Module Descriptors
DIGITAL FORENSICS AND PENETRATION TESTING
COMP70089
Key Facts
Digital, Technology, Innovation and Business
Level 7
30 credits
Contact
Leader: Ange Aly
Hours of Study
Scheduled Learning and Teaching Activities: 78
Independent Study Hours: 222
Total Learning Hours: 300
Assessment
  • DEMONSTRATION - A PRACTICAL SKILLS-BASED DEMONSTRATION - 1 HOUR (INCLUDING 15 MINUTES OF Q&A) weighted at 50% - Learning outcome(s) assessed: 2,3
  • REPORT - A REPORT RELATED TO EVIDENCE GATHERING AND PRESENTATION OF THIS INFORMATION - 2000 WORDS weighted at 50% - Learning outcome(s) assessed: 1,4
Module Details
INDICATIVE CONTENT
This module addresses topics of:

Introduction to digital forensics and penetration testing
Legal, ethical and professional frameworks, including evidential integrity and admissibility
Digital forensic standards, acquisition methods and chain of custody
Windows, Linux and common file systems
Incident response and triage
Foot printing, scanning, enumeration and vulnerability assessment
System exploitation in contained and authorized environments
Post-exploitation, documentation and post-test actions
Log, memory, disk, network and mobile artefact analysis
Reporting, technical communication and presentation of findings
Use of tools such as Wireshark, Autopsy, FTK Imager, EnCase, Kali Linux, and related utilities
Research-led developments in offensive security and digital investigation

BCS / TechSkills / Employability elements:

Professional Practice related to evidence gathering and storage
Digital Forensics approaches and methods used in industry
Legal, social, and ethical aspects of computing in industry
ADDITIONAL ASSESSMENT DETAILS
DEMONSTRATION - A skills demonstration under exam conditions. You will be asked to undertake a penetration test of a given target in a contained and legal environment, within the target there will be 10 “flags” which contain unique information. You will be asked to undertake penetrating testing activities, in line with the ethical hacking lifecycle, to locate the flag information and will need to provide the information contained as answers to the examination.

REPORT - This will assess your understanding of the background science of digital forensics, methodologies, tools, techniques, and standards used in forensic investigations. As a forensic investigator, you will need to conduct a digital forensic investigation during a criminal investigation of a given offence. You will be required to obtain and present any located evidence suggesting criminality, or any information of note e.g. account names, passwords, images, and files etc.

Formative assessment opportunities will be provided throughout the module. In generating documentation of the report staff will regularly review your progress. This will include both written work and forensic process as you progress. For the demonstration aspect regular guidance will be provided in practical sessions.
LEARNING STRATEGIES
Teaching will blend theory and practice through lectures, tutorials, lab-based activities, case studies, and directed independent study. You will apply conceptual knowledge within controlled technical environments, supported by formative exercises that develop confidence in both investigative and offensive security workflows. Resources for independent learning will include academic literature, technical guidance, industry case material, and scenario-based tasks.
LEARNING OUTCOMES
1. Critically evaluate digital forensic principles, penetration testing methodologies, and the legal, ethical, and professional frameworks governing their application from completed research.

Knowledge & Understanding
Research Skills

2. Analyse through research systems and digital evidence sources to identify vulnerabilities, forensically significant artefacts, and indicators of compromise using appropriate industry-standard tools and techniques.

Research Skills
Application and Problem Solving

3. Conduct and document practical penetration testing and digital forensic activities in a controlled environment, selecting appropriate methods to acquire, preserve, examine, and report technical findings.

Application and Problem Solving
Digital Literacy

4. Critically present technical findings and recommendations in a form suitable for academic, professional, and investigative contexts, demonstrating defensible decision-making and awareness of evidential integrity through reflection.

Communication
Reflection
RESOURCES
Wireshark

FTK Imager

EnCase / Autopsy

XRY/XAMN

Kali Linux / ParrotOS

VMWare Workstation v16 or later

Machines and devices for seizing and imaging
TEXTS
Weidman, G. (2024), Penetration Testing: A Hands-On Introduction to Hacking, 2nd Edition, No Starch Press.

Engebretson, P. (2023), The Basics of Hacking and Penetration Testing: Ethical Hacking and Penetration Testing Made Easy, 3rd Edition, Syngress.

Stuttard, D. and Pinto, M. (2023), The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws, 2nd Edition, Wiley.

Kennedy, D., O'Gorman, J., Kearns, D. and Aharoni, M. (2022), Metasploit: The Penetration Tester's Guide, No Starch Press.

OWASP Foundation (2025), "OWASP Testing Guide" [Online] Available at: https://owasp.org/www-project-web-security-testing-guide/ (Accessed: 16/04/2026).
WEB DESCRIPTOR
This module introduces the complementary disciplines of digital forensics and penetration testing. You will explore how systems are attacked, how vulnerabilities are identified and assessed, and how digital evidence can be acquired, examined, and presented in a defensible manner. Through a combination of theory and practical activity, you will develop the knowledge and skills required to investigate incidents, evaluate security weaknesses, and communicate professional findings across technical, business, and investigative contexts.