Core Module Information
Module title: Host-Based Forensics

SCQF level: 11:
SCQF credit value: 20.00
ECTS credit value: 10

Module code: CSN11125
Module leader: Robert Ludwiniak
School School of Computing, Engineering and the Built Environment
Subject area group: Cyber Security and Systems Engineering
Prerequisites

There are no pre-requisites for this module to be added

Description of module content:

The aim of this module is to develop a deep understanding of operating system disk-level architectures, such as Windows and Linux, and demonstrate how the operating system artefacts can be used during an investigation. This will allow students to study how operating systems store system and user data, and thus students will gain an understanding as to what information could technically be held on such systems. This data could include user files, as well as user activities such as login session data, browsing histories, operating system manipulation, and general user interactions with a variety of operating system tools. This understanding will be expanded through theoretical knowledge and practical exercises in extracting information from systems, using a variety of open source and commercial forensic analysis tools, and documenting the results of such a process using consistent and thorough evidential procedures. This includes the production of event timelines, as well as the analysis of system logs, operating system state, file systems, and application data. The module will also consider the ethical and professional issues related to digital forensics. An outline of the main areas includes:- Introduction to the digital forensics processes and principals and forensics tools for data preservation and validation.- Storage devices - analysis of different media types used for data storage and volume level analysis.- File System analysis - understanding of architecture of FAT and NTFS file systems and tools required for data recovery- Operating System artefacts - analysis of specific OS artefacts and their role as digital evidence. This will include both system and user specific artefacts, such as files, browser history, Windows registry, logs and other technologies.- Data analysis - file type metadata and data recovery - introduction of AI and Machine Learning tools for data fragments analysis and ML data recovery support.- AI for forensics and the latest current research such as Forensics as a Service (FaaS).

Learning Outcomes for module:

Upon completion of this module you will be able to

LO1: Develop the analytical and practical skills needed to access, process, and manipulate disk-based user and operating system data using standard operating system commands.

LO2: Identify and evaluate the key transient and persistent information which may be held in operating system disk images.

LO3: Develop analytical skills related to the academic principles and practical skills required to analyse a range of end host devices using current forensic tools and techniques.

LO4: Research, design, implement, evaluate and critically analyse end host devices as part of a complex forensic investigation.

Full Details of Teaching and Assessment
2026/7, Trimester 1, In Person, Edinburgh Napier University
VIEW FULL DETAILS
Occurrence: 001
Primary mode of delivery: In Person
Location of delivery: MERCHISTON
Partner: Edinburgh Napier University
Member of staff responsible for delivering module: Robert Ludwiniak
Module Organiser:


Student Activity (Notional Equivalent Study Hours (NESH))
Mode of activityLearning & Teaching ActivityNESH (Study Hours)NESH Description
Face To Face Lecture 20 Weekly lectures to discuss theoretical and practical aspects of digital forensics
Face To Face Practical classes and workshops 20 Weekly practical lab sessions, to apply and explore methods and tools discussion in lectures. These are student-led, authentic practical activities carried out in our custom cyber virtual environments.
Online Guided independent study 160 Independent study, which is student-centred, with support and guidance from academics in taught classes, support sessions, via online materials, and through assessments.
Total Study Hours200
Expected Total Study Hours for Module200


Assessment
Type of Assessment Weighting % LOs covered Week due Length in Hours/Words Description
Report 30 3~4 Week 15 , WORDS= 2500 Coursework report - forensic investigation based on fictional scenario
Class Test 30 1~2 Week 8 HOURS= 1.5 hours Mid Trimester Class Test Short Answer Exam based on theory and practical aspects of the first half of the module activities.
Practical Skills Assessment 40 3~4 Week 14 HOURS= 1.5 hours Practical assessment carried out in virtual cyber environment, assessing practical skills and methods from the entire module.
Component 1 subtotal: 100
Component 2 subtotal: 0
Module subtotal: 100

Indicative References and Reading List - URL:
Contact your module leader