Aug 06, 2026  
2026-2027 Course Catalog 
    
2026-2027 Course Catalog
Add to Portfolio (opens a new window)

CFI 2082 - Cyber Forensics

Credits: 3
Hours/Week: Lecture 2 Lab 2
Course Description: This course provides an in-depth study of commonly used forensic tools in corporate and law enforcement environments. This course also reviews and solidifies important concepts in forensic methodology and artifacts. 
MnTC Goals
None

Prerequisite(s): CFI 1081  with a grade of C or higher OR instructor consent
Corequisite(s): None
Recommendation: None

Major Content
  1. Acquisition of a hard disk
  1. Write-blocking technologies
  2. The basics of acquiring a forensically sound copy of data from a removable disk
  3. Acquisition using a forensically sound Linux operating system
  4. Drive-to-drive acquisition
  5. Network crossover-cable acquisition
  6. Previewing computer systems
  7. Verification of an evidence file
  1. Analysis Techniques
  1. File types
  2. Creation of keywords and searching
  3. Basic bookmarking
  4. Signature analysis
  5. Hash analysis
  6. Installing external viewers
  7. Detailed copy/UnErase options
  8. Restoring evidence
  9. Timeline view   
  10. Single files
  11. Logical evidence files
  12. Examination methods concerning flash cards & similar devices
 
  1. Compound files
  1. Mounting and searching of compound files
  2. Documenting data contained within these compound files
  3. Pitfalls of not examining compound files properly
  1. Conditions and queries
  1. Uses
  2. Creating an index
  3. Querying an index
  1. Forensic Concepts and Methodology
  1. Creating Forensic case file
  2. Safeguarding and preserving evidential data
  3. Archiving and reopening an archived case
  1. External processing
  1. Virtual File System (VFS) Module
  2. Physical Disk Emulator (PDE) Module
  3. Virus scanning
  4. Dynamic mounting of compound files
  5. Running a target system within a virtual environment
  1. Principles of attempting to recover data lost through the partitioning or formatting process
  1. Partition recovery
  2. Folder recovery
  3. Data carving (manually vs. EnScript)
  1. Reporting
  1. Organizing data and creating reports
  2. Report formats
  3. Exporting metadata
  1. Review of Windows artifacts
  2. Review of file systems and disk partitioning
  3. Search techniques
  1. Reviewing search hits and bookmarking
  2. GREP searching
 

Learning Outcomes
At the end of this course, students will be able to:

  1. demonstrate forensic methodology
  2. perform imaging and analysis of Windows-based systems
  3. perform advanced searching and filtering techniques.
  4. perform external analysis using forensic tools.
  5. demonstrate knowledge of how to detect hacking attacks.
  6. describe how to properly extract evidence to report the crime and conduct audits to prevent future attacks.
  7. explain the principles of digital forensics.
  8. describe incident handling and incident response.

Minnesota Transfer Curriculum (MnTC): Goals and Competencies
Competency Goals (MnTC Goals 1-6)
None
Theme Goals (MnTC Goals 7-10)
None

Practicum hours per week: 0


Courses and Registration



Add to Portfolio (opens a new window)