Course details
Digital Forensics (in English)
DFAa Acad. year 2023/2024 Summer semester 5 credits
The course focuses on the role of computer forensics and the methods used in the investigation of computer crimes. The course explains the need for proper investigation and illustrates the process of locating, handling, and processing computer evidence. A detailed explanation of how to efficiently manage a forensics investigation and how to preserve and present evidence is covered.
Guarantor
Course coordinator
Language of instruction
Completion
Time span
- 26 hrs lectures
- 13 hrs laboratories
- 13 hrs projects
Assessment points
- 55 pts final exam (written part)
- 30 pts numeric exercises
- 15 pts projects
Department
Lecturer
Mutua Nelson Makau, M.Sc. (DIFS)
Ryšavý Ondřej, doc. Ing., Ph.D. (DIFS)
Instructor
Mutua Nelson Makau, M.Sc. (DIFS)
Ryšavý Ondřej, doc. Ing., Ph.D. (DIFS)
Learning objectives
The aim is to understand principles of computer forensics and the basic concepts used in a computer forensics examination; introduces techniques required for conducting a forensic analysis of systems and data.
Student acquaints basic concepts and principles of computer forensics and skills in a computer forensic examination.
Why is the course taught
The course prepares students for the possible role of cyber attack investigator or forensic analyst within security teams.
Prerequisite knowledge and skills
Basic knowledge of operating systems, storage media, networks, and the ability to create simple programs.
Study literature
- Nipun Jaswal: Hands-On Network Forensics: Investigate network attacks and find evidence using common network forensic tools, Packt Publishing, 2019.
- Bruce Nikkel , Practical Linux Forensics, No Starch Press, 2021
Fundamental literature
- Daren Hayes, Practical Guide to Digital Forensics Investigations, Pearson IT Certification; 2nd edition, 2020.
- Gerard Johansen: Digital Forensics and Incident Response: Incident response techniques and procedures to respond to modern cyber threats, Packt Publishing; 2nd edition, 2020
Syllabus of lectures
- Investigation Techniques
- Data Acquisition
- Data Recovery and Analysis
- Windows System Forensics
- Microsoft 365 Forensics
- Web Browser Forensics
- Events and Logs
- Network Forensics
- Encryption Traffic Analysis
- Memory Forensics
- Malware Analysis
- Password Recovery
- Case Study
Syllabus of laboratory exercises
Hands-on activities in the following areas:
- Investigation Techniques Basics
- Data Acquisition
- Data Recovery and Analysis
- Windows System Forensics
- Microsoft 365 Forensics
- Web Browser Forensics
- Events and Logs
- Network Forensics
- Encryption Traffic Analysis
- Memory Forensics
- Malware Analysis
- Password Recovery
- Case Study
Syllabus - others, projects and individual work of students
Performing the investigation of the selected cases. Solving the cases and writing the report.
Progress assessment
- Project (15 points).
- Hands-on labs (30 points). Missed labs can only be replaced if there is a serious obstacle in the study.
- Final exam (55 points). Minimum of 20 points of the final exam is necessary to pass the course.
Controlled activities include the project (15 points), hands-on labs (30 points), and the final exam (55 points). Missed labs can only be replaced if there is a serious obstacle in the study.
Exam prerequisites
How to contact the teacher
As part of face-to-face activities. Possibilities of individual consultations during the teacher's consultation hours or at other times by appointment.
Course inclusion in study plans
- Programme IT-MGR-2, field MBI, MBS, MGM, MIN, MIS, MMM, MPV, MSK, any year of study, Elective
- Programme IT-MGR-2 (in English), field MGMe, any year of study, Compulsory-Elective group I
- Programme MIT-EN (in English), any year of study, Compulsory-Elective group B
- Programme MITAI, field NADE, NBIO, NCPS, NEMB, NEMB up to 2021/22, NGRI, NHPC, NIDE, NISD, NISY, NISY up to 2020/21, NMAL, NMAT, NNET, NSEC, NSEN, NSPE, NVER, NVIZ, any year of study, Elective