EE547 Digital Forensics

Schedule

Wed 13h00-15h30 (lecture in s4214)
Wed 15h30-16h00 (lab in s5104)

References

  • B. Carrier. “File System Forensic Analysis”, Addison Wesley, 2005, 569 p.
  • M.H. Ligh et al., “The Art of Memory Forensics – Detecting Malware and Threats in Windows, Linux and Mac Memory”, Wiley, 2014, 886p.
  • Harlan Carvey, “Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 8”, 4th Edition, Syngress, 210, 350p.

Resource

WeekDateLectureReferencesOthersLaboratories
1
10 Sep 25
Intro to digital forensics (recording)Carrier §1-3Lab setup
Lab 1 – Intro to X-Ways
(due 20 Sep at 13h00)
217 Sep 25Volumes and partitions (recording)Carrier §4-7Lab 2 – Volumes and Partitions
(due 27 Sep at 13h00)
324 Sep 25FAT32 file system (recording)Carrier §8-10Lab 3 – FAT32
(due 4 Oct at 13h00)
41 Oct 25NTFS file system (recording)Carrier §11-13Lab 4 – NTFS
(due 18 Oct at 13h00)
58 Oct 25Windows (recording)CarveyLab 4 con’t
615 Oct 25Windows (con’t)
Linux (recording)
CarveyLab 5 – Windows 10
(due 25 Oct at 13h00)
722 Oct 25Linux (con’t)Lab 6 – Linux
(due 1 Nov at 13h00)
829 Oct 25Windows Objects (recording)
Process, handles and tokens (recording)
Ligh §1, 3-5Ligh §6Must have
selected a
research paper
Lab 7 – Memory Acquisition
(due on 8 Nov at 13h00)
95 Nov 25Process memory internals (recording)Ligh §7-8Lab 8 – Malicious Processes
(due on 15 Nov at 13h00)
1012 Nov 25Kernel forensics and rootkits (recording)Ligh §13Lab 9 – Rootkits
(due on 22 Nov at 13h00)
1119 Nov 25Final exercise
(recording)
Final exercise (Instructions, template)
(due on 6 Dec at 13h00)
1226 Nov 25No class (work on exercise and presentation)Final exercise
133 Dec 25Student presentations (schedule, eval sheet)
1410 Dec 25No class (end of term)

Scroll to Top