CMU6XX-CF

Cyber Forensics

A technical and legal grounding in digital evidence, covering collection, preservation, and analysis of data from networks, file systems, and malware, within a rigorous ethical and procedural framework.

When
2025/26, Semester 1
Institution
Birmingham Newman University
Credits
20 credits
Birmingham Newman University

When something goes wrong in a digital system, a breach, a fraud, an incident, the question is always the same: what happened, and how do we know? Cyber forensics is the discipline that answers that question rigorously: collecting, preserving, and analysing digital evidence in ways that can withstand legal and technical scrutiny.

This module builds on an existing grounding in cyber security. It sits at the intersection of technical investigation, legal process, and ethical responsibility, three things that must be held together, not treated separately.

Why it matters

Digital evidence is everywhere: in log files, network traffic, deleted partitions, memory dumps, and device metadata. The challenge is not finding it, it is understanding what it means, handling it in ways that preserve its integrity, and reasoning about it honestly. Courts, regulators, and organisations all increasingly rely on digital forensic analysis, and the standards they require are demanding.

As systems grow more complex and attacks more sophisticated, including malware that hides its traces, encryption that protects communications, and cloud environments that span jurisdictions, the forensic analyst must combine technical depth with methodological rigour.

Module design

The module moves students from foundations (what digital evidence is and how to handle it legally and technically) through tools and techniques (data recovery, network forensics, malware analysis), and into the frameworks that govern how findings are reported and used. The legal and ethical thread runs throughout, not as a separate topic but as a constraint that shapes every practical decision.

The design reflects a conviction that forensics cannot be taught purely technically. A forensic analyst who finds the evidence but handles it incorrectly, or who overstates certainty in their conclusions, can cause serious harm. Students are trained to be precise about what the evidence shows and what it does not.

Topics

  • Principles of digital evidence: integrity, chain of custody, admissibility
  • Cryptography in forensic context: encryption, hash functions, digital signatures
  • Authentication, access control, and audit trails
  • Data recovery and file system analysis
  • Network forensics: traffic capture, log analysis, intrusion detection
  • Malware analysis: static and dynamic techniques
  • Security mechanisms and their forensic implications
  • Legal and ethical frameworks in cyber forensics
  • Privacy, anonymity, and the limits of investigation
  • Tools and methodologies used in professional practice

What students leave with

Students understand how digital investigations are structured and conducted, can apply core forensic techniques to realistic scenarios, engage critically with the legal and ethical constraints that govern digital evidence, and communicate findings with appropriate precision. These skills transfer to roles in security operations, incident response, compliance, and law enforcement, and they develop a mode of technical reasoning, careful, evidence-based, methodologically aware, that is valuable across any analytical domain.