Students understand the basic concepts of computer forensics, its technical limitations as well as the related legal issues. They know typical problems and posseses knowledge regarding securing evidence as well as extracting, observing resp. reconstructing data from various sources.
Technical part: Securing evidence (imaging hard disks as well as collecting data from live systems), analysis of file systems (finding resp. reconstructing deleted data), recovering web browsing- and E-Mail activities, tracing back E-Mails.
Legal part: Mandatory data retention as well as interception/searches/seizure, regulating internet usage at work as well as protection of access control systems (hard- and software), privacy, criminal law in the IT area, e.g. data destruction and computer fraud.