Module Overview
This module enables students to build on their cyber security knowledge using digital evidence collection, preservation, and analysis. The module explores the tools and techniques used to investigate data, for example; data recovery, network forensics, and malware analysis. The module also explores the legal and ethical considerations in cyber forensics, ensuring students understand the importance of confidentiality, integrity, and availability. By the end of the module, students will have an awareness of cyber forensics approaches and consider how these could be applied in practice. The module encourages students to understand how digital data can be used in cyber security.
This module covers the investigation and forensics of digital technologies, including; security mechanisms, cryptography, encryption, hash functions, digital signatures, key management, authentication and access control; software security, digital forensics tools, malware, firewalls, intrusion detection, security policies, law and ethics in information security, privacy and anonymity of data.
Note: I prepared the module content and syllabus for this course but did not deliver the teaching.
Syllabus
- Week 1: Foundations & Legal Framework
- Week 2: Evidence Collection & Imaging
- Week 3: File Systems (NTFS/FAT/EXT)
- Week 4: OS Forensics (Registry/Logs)
- Week 5: Memory Forensics (RAM analysis)
- Week 6: Network Forensics & Traffic
- Week 7: Mobile Forensics (iOS/Android)
- Week 8: Cloud Forensics & Virtualization
- Week 9: Steganography & Anti-Forensics
- Week 10: Email & Browser Forensics
- Week 11: Malware Forensics Intro
- Week 12: Reporting & Expert Witnessing