I am the module leader for this module. Robert ludwiniak will be team teaching the module with me.
This structure and other information should be considered a draft. All this is subject to change without notice until it is presented in a lecture.
As an aid for students I may have video presentations covering some of the lecture material. This is not exaustive, and I will not be preparing such material for all lectures. It is not a replacement for attenting the University. However you may find it useful. If the video is available it will be shown in the plan. Note if a link appears broken, then the material is not yet available. Check back later.
| Module Week | Event | Subject | Slides | Extra Material |
|---|---|---|---|---|
| 1 | Lecture A | Introduction to Forensics (RL) | PPT PDF | - |
| Lecture B | Linux Overview + Caine (GR) | PPT PDF | - | |
| Practical | Getting Started with Caine | Using Linuxzoo Video | ||
| 2 | Lecture A+B | Essential Linux for Forensics (GR) | PPT PDF | - |
| Practical | Essential Linux (ls,cd,cat,etc) | - | ||
| 3 | Lecture A+B | Linux filesystem + Searching (GR) | PPT PDF | - |
| Practical | Filesystem Linux (find,grep,fdisk,etc) | - | ||
| 4 | Lecture A | Forensic Processes (RL) | PPT PDF | - |
| Lecture B | Advanced Search in Linux (GR) | PPT PDF | - | |
| Practical | Extended Linux - regexp,tail,sort,mount | - | ||
| 5 | Lecture A | The PC BOOT process (RL) | PPT PDF | - |
| Lecture B | Advanced Linux (GR) | PPT PDF | - | |
| Practical | Advanced Linux - xxd, gui, autopsy | - | ||
| 6 | Lecture A+B | Forensic Acquisition (RL) | PPT PDF | - |
| Practical | Image Capture and Validation | - | ||
| 7 | Lecture A+B | Disk Analysis (RL) | PPT PDF | - |
| Practical | Storage device analysis | - | ||
| 8 | Lecture A+B | Filesystem Analysis (RL) | PPT PDF | - |
| Practical | Essential Filesystem processing | - | ||
| 9 | Lecture A+B | Data Analysis (RL) | PPT PDF | - |
| Practical | Advanced Filesystem Processing | - | ||
| 10 | Lecture A | Registry Forensics (RL) | PPT PDF | - |
| Lecture B | Activity/Browser/app level/Timeline (RL) | PPT PDF | - | |
| Practical | File Contents Forensics | - | ||
| 11 | Lecture A+B | Real-World Walkthrough case study (RL) | PPT PDF | - |
| Practical | Browser and Activity Forensics | - | ||
| 12 | Lecture A+B | Encase (RL) | PPT PDF | - |
| Practical | -- No New Labs -- Revision+Catchup | - | ||