BCIT is planning for a substantial return to on-campus activity for the fall 2021 term as informed by BC Public Health Officer guidelines. Refer to each course listing for details.
This hands-on course aims to introduce the student to the basics of how to acquire sound forensic evidence from the most common digital devices found today. From laptop/desktop computers, mobile phones, tablets, servers, USB drives, RAID arrays or proprietary CCTV DVR's; each device type often requires a unique combination of techniques and forensic tools to capture a forensic image that can be used for evidentiary purposes.
Admission to a Forensic credential program or permission of the Program Coordinator.
Students who have been accepted into a Forensics program where this course is a part of the matrix may register without any further approvals. Students who are not currently accepted in a Forensics program or, if this course is NOT part of your program matrix, please contact the Program Assistants for departmental approval at BCIT_Forensics@bcit.ca. For information on Forensic programs and courses, please visit: https://www.bcit.ca/cas/forensics. This course will be delivered partially online and partially in-person for 2021 Fall term: ONLINE Classes: September 13, 20, 27, Oct. 4, 25, Nov. 8 (Mondays, from 6 - 9:30p) IN PERSON Classes (DTC): - October 9 (Saturday, 9am - 5pm) - October 18 (Monday, 6pm-9:30pm - Midterm) - October 30 (Saturday, 9am - 5pm) - November 1 (Monday, 6pm - 9:30pm - class assignment) - November 15 (Monday, 6pm - 9:30pm - Final) No class October 11 (Thanksgiving Monday)
This course offering is in progress. Please check back next term or subscribe to receive email updates.
Upon successful completion of the course, the student will be able to:
Outline how data is stored and the different types of data storage devices.
Outline the various methods that can be employed to create a forensic image from a variety of digital storage devices.
Select the best method of forensic evidence collection to be implemented for a given device.
Practice removing the physical storage device from a variety of digital devices without compromising the integrity of the host device.
Conduct evidence acquisition from both live and dead systems.
Conduct RAM acquisition.
Execute the acquisition of a complete forensic image using different forensic tools on a variety of devices (tablets, mobile phones, CCTV DVR, Desktop/laptop computer, server).
Effective as of Spring/Summer 2017
FSCT 7509 is offered as a part of the following programs:
Interested in being notified about future offerings of FSCT 7509 - Introduction to Forensic Evidence Imaging and Acquisition?
If so, fill out the information below and we'll notify you by email when courses for each new term are displayed here.