COMP 6215 Forensic Computing
Discussion of the principles of digital forensics in the Microsoft Windows operating system. Emphasis on evidence extraction and storage, volatility order, the Locards exchange principle, and preservation of volatile data and non-volatile data. Analysis of data, including Windows memory, Windows registry, registry file and executable files (.exe). Discussion of cases and use of proprietary tools such as ProDiscover and open-source tools such as Autopsy.