IST463: Digital Evidence and Computer Investigation
by Daniel Demenetiev
Syllabus
- Lecture notes:
- Introduction to Computer Forensics
- Understanding Computer Investigation
(also read the second chapter from the book)
- Lecture 3:
- Hexadecimal numbers
- LAB: Learning FAT12 with WinHex
- Forensically cleaned media
- LAB: Working on an evidence floppy disk
- Using FTK for the same floppy case
- LAB: Working with an evidence CD
- Known plain text attack (theory) and
performing KnownPlaintext Attack with ZipKey
- Turn AutoRun CD on and off
- LAB: Flash Card case
- FTK Ssearch Lab: please answer the following questions about this
hard disk image.
- Analysing Windows Registry
- LAB: work on the arson case. In this case you may assume
that you already acquire the forensic image of the evidence
hard drive. As a result you need to present your work journal and FTK report with
all the evidence found bookmarked.
- Projects and assignments:
- Project 1: floppy drive test policy. Due date is Feb 16, 2008 by midnight.
- Project 1.5: Forensic image of a floppy disk. Due date is TBA.
- Project 2: floppy case report (analysis only). Due date is Saturday, March 1, 2008 by 11:59pm.
- Project 3: CD case report (evidence report only). Due date is Saturday, April 12, 2008.
- Project 4: Flash card case. Due date is Saturday, April 19, 2008..
- Project 5: creating a hard drive "map" from MBRs and boot sectors (in-class project).
- Project 6: wiping a hard drive and creating a forensic copy with Solo-3 (in-class project).
- Project 7: arson case due before the final exam.
- Links to additional information sources: