24,428 courses · 2,504 curriculum guides Sponsored by eAgentic Software Sponsored by eAgentic Software

Advanced Digital Forensics

CET4861 — Advanced Digital Forensics
← Course Modules
3 credit hours 45 contact hours Prerequisites: CET4860 (Introduction to Digital Forensics) is the prerequisite at Daytona State, which publishes this at 3 credits offered fall. It is a hands-on upper-division course requiring prior working knowledge of computer systems and Linux. Access to the programme's forensic laboratory is required. Consult your programme's published curriculum plan. v1.0

Course Description

Advanced Digital Forensics covers the forensic process; NTFS, EXT and HFS+ file systems; Windows registry forensics; RAM and swap capture; and mobile device forensics. It is a hands-on learning experience that requires students to have prior knowledge of computer systems and Linux.

Within the SCNS taxonomy, CET is the Computer Engineering Technology prefix. Daytona State publishes this at 3 credits, offered fall, with CET4860 as prerequisite, giving approximately 45 contact hours at the prefix's unsuffixed convention.

The step up from the introductory course is substantial and it is a step in two directions at once. The file systems get harder — NTFS, EXT and HFS+ are far more complex than FAT, and each stores metadata differently. And the evidence sources multiply: the Windows registry, volatile memory, and mobile devices are each a specialised discipline in their own right. Memory forensics in particular changes what is findable, because a great deal of what matters in a modern intrusion never touches disk at all.

⚠ The Linux prerequisite is real. Much advanced forensic tooling is command-line and Linux-based, and students who are not comfortable in a shell will spend this course fighting the environment rather than learning the subject.

Daytona State does not publish a lecture and laboratory split for its CET courses. The prefix's unsuffixed courses run consistently at 15 contact hours per credit — CET1588, CET2544, CET2691, CET2792, CET2793, CET2794, CET3505 and CET4542 are all published at 3 credits and 45 hours, without exception. Its C-suffixed courses run at 20 or above and its L-suffixed laboratories at 30. This course is unsuffixed and is priced at the unsuffixed convention.

Learning Outcomes

Required Outcomes

Optional Outcomes

Major Topics

Required Topics

Optional Topics

Resources & Tools

Career Pathways

Special Information

⚠⚠ Memory forensics changes what is findable — and the evidence disappears at power-off

⚠ Mobile forensics is a distinct discipline with distinct obstacles

⚠⚠ Chain of custody and admissibility — evidence you cannot defend is evidence you do not have

⚠⚠ Authorisation is the line between a security professional and a defendant

⚠ Certifications carry real weight in this field — more than in most

How Florida course levels affect transfer

The first digit of an SCNS number denotes the year of offering, not transferability. Courses at the 1000 and 2000 levels transfer transparently between Florida public institutions, and 3000 to 4000 is unproblematic since both are upper division. The boundary that actually matters is 2000 to 3000, where lower-division credit generally cannot satisfy an upper-division requirement.

⚠ That boundary is live in this prefix. Daytona State offers CET courses at the 1000, 2000, 3000 and 4000 levels, the upper-division ones forming part of a bachelor of applied science. A 2000-level CET course does not substitute for its 3000- or 4000-level counterpart even where the subject matter overlaps — compare CET2880C/CET2881C (Data Forensics I and II, lower division) with CET4860/CET4861 (Introduction to and Advanced Digital Forensics, upper division). Confirm with an advisor which lower-division courses feed the BAS.

CET4861 is 3 credits and approximately 45 contact hours, offered fall at Daytona State, prerequisite CET4860.

⚠ Comfort with Linux and the command line is assumed, not taught — if that is weak, address it before the course starts. See also CET4862 (Network Forensics and Incident Response).


Generated September 3, 2026 · Updated September 3, 2026