IT6853 – Computer Forensics
Note: These resources were developed with the support from Affordable Learning Georgia (ALG)- Round 18, Grant#549, 2021.
Introduction
IT6853 – Syllabus – HERE
Modules
Module 1 – Introduction to Computer Forensics
Module 2 – Windows File System and Artifacts
Module 3 – Linux File System and Artifacts
- Study Guide
- Slides
- Lecture
- Reading #1
- Reading #2
- Resources – video Inode
- Resources – Example of Linux Forensics
- Lab C
Module 4 – Introduction to Partitions
- Study Guide
- Slides
- Lecture
- Reading #1
- Reading #2
- Resources – MBR
- Resources – MBR_GPT_cheatsheet
- Resources – Paper #1
- Resources – Paper #2
- Quiz 1
Module 5 – Data Acquisition
- Study Guide
- Slides
- Lecture
- Reading #1
- Reading #2
- Resources – Procedure_for_Data_Acquisition
- Resources – Paper #1
- Resources – Paper #2
- Lab D
Module 6 – Windows Registry
- Study Guide
- Slides
- Lecture
- Reading #1
- Resources – Windows_Registry_Documentation
- Resources – Paper #1
- Quiz 2
Module 7 – Web Browser Forensics
Module 8 – Network Forensics
- Study Guide
- Slides
- Lecture
- Reading #1
- Resources – Paper #1
- Resources – Video_example
- Resources – Network_Basis
- Lab E
Module 9 – Automating Forensic Analysis and Reporting
- Study Guide
- Slides
- Lecture
- Reading #1
- Reading #2
- Resources – Forensic_Tools
- Resources – Forensic_Tools2
- Lab F
Module 10 – Data/File Carving and Steganography
- Study Guide
- Slides
- Lecture
- Reading #1 – File Carving
- Reading #2 – Steganography
- Resources – Paper #1
- Resources – Paper #2
- Lab G
Module 11 – Email Forensics
- Study Guide
- Slides
- Lecture
- Reading #1
- Reading #2
- Resources – Paper #1
- Resources – Gmail_Data_For_Forensics
- Resources – PST_Files
- Resources – Email_Attachment_TimeStamps
- Quiz 3
Module 12 – Mobile Forensics
- Study Guide
- Slides
- Lecture
- Reading #1
- Reading #2
- Resources – Paper #1
- Resources – Paper #2
- Resources – Challenges_Mobile_Forensics
- Lab H
Module 13 – Recovering Passwords
Module 14 – Log Analysis
- Study Guide
- Slides
- Lecture
- Lab I (Section B)