CS X410 - Digital Forensics
Course Description
Digital forensics involves the recovery and analysis of data recovered from digital devices. It involves all devices able to store digital data. The goal of the forensic examiner is to identify, collect, examine \ analyze digital data while ensuring its integrity. It is a formal analysis of digital evidence to provide or disprove a committed violation. The investigator must understand the chain of custody, evidence preservation as well as testifying in administrative \ criminal proceedings.Learner Outcomes
By the end of this course, students will:
- Develop an understanding of computer-based investigations.
- Articulate the strategy to conduct an efficient investigation service.
- Identify the validation process to create a forensic image.
- Articulate the boot process & identify the most used filesystems.
- Identify the key data points to support or not support the hypothesis about the user’s actions on the systems.
- Articulate how to identify & recover common artifacts of common operating systems.
- Articulate the steps to analyze RAM.
- Articulate the investigation techniques of e-mail forensics.
- Analyze internet artifacts.
- Articulate the steps of open-source intelligence techniques.
- Articulate common network protocols, hardware, models to connect devices & share information.
- Develop a forensic examiner report.
- Articulate expert witness ethics.
Instructors
Applies Towards the Following Certificates
- Applied Cybersecurity : Required