| Th | Tu | Pr | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 3 | 0 | 0 | 3 | 3 | 25 00:45 | 50 01:30 | 100 03:00 | 200 |
To learn how computers work and handle data; to understand electronic evidence and various computer artefacts; to learn electronic evidence acquisition techniques; and to learn how to analyze Windows, Linux and Mac OS machines.
Number Systems: Binary, Octal, Decimal and Hexadecimal, Conversion and Operations on Binary Number Systems, Representing Information in Hexadecimal and Binary, Little Endian and Big-Endian Formats. Computer Architecture: Input Devices, Central Processing Unit, Storage Devices and Output Devices. Secondary Storage Devices: Understanding Disk, Volume and Partition, HDD and SSD Structures, Introduction to MBR, GPT and VBR. Basics of Operating Systems: Role of Operating System, Boot Process, Introduction to Process and Memory Management.
Digital Forensics: Definition, Process, Locard's Principle of Exchange, Branches of Digital Forensics, Handling Digital Crime Scene, Important Documents and Electronic Evidences. Introduction to Evidence Acquisition: Identification, Acquisition, Labelling and Packaging, Transportation, Chain-of-Custody, Importance of Documentation and Preservation. Acquisition Process: Write-Blockers, Imaging Techniques, Evidence Integrity, Standard Operating Procedures for Acquisitions and Preservation of Evidences. Introduction to Data Recovery and Carving: Importance of Data Recovery in Forensic Investigation, Carving Methods, Difference between Data Recovery and Carving.
Windows OS Architecture, File System Analysis: Understanding and Analyzing FAT and NTFS File Systems, Recreating FAT and NTFS Partitions, Analyzing Unallocated Partitions. Registry Analysis: Understanding Windows Registry, Analyzing Windows Registry, Finding Important Artefacts Related to User Activities, User/Application Configurations and Preferences; Attached Devices, Shared Locations, Recently Accessed Documents, Programs and Locations; Installed Applications and Others from Windows Registry. Event and Log Analysis: Introduction to Windows Events, Understanding Windows Events (Evt and Evtx Files), Analyzing Logs of Third-party Applications.
Linux OS Architecture, File System Analysis: Understanding and Analyzing EXT File System, Recreating EXT Partitions, Analyzing Unallocated Partitions. Log Analysis: Understanding Various Logs, Analyzing Important Logs to Find Important Artefacts Related to User Activities, User/Application Configurations and Preferences; Attached Devices, Shared Locations, Recently Accessed Documents, Programs and Locations; Installed Applications.
MAC OS Architecture, File System Analysis: Understanding and Analyzing HFS and HFS+ File System, Recreating HFS Partitions, Analyzing Unallocated Partitions. Log Analysis: Understanding Various Logs, Analyzing Important Logs to Find Important Artefacts Related to User Activities, User/Application Configurations and Preferences, Attached Devices, Shared Locations, Recently Accessed Documents, Programs and Locations, Installed Applications.
| Th | Tu | Pr | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 3 | 1 | 0 | 4 | 4 | 25 00:45 | 50 01:30 | 100 03:00 | 200 |
To learn security audit and compliance; to understand the process of security audit; to understand industry-standard auditing practices; to learn various security standards; to learn policy-making and organizational structure; and to understand risk and continuity planning.
What is IT security assessment? What is an IT security audit? What is compliance? How does an audit differ from an assessment? Why are governance and compliance important? What if an organization does not comply with compliance laws? What is the scope of an IT compliance audit? What does your organization do to be in compliance? What are you auditing within the IT infrastructure? Maintaining IT compliance.
Defining the scope for audit, identifying critical requirements for the audit, assessing IT security, obtaining information, documentation and resources, mapping the IT security policy framework definition to the seven domains of a typical IT infrastructure, identifying and testing monitoring requirements. What are controls and why are they important: goal-based security controls, implementation-based security controls, the security control formulation and development process, setting the stage for control implementation through security architecture design, implementing a multitiered governance and control framework in a business. The IT audit process: audit plan, audit process, types of IT audits, Computer-Assisted Audit Techniques (CAATs) for sampling, application reviews, and auditing application controls.
Identifying the minimum acceptable level of risk and appropriate security baseline definitions, seven domains of a typical IT infrastructure, writing the IT infrastructure audit report. Compliance within the User Domain, the Workstation Domain, the LAN Domain, and the LAN-to-WAN Domain: requirements, business drivers, common devices/components, maximizing C-I-A, penetration testing and validating configurations. Compliance within the Remote Access and Application Domain: common devices/components, application server vulnerability management, application patch management.
Introduction to risk analysis, risk identification, risk assessment, risk response and mitigation, risk reporting. Introduction to Business Continuity Planning (BCP): overview of the BCP life cycle, need for BCP, identifying and selecting business continuity strategies. Introduction to Disaster Recovery (DR) planning: identification of potential disaster status, DR strategies, plans for business resumption.
Indian IT Act with amendments, adjudication under the Indian IT Act. Auditing standards and frameworks: ISO/IEC 27001/2, COBIT, SOC Compliance, HIPAA, GDPR and PCI DSS.
| Th | Tu | Pr | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 3 | 1 | 0 | 4 | 4 | 50 00:45 | 50 01:30 | 100 03:00 | 200 |
The primary objective is to teach students how to identify and classify various types of cybercrimes occurring in the digital realm; comprehend the fundamental principles and methodologies of Digital Forensics, including data acquisition, analysis, and preservation of digital evidence in accordance with legal standards; and gain insight into the key sections of the IT Act and related laws governing the admissibility of digital evidence in legal proceedings.
Cyber-crime – overview, internal and external, online and offline attacks. Cyber-crime against individuals and organizations – email spoofing, phishing, spamming, unauthorized access, DoS/DDoS, computer sabotage, malware, email bombing, salami attack, software piracy, industrial espionage, crimes on social media, banking frauds, IP frauds.
Digital Forensics – introduction, objective, methodology, rules and services, branches: Live, Disk, Network, Mobile Device Forensics etc.
Incident Response and First Responder at crime scene – role, toolkit, stages, do's and don'ts. Types and sources of digital evidence, collection principles, Best Evidence Rule, forensic readiness, ethics, search/seizure/preservation of volatile and non-volatile evidence, imaging, hashing, deleted data recovery.
IT Act 2000 – objectives, applicability, definitions, amendments; digital signature, electronic records/evidence/governance; IT (Amendment) Act 2008; cyber-crimes under Sections 43(a)-(j), 43A, 65, 66, 66A-66F, 67, 67A, 67B, 70, 70A, 70B, 80 with penalties; penal provisions for phishing, spam, malware, hacking, stalking; relevant sections of Indian Evidence Act.
| L | T | P | C | TCH | TA-1&2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 4 | 0 | 0 | 4 | 4 | 50 01:30 | 50 01:30 | 100 03:00 | 200 |
A comprehensive understanding of forensic voice and video analysis — covering the history and theory of voice production, speaker recognition and profiling techniques, handling and examination of audio evidence, and forensic video examination including processing, authentication, legal admissibility, biometric analysis and CCTV forensics through related case studies.
History of voice analysis, voice production theory, interspeaker/intraspeaker variations, text-dependent/independent recognition, discriminating tests, handling and physical examination of audio recording evidences, marking of speakers, preparation of working copies.
Segregation of speech samples, auditory/spectrographic/automatic recognition techniques, enhancement and normalization, authenticity and integrity, speech signal processing, Fourier analysis, analogue-to-digital conversion, instruments, report writing, admissibility of audio evidence in court.
Definition, scope, significance in crime investigation, collection/handling/preservation of video files, frame extraction, shot-by-shot analysis, video authentication, metadata analysis, hash value generation, biometric analysis, facial biometrics.
Acquisition/handling/preservation of CCTV footage, hash generation, DVR/NVR extraction, chain of custody, authentication and enhancement, forensic tools, legal admissibility.
| Th | Tu | Pr | C | TCH | TA-1/2 | MSE | Univ. Exam | Total |
|---|---|---|---|---|---|---|---|---|
| 03 | 00 | 00 | 03 | 03 | 25 00:45 | 50 01:30 | 100 03:00 | 200 |
Definition & characteristics, evolution, physical/logical design, IoT components, levels and deployment techniques, applications & domains, enabling technologies, challenges in IoT.
M2M vs IoT, Software Defined Networking (SDN), Network Function Virtualization (NFV), SNMP and its limitations, network operator requirements, H/W and S/W communications (UART, SPI, I2C, JTAG).
Protocol stack for IoT, HTTP, MQTT, XMPP, COAP basics and architectures.
Interoperability, need for security, privacy & threats, attack vectors & surfaces, pen testing approaches, OWASP Top 10 for IoT, threat modeling, cloud security architecture, case study.
Introduction to IoT forensics, forensic investigation of IoT devices & components, forensic tools & techniques, standards and guidelines, case study.
Teaching has always been close to my heart — a passion shaped by my mother, who served as a state award–winning teacher in the government school system. Inspired by her dedication and impact, I chose to pursue a life in academia where I could blend learning, discovery, and the joy of guiding future engineers.
My academic journey began with a B.Tech. in Computer Science and Engineering from NIT Calicut, followed by an M.Tech. from the University of Kerala. I then completed my Ph.D. in Computer Science at the University of Hyderabad, with doctoral research carried out at the Center of Excellence in Cyber Security, IDRBT — an institute established by the Reserve Bank of India.
I had the privilege of being mentored by Prof. B. M. Mehtre, a pioneer behind India's first Automated Fingerprint Identification System (AFIS). Over the years, my research has led to publications in Forensic Science International (SCI, Q1) and Signal, Image and Video Processing (SCIE, Q2), as well as multiple Scopus-indexed conference papers and book chapters.
At IDRBT, I led large-scale cyber drills involving more than 25 participants at a time, helping banks improve incident response capabilities in line with RBI directives. My digital forensics experience includes the FRED forensic workstation and tools such as EnCase, Oxygen Forensics, and Paraben SIM analysis suites.
Today, my research spans image forensics and cyber defense analytics—driven by a belief that technology should enable trust, and that education empowers individuals to secure the world they build. Guided by this philosophy, I combine research with hands-on forensic practice, using tools such as Amped FIVE and Amped Authenticate to examine CCTV footage and verify the authenticity of questioned images.
NB: All academic programs completed in Regular Full-Time mode.
| Service | Govt Agencies (MHA) | Other Govt | Private / Industries |
|---|---|---|---|
| Digital Forensic As-A-Service per Exhibit | ₹ 13,310 /- | ₹ 13,310 /- same | ₹ 13,310 /- same |