Digital Forensics
This course aims to teach student how to conduct a digital forensics analysis of the file system, e.g. NTFS and FAT, volatile memory, and network traffic, using a sound digital investigation process. It begins by a basic background of interoperating raw-data and timestamps. Then NTFS and FAT file system layout will be discussed in detail. The basic of memory acquisition, analysis and evidence extraction will also be introduced during the course. Finally, different topic may cover after the essential topics get introduced, such as data carving, evidence inference and reconstructing the digital crime scene.