Course Notes

Notes are mainly based on pages of the text plus some added examples and comments. The notes are in PDF file format. You may download a free copy of Adobe Reader to read PDF files.

1. Overview of Computer Forensics (19 pages) posted on WebCT, 8/22/2006

2. Hard Disk Acquisition (12 pages) and two sample warrants (6 and 7 pages, respectively), posted on WebCT, 8/29/2006

3. Computer Foundations (10 pages) posted on WebCT, 9/05/2006

4. Volume and Partition Analysis (7 pages) plus partition table examples (3 pages) and Demos of partition tools (15 pages), a pre-exam and hard disk acquisition form of SCSO added to topic #2, posted on WebCT, 9/12/2006

5. File Systems (14 pages) posted on WebCT, 9/19/2006

6. FAT File Systems (incomplete, 14 pages) posted on WebCT, 9/26/2006

6-1. FAT File Systems (Part 2, 17 pages) posted on WebCT, 10/10/2006

7. NTFS File System (incomplete, 15 pages) posted on WebCT, 10/18/2006

8. String Searches (12 pages) posted on WebCT, 10/24/2006

9. FTK (10 pages) posted on WebCT, 10/31/2006

10. FTK Demo (guest lecture by Luke Erickson), on FTK, Windows XP registry, imaging, efs, word encrpytion, email, searching, aol Im, graphics, and report writing, 11/07/2006.

11. Sample Forensic Report (guest lecture by Sergeant Stenger of Orange County Sheriff's Office) posted on WebCT, 11/14/2006

11-1. Guidelines (Templates) for Computer Forensic Examination Report (Courtesy of Sergeant Purcell of Seminole County Sheriff's Office) (a zip file) posted on WebCT, 11/21/2006

12. Windows Forensics (Thumbs.db, Link and Spool files, Recycle Bin) (10 pages) posted on WebCT, 11/30/2006