In this course students will learn how to understand and differentiate between file systems and operating systems; explain in detail the FAT file system; be exposed to the NTFS file system; identify Windows and registry artifacts; understand hashing and its uses in digital forensics; understand Fourth Amendment considerations when searching and seizing digital evidence, chain of custody; use hardware write blockers to perform data acquisitions using methods and tools discussed in class; perform basic data recovery; understand file signatures and its uses and be introduced to memory (RAM) forensics and analysis.
CS 505 Computer Networks (or Permission of Department)