EE547 Digital Forensics

Schedule

Wed 13h00-15h00, s4214 (lecture)
Wed 15h00-16h00, s4126 (labo)

Availability for s4126

Mon 8h00-13h30, Tue 8h00-16h30, Wed 8h00-16h30, Thu 12h00-16h30, Fri 8h00-12h40

Lab report submission

Lab reports are to be submitted prior to the beginning of the next lab. Work submitted late will be subject to a 15% penalty per day unless an arrangement has been made with the instructor prior to the due date.

You must complete and submit all your laboratories in order to pass the course.

References

Some useful resources to supplement the lecture material (see the Course Description page to get the list of mandatory textbooks)

  • B. Carrier. “File System Forensic Analysis”, Addison Wesley, 2005, 569 p.
  • M.H. Ligh et al., “The Art of Memory Forensics – Detecting Malware and Threats in Windows, Linux and Mac Memory”, Wiley, 2014, 886 p.
  • Harlan Carvey, "Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 8", 4th Edition, Syngress, 210, 350 p.

Resource

 

Wk

Date

Lectures

References

Others

Laboratories

1

16 Sep

Intro to digital forensics

Carrier §1-3

 

Lab 1 - Intro to X-Ways

(Resources and Disk image)

(due 23 Sep at 13h00)

2

23 Sep

Volumes and partitions

Carrier §4-7

 

Lab 2 - Volumes and Partitions

(due 30 Sep at 13h00)

3

30 Sep

FAT32 file system

Carrier §8-10

 

Lab 3 - FAT32

(due 7 Oct at 13h00)

4

7 Oct

NTFS file system

Carrier §11-13

 

Lab 4 - NTFS

(due 21 Oct at 13h00)

5

14 Oct

Windows

Carvey

 

 

6

21 Oct

Windows (con't)

Linux

Carvey

 

Lab 5 - Windows 10

(due 28 Oct at 13h00)

7

28 Oct

Linux (con't)

 

 

 

8

4 Nov

Windows Objects

Ligh §1, 3-5

Project proposal

Lab 6 - Linux

(due 11 Nov at 13h00)

9

11 Nov

Process, handles and tokens

Ligh §6

Final Exercise

(Brief, Instructions)

Lab 7 - Memory Acquisition

(due on 18 Nov at 13h00)

10

18 Nov

Process memory internals

Ligh §7-8

 

Lab 8 - Malicious Processes

(due on 25 Nov at 13h00)

11

25 Nov

Kernel forensics and rootkits

Ligh §13

 

Lab 9 - Rootkits

(due on 2 Dec at 13h00)

12

2 Dec

Student presentations

 

 

 

13

9 Déc

Student presentations

 

 

 

14

11 Déc

Exam week (student presentations)