EE547 Digital Forensics
Schedule
Wed 13h00-15h00 (lecture)
Wed 15h00-16h00 (labo)
References
- B. Carrier. “File System Forensic Analysis”, Addison Wesley, 2005, 569 p.
- M.H. Ligh et al., “The Art of Memory Forensics – Detecting Malware and Threats in Windows, Linux and Mac Memory”, Wiley, 2014, 886 p.
- Harlan Carvey, "Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 8", 4th Edition, Syngress, 210, 350 p.
Resource
- All lab resources are available on your USB thumbdrive
- Aide-mémoire
- Online tutorial on dd utility
Wk |
Date |
Lectures |
References |
Others |
Laboratories |
|
1 |
12 Jan |
Carrier §1-3 |
|
(due 19 Jan at 13h00) |
||
2 |
19 Jan |
Carrier §4-7 |
|
Lab 2 - Volumes and Partitions (due 26 Jan at 13h00) |
||
3 |
26 Jan |
Carrier §8-10 |
|
(due 2 Feb at 13h00) |
||
4 |
2 Feb |
Carrier §11-13 |
|
(due 16 Feb at 13h00) |
||
5 |
9 Feb |
Carvey |
|
|
||
6 |
16 Feb |
Windows (con't) |
Carvey |
|
(due 23 Feb at 13h00) | |
7 |
23 Feb |
Linux (con't) |
|
(due 2 Mar at 13h00) |
||
8 |
2 Mar |
Ligh §1, 3-5 Ligh §6 |
Paper selection |
(due on 9 Mar at 13h00) |
||
9 |
9 Mar |
Ligh §7-8 |
(due on 16 Mar at 13h00) |
|||
10 |
16 Mar |
Ligh §13 |
|
(due on 23 Mar at 13h00) |
||
11 |
23 Mar |
|
|
Final exercise (Instructions, template) (due on 20 Apr at 13h00) |
||
12 |
30 Mar |
No class (work on exercise and presentation) |
|
|
||
13 |
6 Apr |
Student presentations (schedule, eval sheet) |
|
|
||
14 |
|
|
|
|
|