CSC-274 Digital Forensics

Computer Forensics and Investigation presents principles and techniques of conducting computing investigations. Computer forensics involves obtaining and analyzing digital information for use as evidence in civil, criminal, or administrative cases. Topics include: ethics, current computer forensics tools, digital evidence controls, processing crime and incident scenes, data acquisition, e-mail investigations, and becoming an expert witness. Hands-on experience, using a forensic software package will be part of the course.

Credits

3

Prerequisite

CSC-260 or Equivalent Experience

Lecture Contact Hours

3

Lab Contact Hours

0

Other Contact Hours

0

Department

  • Computer Science

Grading Scheme

  • Letter

SUNY Gen Ed Credit

  • No

Semesters Course Will Be Offered

  • Spring

Course Learning Outcomes

  1. Describe a computer investigation and the steps involved to complete a case
  2. Use appropriatetools for forensic investigations
  3. Prioritize tasks in an investigation
View Course Outline

CSC 274: Digital Forensics

Department

Computer Science

Course Description

Computer Forensics and Investigation presents principles and techniques of conducting computing investigations. Computer forensics involves obtaining and analyzing digital information for use as evidence in civil, criminal, or administrative cases. Topics include: ethics, current computer forensics tools, digital evidence controls, processing crime and incident scenes, data acquisition, e-mail investigations, and becoming an expert witness. Hands-on experience, using a forensic software package will be part of the course.

Credit Hours

3

Contact Hours

Lecture3
Lab0
Other0

Grading Scheme

Letter

Semester(s) Course Will Be Offered

Spring

Prerequisites

CSC-260 or Equivalent Experience

Course Learning Outcomes

  1. Describe a computer investigation and the steps involved to complete a case
  2. Use appropriatetools for forensic investigations
  3. Prioritize tasks in an investigation

Topic Outline

  1. Computer Forensics as a Profession
  2. Definitions, history, resources
  3. Computing Investigation Processes
    1. Systematic approach, data-recovery, steps in an investigation
  4. Microsoft Operating Systems, Boot Processes and Disk Structures
    1. Understanding the file systems, boot and startup tasks
    2. Macintosh and Linux Operating Systems, Boot Processes and Disk Structures
    3. Understanding the file systems, boot and startup tasks, and other disk structures
  5. The Investigator's Office
    1. Forensic lab certification requirements, physical layout of a lab and workstations
    2. Current Computer Forensics Tools
  6. Explore command line and GUI tools, hardware tools
  7. Digital Evidence Controls
    1. Identifying, securing at the scene, cataloging and processing evidence
  8. Crime/Incident Scene Processing
    1. Preparing for a search, seizing digital evidence, reviewing a case