Every click, file, log, message and network connection can leave a digital trace. This course introduces you to the world of digital forensics, where specialist tools and techniques are used to investigate devices, networks and cyber incidents.
Purpose
Digital forensics is a vital area of computing and cyber security. As individuals and organisations rely more heavily on digital systems, there is a growing need to investigate security breaches, recover digital evidence and understand how incidents have occurred.
This course introduces learners to the processes and procedures used in digital forensic investigations. You will explore how evidence is identified, preserved, acquired, examined and analysed. You will also consider the legal, ethical and professional responsibilities involved in handling digital evidence.
Learners will investigate the use of forensic tools, system logs, network data and file system structures across different operating systems. You will also develop a forensic examination plan and make recommendations to improve system security based on investigation findings.
Goals
By the end of this course, learners will be able to:
· Understand what digital forensics is and why it is important.
· Examine the processes and procedures used in digital forensic investigations.
· Understand how digital evidence should be collected, preserved and analysed.
· Explore legal, ethical and professional guidelines for forensic investigation.
· Investigate the role of organisations and agencies involved in cyber crime and digital evidence.
· Use hardware and/or software tools to support a digital forensic investigation.
· Examine file system structures across different operating systems.
· Develop a forensic examination plan.
· Make recommendations to improve system security following an investigation.
· Develop analytical, problem-solving, communication and critical thinking skills relevant to cyber security and digital investigation.
On this course, you may explore topics such as:
· The meaning and purpose of digital forensics.
· The stages of a digital forensic investigation.
· Evidence assessment, acquisition, preservation, examination and analysis.
· Sources of digital evidence, including logs, access records, system data and network activity.
· Legal and ethical requirements, including the Data Protection Act 2018, Computer Misuse Act 1990 and Freedom of Information Act 2000.
· Law enforcement and professional guidelines linked to digital evidence.
· Hardware and software tools used in forensic investigation.
· SIEM tools, system logs, network monitoring and penetration testing tools.
· Investigation of devices, networks or cyber attacks.
· File system structures across operating systems such as Windows, Linux, UNIX, MacOS and Android.
· Forensic examination planning and recommendations for improving system security.
Assessment may include written explanations, diagrams, investigation plans, practical forensic activities, tool comparisons, case-study analysis and evaluative reports.