Operating System Analysis
This course will examine in considerable depth how file and operating systems determine the type of information available to examiners. In particular the design and behavior of these systems will be discussed and students will be taught to recover information from these systems at the binary level. The features and limitations of current forensic software tools will a lso be covered, with particular attention paid to the techniques by which the automated tools interpret data. A range of operating systems will be examined, including PC, mobile phone and embedded systems.
Prerequisite: Complete DFS-501