Key information
Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: 7
Delivered by: NCI
Awarding Institution: German University of Digital Science
Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350
Microcredential Information
This module aims to enable learners to develop a knowledge, skills and competence to approach a Digital Forensics investigation whilst safe-guarding the chain of custody of acquired digital forensic evidence. This module also aims to develop skills associated with eDiscovery. Learners will gain practical experience in using various tools used in Windows forensics, Linux forensics, mobile forensics, network forensics and eDiscovery. This module provides an in-depth coverage of various sub-domains of digital forensics and how it is related to eDiscovery.
Key Details
Time commitment
- (Estimated) Total workload: 125 hours
- Directed e-Learning Activities: 12 hours
- Synchronous Lectures: 12 hours
- Tutorial Sessions: 12 hours
- Private study including examination preparation: 89 hours
Assessment
Type Assessment Description Outcome addressed % Assessment Date Continuous Assessment 1 This assessment will consist of practical tasks in the form of a LO1, LO2, LO3 40 Week 6 homework. This will assess learners’ knowledge and competences on digital forensic processes, concepts and various tools used in digital investigations.
Continuous Assessment 2 A proctored assessment that will assess learner’s knowledge and analytical skills regarding enterprise search and eDiscovery rules, processes, and platforms. Learners will conduct practical activities using various tools and write a report on their work. LO4, LO5 60
Week 11 Reassessment strategy: The reassessment strategy for this module will consist of an assessment that will evaluate all learning outcomes.
Register your interestSubjects covered
Lecture Topic Detail
1. Introduction Introduction to the module. Principles of forensics, need of digital forensics, background to digital forensics,
Computer crime. Categories of incidents. Cybercrime investigation. Scenarios of eDiscovery and digital forensics investigations.
2. Digital forensics models and methodologies. Digital evidence. Direct and circumstantial evidence. Types of data (content and non-content). The digital forensics process. Exemplar models and methodologies. Standards and best practices.
3. Digital Evidence Sources of digital evidence and the investigation process. Evidence handling rules. ACPO principles of computer related evidence. Legal and ethical obligations. Handling digital evidence (Identification, Collection, Acquisition, Preservation) Triage and anti-forensics. Chain of custody. Need to maintain extensive documentation. Digital evidence admissibility (Assessment, Consideration, and Determination) Digital forensics report writing, typical parts, letter of findings, affidavits.
4. Forensic Tools Types of computer forensic tools, various tasks performed by forensic tools and its details. Drive imaging. Password cracking tools. Forensic workstation, choosing the forensic toolkit. Validating and testing forensic software, using NIST tools. Cloud platform challenges and considerations.
5. Windows Forensics Importance of operating system forensics. Relevant windows data structures. History of the windows registry, registry editor key, registry information. Tracking user activity by analysing shellbags and quick access/Recent Files Review bitlocker encryption and location of recovery keys.
6. Network Forensics Basics of network forensics When to apply network forensics. Key elements in communication. Network trace. Key concepts to interpret a network trace. IP and MAC addresses and networking infrastructure. Show how session keys (perfect forward secrecy) encryption/decryption works with RSA .Public Key encryption. Explain the role of deep packet inspection and web application firewalls in a network.
7. Mobile Device Forensics Mobile devices, mobile phones in crime, collecting a phone for analysis, data recovered from a mobile phone. Components of mobile phone. Accessing the data from a mobile phone. Tools used for mobile forensic analysis.
8. Linux Forensics Linux shell, linux boot sequence. Filesystems and disk/directory Encryption techniques. Important directories and sub-directories. File deletion in linux. Find Recently accesses/modified/changed files Log analysis /var/log/*
9. Introduction to Electronic Discovery & Enterprise Search What is discovery, how is conventional discovery different to eDiscovery. What is electronic discovery. Common challenges of electronic discovery. Examine Microsoft Purview or Gcloud Vault , eDiscovery platforms. Discuss Full-text search, Faceting, Nearest-Neighbour/Clustering.
Highlighting of hits. Rich document handling. Document fields and schema design.
10. Electronic Discovery Reference Model Discussing various phases of Electronic discovery reference model in detail. Information governance. Deduplication, keyword searching, technology assisted review (TAR), email threading, textual near duplicate identification.
11. Electronic Discovery Processes Approaches to eDiscovery. Forms of electronically stored information. What constitutes evidence and what is metadata. Selecting an eDiscovery tool. Significance of quality assurance in eDiscovery practices. Email archiving/journaling.
12. Revision, catchup and formative feedback
Register your interestLearning objectives
The Digital Forensics, Chain of Custody and eDiscovery module is intended to enable learners to develop knowledge, skills, and competences in digital forensics, as well as eDiscovery. From a practical perspective, learners develop expertise on a range of tools associated with mobile, network and the digital forensics of various operating systems. Furthermore, learners investigate and assess digital forensic case studies.
On successful completion of this module the learner will be able to:
LO1: Demonstrate in-depth critical awareness and interpretation of laws, compliance requirements, methods and procedures used in digital forensics investigations.
LO2: Carry out a forensic investigation of operating systems, mobile devices and networks, critically analyse the evidence and document the findings in a report.
LO3: Compare, evaluate and use forensic tools to forensically analyse digital devices.
LO4: Carry out an eDiscovery engagement across multiple platforms making use of various electronic discovery tools.
LO5: Critically analyse the results of an eDiscovery review, prepare production sets, write reports, and appraise the concepts for information retrieval and enterprise search technologies.
Register your interestMaking Europe cyber-aware
Our digital world is under constant attack. Master the advanced skills to defend critical data and infrastructure. Become a sought-after expert in one of today’s most vital and in-demand career fields.
Download prospectusFAQs
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.