Sidan finns bara på engelska

Note: this is an information page, the course is given through LiU's e-learning system lisam

Digital Forensics and Incident Response

This course introduces the foundations and practice of digital forensics and incident response. The course combines lectures with hands-on laboratory work where students investigate digital evidence, reconstruct attacker activity, and document their findings in a professional manner.

Digital Forensics Process

Course overview

Digital forensics and incident response are concerned with identifying, preserving, analysing and interpreting digital evidence after security incidents. In this course, students learn how forensic investigations are performed across different systems and data sources, and how technical findings can be communicated clearly and responsibly.

The course is particularly relevant for students interested in cybersecurity, secure systems, computer networks, system administration, and investigative work after intrusions or malware incidents.

Lectures

The lecture part gives the conceptual and methodological background needed for the laboratory work and the written examination. Topics include:

  • Introduction to digital forensics and incident response;
  • Preparation, evidence handling and investigation workflow;
  • File system forensics;
  • Network forensics;
  • Logs, timestamps and timeline analysis;
  • Local system forensics.

Additional topics may be included depending on the course instance, such as memory forensics, malware-related artefacts, mobile or hardware forensics, legal aspects, critical infrastructure, or advanced incident-response scenarios.

Lab

The laboratory part is the practical core of the course. Students work with forensic tools and realistic evidence sources, and are expected to document both their process and their conclusions.

The labs include:

Getting started with the forensic environment

Students become familiar with the forensic workstation environment and basic operational procedures, including virtual-machine use, working with evidence files, mounting file systems read-only, and handling common tool issues.

Autopsy and forensic case work

Students use Autopsy as a graphical forensic analysis environment. The focus is on creating cases, adding evidence sources, browsing file systems, running selected analysis modules and comparing artefacts across evidence sources.

The Trixtele breach investigation

Students investigate a simulated breach scenario. The work includes acquisition and analysis of evidence, investigation of privilege escalation and lateral movement, assessment of information access and possible exfiltration, and recommendations for containment, eradication and recovery.

Network forensics challenge

Students analyse packet captures from an attacked network. Topics include web defacement, web shells, malware delivery, suspicious downloads, HTTP analysis and use of tools such as Wireshark and NetworkMiner.

Memory forensics

Students perform basic memory analysis using Volatility. The work includes identifying operating-system information, processes, network activity, registry artefacts, cached credentials and signs of malicious activity.

  • Official course information in Studieinfo.
  • Lisam course room: available to registered students.