M.Sc. (Information Technology) Cyber Forensics Practical Syllabus - Mumbai University
This is the University of Mumbai syllabus for M.Sc. (Information Technology) under NEP 2020, in force from the academic year 2024-25. Semesters I and II are set by item 6.29 (N) and Semesters III and IV by item 6.2 (N). The University examines this programme under form 1113161, whose Summer 2026 timetable is headed NEP-2020; the distance and older Choice Based modes of the same degree are examined under different forms and different papers.
Loading syllabus...
Syllabus for Cyber Forensics Practical
- 1 Computer Forensics Investigation Process a. Recovering Data using the EaseUS Data Recovery Wizard. b. Performing Hash, Checksum, or HMAC Calculations using the HashCalc. c. Creating a Disk Image File of a Hard Disk Partition using the R- drive Image Tool.
- 2 Understanding Hard Disks and File Systems a. Analyzing File System Types Using the Sleuth Kit (TSK). b. Analyzing Raw image using Autopsy. c. Analyze file system of Linux image file. d. Analyze file system of Windows image file.
- 3 Data Acquisition and Duplication a. Creating a dd image file b. Investigating NTFS Drive Using DiskExplorer for NTFS. c. Viewing Content of Forensic Image Using Access Data FTK Imager Tool
- 4 Defeating Anti-forensics Techniques a. Cracking Application Password b. Detecting Steganography c. Perform a practical of identifying the packer used to pack a file by using ExeInfo PE and then unpacking the file using UPX.
- 5 Performing OS Forensics a. Performa a Practical collect volatile information from a host computer running on a Windows OS by using tools PsTools, LogonSessions, and NetworkOpenedFiles. b. Performa a Practical for Discovering and Extracting Hidden Forensic Material on Computers Using OSForensics. c. Performing a Computer Forensic Investigation Using the Helix Tool d. examine Windows event logs using Event Log Explorer.
- 6 Network Forensics a. Investigating Network Traffic Using Wireshark b. Investigating Network Attacks using Kiwi Log Viewer
- 7 Investigating Web Attacks a. Analyzing Domain and IP Address Queries Using SmartWhois Tool
- 8 Database Forensics a. Analyzing SQLite Databases using DB Browser for SQLite
- 9 Malware Forensics a. Perform Static Analysis of the Suspicious File b. performing dynamic analysis of a malicious file to find the processes It starts, network operations, file changes and other activities.
- 10 Investigating Email Crimes a. Recovering Deleted Emails Using the Recover My Email utility. b. Tracing an Email Using the eMailTrackerPro Tool.
- 11 Mobile Forensics a. Analyzing the Forensic Image and Carving the Deleted Files Using Autopsy. Course Outcomes(OCs) After completion of the course: OC1: Data Recovery: Students will be able to recover lost or deleted data using tools like EaseUS Data Recovery Wizard, ensuring data integrity and completeness during investigations. OC2: Hashing and Checksum Calculations: Students will perform hash, checksum, or HMAC calculations using HashCalc, enabling them to verify data integrity and authenticity. OC3: Disk Imaging: Students will create disk image files of hard disk partitions using tools like R-drive Image Tool, ensuring preservation of evidence for analysis. OC4: File System Analysis: Students will analyze different file system types using Sleuth Kit (TSK) and Autopsy, enabling them to understand file structures and recover relevant evidence. OC5: Data Acquisition and Duplication: Students will create dd image files, investigate NTFS drives using DiskExplorer for NTFS, and view content of forensic images using FTK Imager Tool, ensuring accurate and thorough data acquisition. OC6: Defeating Anti-Forensics Techniques: Students will learn to crack application passwords, detect steganography, and identify and unpack packed files using tools like ExeInfo PE and UPX, ensuring effectiveness in overcoming anti-forensics measures. OC7: OS Forensics: Students will collect volatile information from Windows hosts using PsTools, LogonSessions, and NetworkOpenedFiles, discover and extract hidden forensic material using OSForensics, and perform computer forensic investigations using Helix Tool, enabling them to conduct thorough examinations of operating systems. OC8: Network Forensics: Students will investigate network traffic using Wireshark and analyze network attacks using Kiwi Log Viewer, enabling them to identify and analyze network- related evidence effectively. OC9: Web Attacks Investigation: Students will analyze domain and IP address queries using SmartWhois Tool, enabling them to investigate web-related attacks and activities. OC10: Database Forensics: Students will analyze SQLite databases using DB Browser for SQLite, enabling them to extract and analyze data stored in databases for forensic purposes. OC11: Malware Forensics: Students will perform static and dynamic analysis of suspicious files, enabling them to identify and analyze malware behavior and impact. OC12: Email Crimes Investigation: Students will recover deleted emails using tools like Recover My Email utility and trace emails using eMailTrackerPro Tool, enabling them to investigate email-related crimes effectively. OC13: Mobile Forensics: Students will analyze forensic images and carve deleted files from mobile devices using Autopsy, enabling them to conduct investigations involving mobile devices comprehensively.
Reproduced from the University of Mumbai syllabus for M.Sc. (Information Technology) under NEP 2020, in force from the academic year 2024-25. Wording, unit numbering and lecture allocation are as printed in that syllabus. The PDF above is the syllabus's own page, unaltered.
The complete syllabus
This subject is cut from the University circular for the whole diploma. Open it here if you want the whole thing rather than a single subject.
Use Part 1 or Part 2 NEP first so the module scope matches your Mumbai University exam.
Use MSc IT notes only after confirming the semester units and topic order.
Open MSc IT question papers after the syllabus check so revision follows the same course structure.