B.E. (Computer Engineering) Digital Forensics Syllabus - Mumbai University 2026
The University has moved this degree onto NEP 2020 one year at a time. The first and second years are NEP 2020 syllabi; the third and fourth years are still examined on the REV-2019 'C' Scheme, which is what the University sets for them this year.
Loading syllabus...
Syllabus for Digital Forensics
Module 1: Introduction to Digital Forensics
- 1.1 Digital ForensicsDefination, Digital Forensics Goals, Digital Forensics Categories - Computer Forensics, Mobile Forensics, Network Forensics, Database Forensics
- 1.2 Introduction to Incident - Computer Security Incident, Goals of Incident Response, CSIRT, Incident Response Methodology, Phase after detection of an incident
Module 2: Digital Evidence, Forensics Duplication and Digital Evidence Acquisition
- 2.1 Digital evidence, Types of Digital Evidence, Challenges in acquiring Digital evidence, Admissibility of evidence, Challenges in evidence handling, Chain of Custody
- 2.2 Digital Forensics Examination Process - Seizure, Acquisition, Analysis, Reporting. Necessity of forensic duplication, Forensic image formats, Forensic duplication techniques,.
- 2.3 Acquiring Digital Evidence - Forensic Image File Format, Acquiring Volatile Memory (Live Acquisition), Acquiring Nonvolatile Memory (Static Acquisition), Hard Drive Imaging Risks and Challenges, Network Acquisition
Module 3: Forensics Investigation
- 3.1 Analyzing Hard Drive Forensic Images, Analyzing RAM Forensic Image, Investigating Routers
- 3.2 Malware Analysis - Malware, Viruses, Worms, Essential skills and tools for Malware Analysis, List of Malware Analysis Tools and Techniques
Module 4: Windows and Unix Forensics Investigation
- 4.1 Investigating Windows Systems - File Recovery, Windows Recycle Bin Forensics, Data Carving, Windows Registry Analysis, USB Device Forensics, File Format Identification, Windows Features Forensics Analysis, Windows 10 Forensics, Cortana Forensics
- 4.2 Investigating Unix Systems - Reviewing Pertinent Logs, Performing Keyword Searches, Reviewing Relevant Files, Identifying Unauthorized User Accounts or Groups, Identifying Rogue Processes, Checking for Unauthorized Access Points, Analyzing Trust Relationships
Module 5: Mobile Forensics
- 5.1 Android Forensics, Mobile Device Forensic Investigation - Storage location, Acquisition methods, Data Analysis
- 5.2 GPS forensics - GPS Evidentiary data, GPS Exchange Format (GPX), GPX Files, Extraction of Waypoints and TrackPoints, Display the Tracks on a Map.
- 5.3 SIM Cards Forensics - The Subscriber Identification Module (SIM), SIM Architecture, Security, Evidence Extraction.
Module 6: Browser, Email Forensic & Forensic Investigation Reporting
- 6.1 Web Browser Forensics, Google chrome, Other web browser investigation Email forensics - Sender Policy Framework (SPF), Domain Key Identified Mail (DKIM), Domain based Message Authentication Reporting and Confirmation (DMARC)
- 6.2 Investigative Report Template, Layout of an Investigative Report, Guidelines for Writing a Report
Textbooks
- 1 Kevin Mandia, Chris Prosise, “Incident Response and computer forensics”, Tata McGrawHill, 2006
- 2 Digital Forensics Basics A Practical Guide Using Windows OS — Nihad A. Hassan, APress Publication, 2019
- 3 Xiaodong Lin, “Introductory Computer Forensics: A Hands-on Practical Approach”, Springer Nature, 2018 Suggested MOOC Course Links
- 1 Course on “Ethical Hacking” https://nptel.ac.in/courses/106/105/106105217/
- 2 Course on “Digital Forensics” https://onlinecourses.swayam2.ac.in/cec20_lb06/preview
- 3 Course on Cyber Incident Response https://www.coursera.org/learn/incident-response
- 4 Course on “Penetration Testing, Incident Responses and Forensics” https://www.coursera.org/learn/ibm-penetration-testing-incident-response-forensics
Reproduced from the University of Mumbai syllabus for B.E. (Computer Engineering) under REV-2019 'C' Scheme, in force from the academic year 2022-23. Wording is as printed in that syllabus. Module numbering is as printed there too.
The complete syllabus
This subject is cut from the University circular for its year. Open a document here if you want the whole thing rather than a single subject.