Government Engineering College
Patan
Computer Science and Engineering
(CSE)
Digital Forensics (3170725)
BE Semester-VII
Date:-
To Study about Computer & D List possible System and Third party software tool s
available forensic investigation.
Browser history & Digital Forensics Investigation.
A. Find and State the importance of browser history in digital forensic investigation. Find
out case studies where browser history is used during digital forensics investigation
and prepare a brief summary of this case study.
B. Install Browser History Capturer and Browser History Viewer on your system and
write installation steps. Explore functionalities of tool with example and discuss them
with screenshots in your practical report.
Install LastActivityView, ProduKey, UninstallView, OpenedFilesView, SearchMyFiles,
WinLogOnView, and SysExporter on your system. Write brief summary of each tool.
Explore functionalities of these tools and discuss their usage with example with screenshots
in your practical report.
Install NMap, Wireshark on your system write installation steps of each network tool. Discuss
the functionalities of these tools with screenshots in your practical report. Explain use of these
tools in digital forensics.
Install MAGNET RAM Capture, MAGNET Encrypted Disk Detector, and MAGNET Web
Page Saver on your system and discuss steps of installation in your practical report. Discuss
the functionalities of these tools with screenshots in your report. Explain the use of these tools
in digital forensics.
Install Autopsy on your system and Write installation steps with screenshots in your practical
report. Discuss the functionalities of this tool.
Computer Operating system Artifacts:
Finding deleted data, hibernating files, examining window registry, recycle bin operation,
understanding of metadata, Restore points and shadow copies.
Demonstrate COFEE Tool.
Comparison of two Files for forensics investigation by Compare IT software.
Install ExifTool, HashMyFiles, and HxD tools in computer system .discuss their functionality
with screenshots.
LIST OF EXPERIMENTS
Index
PR Faculty
CO TITLE Page No Start Date End Date
NO sign
1 CO1 Experiment -1
2 CO4 Experiment -2
3 CO4 Experiment -3
4 CO4 Experiment -4
5 CO4 Experiment -5
6 CO4 Experiment -6
7 CO4 Experiment -7
8 CO4 Experiment -8
9 CO4 Experiment -9
10 CO4 Experiment -10
Course Outcomes:
CO-1 Describe Forensic science, Digital Forensic, motives and modus operandi behind
cyber attacks.
CO-2 Recall various technical concepts of digital computer system.
CO-3 Interpret the cyber pieces of evidence, Digital forensic process model and
their legal perspective
CO-4 Demonstrate various forensic tools to investigate the cybercrime and to identify
the digital pieces of evidence
CO-5 Analyze the digital evidence used to commit cyber offences.
RUBRICS FOR LABORATORY PRACTICALS ASSESSMENT
Subject Name : Digital Forensics
Subject Code : 3170725
Semester : 7
Term : Odd Term 2024
Term Start Date : ______________ End Date: ______________
Rubrics Criteria Marks Points Distribution
ID
RB1 Submission 10 (1 marks On Time Thereafter in given deadline (50 % )
Regularity for each (100 %) Or 0
exp.)
RB2 Assessment based on 10 (two
presentation of work progressive As per Table 1.
evaluation -
5 marks
each)
Table 1.
RB2 1. Two presentations will be conducted in whole semester. Each Presentation
will carry 5 marks.
2. First presentation will be conducted at the mid of semester which cover
experiments no 1 to 5.second at the end of semester which cover
experiments no 6 to 10.
3. Two students in a group will work on all experiment throughout the
semester and present the same during the evaluation.
4. Points mentioned in student presentation evaluations sheet will be
considered during the presentation to carry out progressive assessment of
5 marks in each phase.
Student Presentation Evaluations
Presentation- I: / /2024
Presentation- II: / /2024
Weights 100 % 75 % 50% 25 % AB
=0 Total
1 Organizatio Information Information Most of information sequence of
n of presented as presented in presented in sequence information jumpy
presentation interesting story in logical sequence;
(1) logical, easy to easy to follow
follow sequence
P-1
P-2
2 Backgroun Material Material Material Material not
d Content sufficient for sufficient for sufficient for clearly related to
clear clear clear topic Uses
and understanding understanding understanding graphics that
supportive AND and effectively Uses graphics that rarely
stuff (1) exceptionally presented. Uses relate to text and support text and
presented. Uses graphics that presentation presentation
graphics that explain text and
explain presentation
and reinforce text
and presentation
P-1
P-2
3 Knowledge Outstanding Admirable Average Inadequate
(1)
P-1
P-2
4 Presentatio Refers to slides to Refers to slides to Refers to slides to Reads most
n Skills make points; fully make points; eye make points; slides; no or just
(Eye contact engaged with. contact majority of occasional eye occasional eye
and Correct, precise , time. Voice is contact, Voice contact,
Voice is clear clear with few fluctuates from low to Mumbling
speaking
fluctuations clear.
ability)(2)
P-1
P-2
Student Signature: ____________________
LABORATORY EXPERIMENTS(Practical) ASSESSMENT
SUBJECT NAME: Digital Forensics
SUBJECT CODE: 3170725
TERM: Odd Term 2024
Enrolment No. ____________ Name:_________________________________
Semester : ______________
Class: ____________ Batch:______________
Sr.No Exp .No CO RB1 RB2 Total
1 1 1
2 2 4
3 3 4
4 4 4
5 5 4
6 6 4
7 7 4
8 8 4
9 9 4
10 10 4
TOTAL
Student Signature: ____________________
Experiment 1:
AIM : To Study about Computer & Digital Forensics. List available system and third party
software tools for forensic investigation.
Competency and Practical Skills: Basic understanding of digital forensic and digital forensic
tools.
Relevant CO: CO1
Objectives: To gain knowledge about computer and digital forensic and its tools.
Equipment/Instruments: Computer, digital forensic softwares.
1. What is Digital Forensics?
2. What is computer Forensics?
3. Differentiate digital forensics and computer forensic.
4. What Can Digital Forensics Do?
5. What Is Anti-Forensics?
6. List digital forensic, system and third party tools with reference.
Experiment 2:
AIM: Browser history & Digital Forensics Investigation.
Competency and Practical Skills: To demonstrate the installation of available software tool
and use it.
Relevant CO: CO4
Objectives: To learns how different tool available are used to find browser history logs, capture
the browser history from different browser used in the computer system and interpret the
collected information for finding fact.
Equipment/Instruments: computer system, software tool (browser history capture tool).
1. What is browser history? How computer systems maintain browser history?
2. Find and State the importance of browser history in digital forensic investigation. Find
out case studies where browser history is used during digital forensics investigation and
prepare a brief summary of this case study.
3. Install Browser History Capturer and Browser History Viewer on your system and write
installation steps. Explore functionalities of tool with example and discuss them with
screenshots in your practical report.
Experiment 3:
AIM: Install Last Activity View, ProduKey, UninstallView, OpenedFilesView, SearchMyFiles,
WinLogOnView, and SysExporter on your system. Write brief summary of each tool. Explore
functionalities of these tools and discuss their usage with example with screenshots in your
practical report.
Competency and Practical Skills: To demonstrate the installation of available system &
software tool and use it.
Relevant CO: CO4
Objectives: To study different utilities and system tool available for targeted operating system
and use the same for finding usuful insights from the system.
Equipment/Instruments: computer system, software tool.
Experiment 4:
AIM: Install NMap, Wire shark on your system. Write installation steps of each network tool.
Discuss the functionalities of these tools with screenshots in your practical report. Explain use of
these tools in digital forensics.
Competency and Practical Skills: To demonstrate the installation and use of available software
tools.
Relevant CO: CO4
Objectives: To learn how different network tools are used in forensic for gaining insights from
the networks.
Equipment/Instruments: computer system, software tool (Network software tools).
Experiment 5:
AIM: Install MAGNET RAM Capture, MAGNET Encrypted Disk Detector, and MAGNET
Web Page Saver on your system and discuss steps of installation in your practical report. Discuss
the functionalities of these tools with screenshots in your report. Explain the use of these tools in
digital forensics.
Competency and Practical Skills: To demonstrate the installation and use of available software
tools.
Relevant CO: CO4
Objectives: To learn how different software tools are used in forensic to capture the live
moments in the computer memories.
Equipment/Instruments: computer system, software tool.
Experiment 6:
AIM:
Install Autopsy in your computer system and write installation steps with screenshots in your
practical report. Discuss the functionalities of this tool.
Competency and Practical Skills: To demonstrate the installation and use of available software
tools.
Relevant CO: CO4
Objectives: To learn how software tools are used in forensic to recover artifacts from the device,
network, file system, and registry etc.
Equipment/Instruments: computer system, software tool.
Experiment 7:
AIM: Computer Operating system Artifacts
Finding deleted data, hibernating files, examining window registry, recycle bin operation,
understanding of metadata, Restore points and shadow copies.
Competency and Practical Skills: To demonstrate the finding and locating various sources of
artifact in computer system.
Relevant CO: CO4
Objectives: To learn how to locate various computer system artifacts for finding useful hidden
data from computer system
Equipment/Instruments: computer system, Operating system.
Experiment 8:
AIM: Demonstrate COFEE Tool
Competency and Practical Skills: To demonstrate the installation and use of available software
tools.
Relevant CO: CO4
Objectives: To learn how Microsoft based product COFEE tool helps computer forensic
investigators extract evidence from a Windows computer.
Equipment/Instruments: computer system, software tool.
Experiment 9:
AIM: Comparison of two files for forensics investigation by Compare IT software.
Competency and Practical Skills: To demonstrate the installation and use of available software
tools.
Relevant CO: CO4
Objectives: learn how Compare IT tool is used to compares and identifies the differences
between two files.
Equipment/Instruments: computer system, software tool (Compare IT), Data files.
Experiment 10:
AIM: Install ExifTool, HashMyFiles, and HxD tools in computer system .Discuss their
functionality with screenshots.
Competency and Practical Skills: To demonstrate the installation and use of available software
tools.
Relevant CO: CO4
Objectives: learn utility software to perform different operation on files.
Equipment/Instruments: computer system, software tool.