This Level 7 Digital Forensics portfolio requires students to conduct a structured forensic investigation across disk, memory and Windows Registry evidence. The assessment develops practical investigative skills alongside professional forensic reporting and requires students to preserve evidence integrity, document methodology, interpret technical artefacts and communicate findings clearly. The portfolio is equivalent to 3,500 words and forms 60% of the module assessment. The first part involves analysing a seized USB forensic image in the context of a suspected insider involved in video piracy and potentially more serious criminal activity. Students must follow ACPO digital forensic best practice, verify image integrity before and after examination, maintain a clear chain of custody, identify significant device properties and artefacts, and justify conclusions using evidence. Tools such as FTK Imager and Autopsy may be used, alongside other appropriate forensic utilities. The scenario also requires examination of an encrypted VeraCrypt container discovered within the evidence. The second part focuses on memory forensics using a Windows memory dump. Students are expected to reconstruct process execution timelines, examine suspicious processes including PowerShell, Notepad and AtomicService, identify process owners and SIDs, extract relevant memory artefacts and produce an executive summary suitable for a non-technical audience. The third part requires an extensive Windows Registry and system artefact investigation. Students examine operating-system information, users, network configuration, login activity, suspicious files, executable and DLL creation, BAM records, Prefetch artefacts, scheduled tasks, persistence mechanisms and evidence of potentially malicious activity. Findings must be supported with screenshots, extracted artefacts or other appropriate evidence. The assignment must use the university's official portfolio template and be submitted as a PDF. The template organises the work into forensic image analysis, memory investigation and Windows Registry investigation sections. For a public Reference Library entry, this title is better than simply “Digital Forensics Coursework” because it clearly communicates the three major technical components of the work.
Digital Forensics · Cyber Security · Disk Forensics · Memory Forensics · Windows Registry Forensics · FTK Imager · Autopsy · Volatility 3 · RegRipper · Chain of Custody · ACPO Guidelines · Forensic Imaging
Megaminds has supported academic requirements in cyber security / digital forensics, digital forensics and related disciplines.