CHE-20042 - Digital Forensics
Coordinator: Robert A Jackson Room: LJ1.16 Tel: +44 1782 7 33042
Lecture Time: See Timetable...
Level: Level 5
Credits: 15
Study Hours: 150
School Office: 01782 734921

Programme/Approved Electives for 2020/21


Available as a Free Standing Elective






Barred Combinations


Description for 2020/21

This module provides an introduction to the subject of Digital Forensics, which is becoming increasingly important now that computers and mobile devices are frequently a subject of criminal investigations. It will cover basic technical concepts, labs and tools for carrying out forensic investigations, how evidence is collected, specific issues with Windows operating systems, mobile devices, internet and social media, multimedia forensics and how the law currently applies to digital forensics. As well as lectures and workshops, the students will be introduced to digital forensics software, and prepare a group digital presentation.

To provide an introduction to Digital Forensics including the following topics:
-Introduction to digital forensics
-Technical concepts computer hardware and software and definitions
-Labs and tools for carrying out digital forensics investigations
-Collecting evidence
-Specific systems Windows, Linux, Apple IOS
-Mobile devices
-Internet/E-mail/Social media
-Network forensics
-Multimedia forensics
-Digital forensics and the law

Talis Aspire Reading List
Any reading lists will be provided by the start of the course.

Intended Learning Outcomes

explain the key technical concepts involved in digital forensics, including computer storage and memory in different environments, data types and file systems
: 1
describe artifacts of operating systems, including vulnerabilities (concentrating on Windows as this is most encountered): 1
describe the digital forensics of mobile devices and how data can be recovered from them, and demonstrate how digital forensics methods can be applied to the internet, including e-mail and social networks: 1
give examples of how 'anti-forensics' methods are used to hide or destroy data, and discuss how the law is applied in digital forensics investigations: 1
research, prepare and present a group presentation on a topic of relevance to digital forensics: 3
discuss how digital forensics investigations are carried out and describe how evidence is collected using digital tools and appropriate software: 2

Study hours

10 hours of lectures
10 hours of workshops (including use of digital forensics software)
30 hours - preparation of group digital presentation
40 hours - working on independent case study
60 hours - independent study and class test completion

School Rules

Successful completion of CSC-10025 or CHE-10039

Description of Module Assessment

1: Class Test weighted 20%
Class Test
An unseen 1 hour class test consisting of a series of short answer questions on various digital forensics topics.

2: Case Study weighted 40%
In Depth Case Study
Students will carry out an in depth case study individually on a topic allocated from those covered in the workshops. The case study will be presented in the form of a report (equivalent to ~2000 words) describing the case and the results and conclusions obtained.

3: Group Presentation weighted 40%
Group Digital Presentation
Students will be divided into small groups (~4 students) and prepare a 30 minute digital presentation. Each student will make an individual contribution (~7-8 minutes) to the presentation, and their mark for the presentation will be a combination of self, peer and tutor assessment.