|
|
|
Sep 21, 2026
|
|
CSEC 220 - CHFI 3: Operating Systems Forensics Credits: 3 Semesters Offered: Spring, Summer and Fall Description Third volume in a four-course series preparing students for the EC-Council Computer Hacking Forensic Investigator (CHFI) certification. Builds on foundational forensic knowledge by introducing advanced investigative techniques for extracting, interpreting, and documenting evidence from Microsoft Windows, Apple macOS, and Linux environments. Examines file systems, memory, logs, and system artifacts using both commercial and open-source tools. Covers file recovery, timeline analysis, malware trace discovery, and live response procedures. Culminates in the development of a comprehensive forensic examination report based on simulated case data.
Student Learning Outcomes
- Acquire digital evidence from Windows, macOS, and Linux operating systems, including memory, disk, and live system artifacts, using forensic methods.
- Analyze operating system-specific system files, event logs, and registry or artifact structures to identify user activity and indications of malicious behavior.
- Recover deleted files and forensic artifacts from New Technology File System (NTFS), Apple File System (APFS), and Extended File System version 4 (EXT4) file systems with appropriate forensic tools.
- Investigate malware persistence and tampering occurring on different operating systems through advanced artifact analysis.
- Construct forensic timelines and reconstruct event sequences using the correlation of logs, timestamps, and platform-specific artifacts.
- Document forensic findings in a professionally formatted examination report suitable for legal and investigative audiences.
Prerequisite: CSEC 121 Corequisite: None Graded: Letter Grade
Add to Portfolio (opens a new window)
|
|
|