-
Folder recovery
-
Data carving (manually vs. EnScript)
-
Reporting
-
Organizing data and creating reports
-
Report formats
-
Exporting metadata
-
Review of Windows artifacts
-
Review of file systems and disk partitioning
-
Search techniques
-
Reviewing search hits and bookmarking
-
GREP searching
Learning Outcomes At the end of this course, students will be able to:
- demonstrate forensic methodology
- perform imaging and analysis of Windows-based systems
- perform advanced searching and filtering techniques.
- perform external analysis using forensic tools.
- demonstrate knowledge of how to detect hacking attacks.
- describe how to properly extract evidence to report the crime and conduct audits to prevent future attacks.
- explain the principles of digital forensics.
- describe incident handling and incident response.
Minnesota Transfer Curriculum (MnTC): Goals and Competencies Competency Goals (MnTC Goals 1-6) None Theme Goals (MnTC Goals 7-10) None
Practicum hours per week: 0 Courses and Registration
Add to Portfolio (opens a new window)
|
|