This course covered the fundamentals of digital forensics from a technical, evidence-handling perspective, focused on the full investigative process rather than any single tool. The work here looked at how digital evidence is identified, collected, and preserved across computers, mobile devices, networks, and cloud environments, along with how findings get analyzed and reported for use in court. Assignments emphasized the chain of custody and forensically sound acquisition methods, alongside written reporting skills used to communicate findings clearly to both technical and non-technical audiences. Feel free to look through some of the coursework below.
Coursework Artifacts
Reflection
This course put me on both sides of digital forensics: planning the infrastructure and doing the actual investigation. My midterm paper had me design a full forensics lab for a police department, including how it would get officially certified, what equipment and staff it would need, and how everything would be maintained over time. That assignment showed me forensics is as much about process and accountability as it is about the tools themselves. A lab is only as credible as its documentation and standards.
My final paper put that into practice with a mock case investigation. I created an exact digital copy of a laptop’s hard drive using a tool that guarantees nothing on the original gets changed, and pulled texts, call logs, and app data off a phone using specialized extraction software. I also recovered files that had been deleted, using a technique that rebuilds them piece by piece from leftover data on the drive. My biggest learning moment came from realizing how much evidence survives even after someone tries to delete it, and how searching a device for specific keywords can turn scattered messages, emails, and files into a clear, provable timeline.
This experience taught me that digital forensics is not just about finding evidence, but about handling it in a way that holds up. Every step, from copying the data to writing the final report, has to preserve the integrity of the original evidence and be documented well enough to stand up in court. This discipline is something I’ll carry into any future cybersecurity role.