Back close

Course Detail

Course Name Cyber Forensics and Incident Response
Course Code 26SN605
Program M. Tech. in Cyber Security Systems & Networks
Semester 1
Credits 4
Campus Amritapuri

Syllabus

Syllabus

Introduction to cyber forensic investigation and investigation tools including Autopsy and FTK. Digital evidence collection — chain of custody, hash verification, and artifact prioritization. Evidence preservation using write blockers, forensic imaging, and integrity verification. Data recovery through file carving and pattern recognition for fragmented data. Search and seizure of computers and devices — legal frameworks and best practices. Recovering deleted evidence using undelete tools and data reconstruction techniques. Password cracking — dictionary attacks, brute-force, and rainbow tables.

Hardware and storage device forensics — NAND flash internals and SSD basics. File system forensics covering FAT, NTFS, ext4, and APFS with timeline reconstruction. File System Tunneling — NTFS tunneling behavior and forensic implications. OS forensics for Windows, Linux, and Mac — registry analysis and system artifact investigation. Memory forensics using Volatility — process injection detection and malware classification from memory dumps. Mobile forensics for Android logical acquisition on android emulator, chat and location data correlation. Investigating copiers, IVR, Video surveillance, RFID and Sim cards.

OS forensics across Windows, Linux, Android, and iOS — artifact investigation and timeline analysis. Browser forensics — history, cache, cookies, and session reconstruction. E-Mail forensics — header analysis, phishing detection, and email thread reconstruction. Social media forensics — metadata extraction, fake account and bot detection. LLM and Generative AI forensics — tracing AI-generated content, prompt injection artifacts, and model misuse investigation. Explainable AI (XAI) in forensics — interpreting AI-based forensic decisions for legal admissibility. SOC operations and incident response — SIEM workflows, alert triage, and escalation procedures. Anti-forensics — timestomping, log clearing, and detection of anti-forensic artifacts. Code obfuscation detection techniques.

Network and communication forensics — packet analysis. Steganography and image file forensics — LSB analysis and stego-detection. . Espionage and investigations — APT attribution and threat intelligence platforms. Cloud forensics — AWS collection and cloud log analysis. OSINT using tools such as Maltego and SpiderFoot. Online anonymity and rootkits — dark web forensics and de-anonymization techniques. Threat level assessment — threat scoring and MITRE ATT&CK integration. Evidence remnant detection after overwriting, forging, wiping, and destruction. SOC threat hunting — hypothesis-driven investigation, log correlation, and IOC analysis.

Security standards — ISO 27001, NIST SP 800-61, and ISO/IEC 27037 (digital evidence handling standard). Cyber laws and legal frameworks — IT Act 2000 and its amendments, GDPR, and CCPA. Cyber laws in India — BNSS 2023 (Bharatiya Nagarik Suraksha Sanhita), DPDP Act 2023 (Digital Personal Data Protection), and Section 65B of the Indian Evidence Act. CERT-In guidelines — reporting obligations, incident classification, and compliance requirements. Admissibility of digital evidence — chain of custody, legal standards, and court procedures. Case studies — ransomware investigations, APT incidents, and insider threat analysis.

Text Books / References
  1. File System Forensic Analysis – Brian Carrier | ISBN: 978-0-32-126817-2
  2.  Incident Response and Computer Forensics, 3e – Luttgens, Pepe | ISBN: 978-0-07-179869-3
  3.  Android Forensics – Andrew Hoog | ISBN: 978-1-59749-651-3
  4.  iPhone and iOS Forensics – Hoog & Strzempka | ISBN: 978-1-59749-659-9
  5.  Practical Mobile Forensics, 4e – Tamma, Skulkin, Mahalik, Bommisetty | ISBN: 978-1-83864-752-0
  6. Practical Forensic Analysis of Artifacts on iOS and Android – Mohammed Moreb | ISBN: 978-1-48428-026-3

Introduction

This course provides a comprehensive foundation in cyber forensic investigation, digital evidence handling, and incident response. It equips students with the knowledge and skills to investigate cyber incidents across a spectrum of digital environments including host systems, mobile devices, memory, networks, and cloud platforms while adhering to legal frameworks, chain-of-custody requirements, and forensic integrity standards. The course also addresses emerging topics such as AI forensics, SOC threat hunting, and cyber law compliance.

Objectives and Outcomes

Course Objectives

  • To understand digital evidence collection, preservation, and forensic investigation methodologies.
  • To develop proficiency in hardware, memory, mobile, and file system forensics using industry tools.
  • To investigate host/OS, browser, email, social media, network, and cloud artifacts.
  • To explore emerging areas including AI/LLM forensics, SOC operations, and anti-forensic detection.
  • To apply knowledge of cyber laws, compliance standards, and legal frameworks governing digital evidence.

Course Outcomes

COs Description
CO1 Explore cyber forensic investigation, investigation tools, digital evidence collection, evidence preservation, data recovery, and encryption/decryption methods.
CO2 Familiarize with basics of hardware aquisition including disk, SSD, memory and mobile forensics.
CO3 Explore host/OS forensics (Windows, Linux), file system forensics, LLM & Generative AI forensics
CO4 Understand database forensics, e-mail forensics, browser forensics, social media forensics, anti-forensics, and SOC operations in incident response
CO5 Explore network, cloud forensics, including steganography, OSINT, XAI in forensics, and threat assessment.
CO6 Familiarize with cyber laws, regulations, and compliance standards including IT Act 2000 (amendments), BNSS 2023, DPDP Act 2023, CERT-In guidelines, and ISO/IEC 27037.

Prerequisites

  • Network Security
  • Operating Systems

Evaluation Pattern

CO-PO / PSO Mapping

COs PO1 PO2 PO3 PSO1 PSO2 PSO3 PSO4
CO1 3 3 2 3 3 3
CO2 3 3 3 3 3 2
CO3 3 3 3 3 2
CO4 3 3 3 3
CO5 3 3 3 3
CO6 3 3 3

Evaluation Pattern – 60:40

  • Midterm Exam – 30%
  • Viva – 10%
  • Lab Assignments & Case Study – 20%
  • End Semester Exam – 40%

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now