Apr 25, 2024  
2018-2019 Course Catalog 
    
2018-2019 Course Catalog [ARCHIVED CATALOG]

Add to Portfolio (opens a new window)

CRJ 167 - Operating Sys. for Forensics

Credits: 3
Lecture Hours: 2
Lab Hours: 2
Practicum Hours: 0
Work Experience: 0
Course Type: Open
This course provides a comparative study of popular PC-class operating systems. Upon completion of this course, students will be familiar with the interface, file management, resource allocation and common administration procedures of various popular operating systems. Additionally, the course describes data organization and file properties that contribute to forensic investigation. Many discussion topics are reinforced with hands-on exercises and assignments.
Prerequisite:  Instructor approval
Competencies
  1. Examine the basic operation of a computer
    1. Describe the boot process
    2. Describe memory usage
    3. Discuss hardware basics
  2. Interpret computer codes and numbering systems
    1. Describe BCD and ASCII codes
    2. Explain Binary numbering systems
    3. Explain octal numbering systems
    4. Explain Hexadecimal numbering systems
  3. Describe purpose of a computer operating system (OS) and its components
    1. Define kernel
    2. Differentiate between single-user and multi-user systems
    3. Explain file management
    4. Explain memory management including virtual memory/swap space
    5. Explain job management
    6. Explain device management
    7. Explain OS security
  4. Compare and contrast the main user features and typical user data of various, PC-class, operating systems including but not limited to
    1. DOS
    2. Windows 9x
    3. Windows NTx (NT, 2K, XP, Vista, Server 20xx, Win7)
    4. UNIX/POSIX (Linux/OS X).
    5. Windows 2003 Server
    6. Windows XP
    7. Windows Vista
    8. UNIZ/POSIX (Linux/OS X)
  5. Compare and contrast the main administrative capabilities, system files, job/process management of various, PC-class, operating systems including, but not limited to
    1. DOS
    2. Windows 9x
    3. Windows NTx (NT, 2K, XP, Vista, Server 20xx, Win7)
    4. UNIX/POSIX (Linux/OS X).
    5. Windows 2003 Server
    6. Windows XP
    7. Windows Vista
    8. UNIZ/POSIX (Linux/OS X)
  6. Demonstrate effective use of a Hex Editor application.
    1. Explain the term offset.
    2. Practice inserting, altering, deleting, and carving data using the software tool.
    3. Describe HPFS
    4. Describe NFS
    5. Describe Extended File System (ext2/ext3/ext4)
    6. Describe HFS Plus
    7. Describe ReiserFS
    8. Describe UDF and ISO9660
  7. Recognize significance and key components of boot records.
    1. Contrast Master Boot Record (MBR) and BUID Partition Table (GPT) organizational schemes.
    2. Decode appropriate data structures to identify volume parameters on a storage device.
    3. Identify file attributes and permissions
    4. Recognize common file extensions including, but not limited to: .txt, .pdf, .doc, .xls, .jpg, .gif, .bmp, .tmp, .htm, .xml, .log
    5. Explain the correlation of ?magic numbers? and specific application data
    6. Describe metadata
    7. Describe beneficial OS-specific artifacts and logs
  8. Understand and identify different files sytems, inclduing respective data saving, recall and deletion methods.
    1. Describe FAT/GAT16/FAT32.
    2. Describe NTFS
    3. Describe exFAT.
    4. Describe Extended File System (ext2/ext3/ext4).
    5. Describe HFS Plus.
    6. Describe Reiser FS.
    7. Describe UDF and ISO9660.
  9. Identify and analyze primary user data and OS artifacts.
    1. Describe file naming conventions.
    2. Describe dating mehtods (creation/modification/access).
    3. Identify file attributes and permissions.
    4. Recognize common file extensions including, but not limited to: .txt, .pdf, .doc, .docs, .xls, .jpg, .gif, .bmp, .tmp, .htm, .xml, .log, .zip.
    5. Explain the correlation of “magic numbers”/file signatures and specific application data.
    6. Describe metadata.
    7. Describe beneficial OS-specific artifacts and logs.



Add to Portfolio (opens a new window)