Fall 2026 St. John's University

DFR 711: Cyber Forensics & Malware Analysis

An applied graduate course in digital forensics, incident reconstruction, and malware analysis, progressing from guided practice to applied analysis and independent investigation.

Professor: Avijit Roy
Class meets: Mondays, 5:00 PM–7:00 PM | St. Augustine Hall, Room 2-141
Office hours: By appointment Avijit [DOT] Roy [AT] stjohns [DOT] edu

Course Information

Course description: This course provides an introduction to advanced digital forensics topics including malicious software (malware) and its analysis. Students will gain hands-on experience using open-source and commercial software tools in a digital laboratory environment. Students will study the forensic characteristics of Windows, macOS (OS X), and Linux platforms. Reverse-engineering techniques utilized to conduct static and dynamic analysis will be examined. Students will also learn about the importance of principles, legal considerations, controls, and documentation of forensic procedures.

Course approach: Class time will be used for lecture, discussion, demonstrations, guided analysis, and feedback. The field changes rapidly and the course covers multiple evidence sources and platforms. We may not cover every tool command, artifact, or troubleshooting scenario during class. However, you will be provided with the necessary guidance, resources, and supporting materials to complete the required work and continue your learning independently.

Students are expected to complete assigned readings before class and engage in independent technical research outside class. Laboratory guides will provide clear setup instructions and sufficient structure to complete the required work, but later exercises will intentionally require more independent decision-making. The progression is guided practice → applied analysis → independent investigation.

Prerequisites: No formal prerequisite is listed in the current departmental course record. Students are nevertheless expected to be comfortable with operating systems, files and directories, basic networking, and command-line use. Students who need additional background are expected to complete preparatory readings and tutorials as assigned.

Student Learning Outcomes

  • Plan and document a defensible digital forensic investigation, including scope, evidence identification, preservation, acquisition, integrity verification, chain of custody, and reporting.
  • Perform and validate forensic acquisitions and working-copy preparation using appropriate forensic methods.
  • Analyze Windows forensic artifacts, including file-system, Registry, Event Log, execution, persistence, and timeline evidence.
  • Identify and interpret relevant forensic artifacts on Linux and macOS systems.
  • Locate and analyze network-based evidence, including packet captures and supporting network/security logs.
  • Acquire or analyze volatile-memory evidence to identify suspicious processes, network activity, and malware-related behavior.
  • Perform malware triage and static and dynamic malware analysis in an isolated, controlled environment.
  • Apply reverse-engineering, disassembly, and debugging techniques to interpret suspicious code and malware behavior.
  • Recognize common packing, obfuscation, persistence, command-and-control, and anti-analysis techniques.
  • Apply threat-intelligence and threat-hunting concepts, including indicators of compromise and MITRE ATT&CK mapping.
  • Apply mobile-device forensic acquisition and analysis approaches using appropriate tools and datasets.
  • Produce clear, reproducible, evidence-supported reports for technical and non-technical audiences.

Course Outline — Fall 2026

This syllabus provides the planned semester course outline. Canvas is the authoritative source for course readings, laboratory guides, assignment instructions, announcements, release dates, final submission deadlines, and any subsequently announced schedule changes.

Important Fall 2026 University Dates
DateUniversity Calendar Item
Wednesday, September 2First day of classes
Monday, September 7Labor Day — University closed; no classes
Wednesday, September 9Last day to add or change a class
Tuesday, September 22Last day to drop a class without transcript notation
Wednesday, September 23Withdrawal period begins
Monday, October 12Fall Mini Break — University closed; no classes
Tuesday, October 13Monday classes meet
Wednesday, October 21Midterm grades due
Monday, November 9Last day to withdraw or apply for Pass/Fail
Wednesday, November 11Veterans Day — University closed; no classes
Wednesday, November 25Thanksgiving Recess — no classes
Thursday–Saturday, November 26–28Thanksgiving Recess — University closed
Thursday–Friday, December 10–11Snow/Study Days — no classes
Monday–Saturday, December 14–19Final Exam/Assessment Week
September 14 | Meeting 1: DFIR Foundations

Investigative models, incident response, evidence, scope, legal and ethical boundaries, documentation, and chain of custody.

Course orientation · Begin Lab 1 preparation
September 21 | Meeting 2: Evidence Acquisition & Preservation

Order of volatility, imaging, working copies, hashing, integrity verification, and live versus offline acquisition.

Lab 1: Acquisition & Integrity
September 28 | Meeting 3: Windows Forensics I

NTFS, MFT, deleted and unallocated data, Registry foundations, and file-system artifacts.

Windows evidence practice
October 5 | Meeting 4: Windows Forensics II

Event Logs, execution artifacts, Prefetch, LNK and Jump Lists, persistence, and timeline reconstruction.

Lab 2: Windows Investigation
October 12 | No Class

Fall Mini Break — University closed.

Tuesday, October 13 | Meeting 5: Linux & macOS Forensic Artifacts

Cross-platform forensic reasoning and midterm review. This Tuesday follows the Monday class schedule.

Midterm Take-Home released
October 19 | Meeting 6: Midterm Exam & Network Forensics Introduction

In-class midterm exam followed by an initial packet-capture workflow.

In-class Midterm Exam
October 26 | Meeting 7: Network Forensics & PCAP Investigation

Protocols, sessions, DNS/HTTP/FTP evidence, exfiltration, and IOC extraction.

Lab 3: Network Investigation
November 2 | Meeting 8: Memory Forensics

Processes, parent/child relationships, command lines, DLLs, sockets, suspicious memory, and Volatility 3.

Lab 4: Memory Investigation
November 9 | Meeting 9: Malware Foundations & Triage

Hashes, strings, file signatures, PE structure, imports, sections, entropy, and initial indicators.

Malware-analysis environment check
November 16 | Meeting 10: Static & Dynamic Malware Analysis

Behavior monitoring, file-system, Registry, process, and network changes, and controlled execution.

Lab 5: Malware Analysis
November 23 | Meeting 11: Reverse Engineering, Disassembly & Debugging

x86/x64 concepts, control flow, functions, Ghidra disassembly and decompilation, and debugging foundations.

Reverse-engineering practice
November 30 | Meeting 12: Advanced Malware & Threat Hunting

Packing, obfuscation, anti-analysis, persistence, command and control, YARA, Sigma, and MITRE ATT&CK.

Lab 6: Reverse Engineering / Hunting
December 7 | Meeting 13: Mobile Forensics & Integrated Reconstruction

Mobile-device acquisition approaches, artifacts and analysis; integrated incident reconstruction; and the final assignment and research-paper workshop.

Final assignment briefing · Research-paper consultation
December 14–19 | Final Assessment Week

The final integrated assignment and research paper are due on the dates announced in Canvas.

Final Assessment Week
Tentative Major Deadlines
Item Tentative Deadline
Lab 1 — Acquisition & IntegritySunday, September 27, 2026
Lab 2 — Windows InvestigationSunday, October 18, 2026
Midterm ExamMonday, October 19, 2026 (in class)
Midterm Take-Home InvestigationSunday, October 25, 2026
Lab 3 — Network InvestigationSunday, November 1, 2026
Research Paper Topic / ProposalSunday, November 8, 2026
Lab 4 — Memory InvestigationSunday, November 15, 2026
Lab 5 — Malware AnalysisSunday, November 29, 2026
Lab 6 — Reverse Engineering / Threat HuntingSunday, December 6, 2026
Final Integrated AssignmentFinal Assessment Week — exact deadline announced in Canvas
Research PaperFinal Assessment Week — exact deadline announced in Canvas

All deadlines are tentative until posted in Canvas. Canvas is the authoritative source for assignment release dates and final submission deadlines.

Assessments & Grading

Performance is evaluated through applied investigations, individual assessments, research, and professional participation.

Technical Laboratory Investigations

25% · Applied forensic and malware-analysis investigations.

Students will complete a series of applied forensic and malware-analysis investigations. Early laboratories will provide precise step-by-step setup and workflow guidance. Later laboratories will provide the evidence, objectives, constraints, and expected deliverables while requiring students to determine more of the investigative path independently.

  • Evidence acquisition, hashing, working copies, preservation, and chain-of-custody documentation.
  • Windows artifact analysis and timeline reconstruction.
  • Network forensic analysis using packet captures and related evidence.
  • Memory-forensic analysis using Volatility 3 or an equivalent approved tool.
  • Malware triage and static/dynamic analysis in an isolated environment.
  • Reverse-engineering and/or threat-hunting using tools such as Ghidra, YARA, and MITRE ATT&CK.

Midterm Exam

15% · In class.

An in-class exam will assess foundational concepts, forensic methodology, evidence handling, acquisition, operating-system artifacts, and the interpretation of technical evidence covered through the first half of the course. The exam may include short-answer, scenario-based, artifact-interpretation, and applied reasoning questions.

Midterm Take-Home Investigation

15% · Independent case analysis and concise forensic report.

The midterm take-home assignment will require students to analyze a defined evidence set or case scenario and produce a concise forensic report. Students will be expected to document methodology, tool versions, relevant findings, supporting evidence, limitations, and conclusions. This assignment is designed to assess independent investigation and professional documentation beyond the timed exam.

Final Integrated Analysis

20% · Integrated forensic and malware-analysis assignment.

The final technical assignment will integrate multiple course areas. Depending on the final evidence package, students may be asked to correlate disk/host artifacts, volatile memory, network evidence, and a suspicious executable; reconstruct a timeline; identify indicators of compromise; interpret malware behavior; and produce a defensible evidence-supported report.

Research Paper

20% · Graduate-level research on an approved topic.

Each student will complete a graduate-level research paper on an approved topic related to digital forensics, malware analysis, incident response, forensic tooling, evidence interpretation, threat hunting, or a closely related area. The paper must demonstrate a clear research question or technical problem, engagement with relevant literature, critical analysis, and a defensible contribution or synthesis.

Participation & Professional Practice

5% · Preparedness, engagement, and responsible laboratory practice.

Participation includes preparation, technical discussion, demonstrations, professional collaboration, appropriate questions, evidence-based reasoning, and responsible use of the laboratory environment.

Grading Breakdown

AssessmentWeight
Technical Laboratory Investigations25%
Midterm Exam (in class)15%
Midterm Take-Home Investigation15%
Final Integrated Forensic/Malware Analysis Assignment20%
Research Paper20%
Class Participation, Preparedness & Professional Practice5%
Total100%

Grading Scale

A93–100A−90–92
B+87–89B83–86
B−80–82C+77–79
C73–76C−70–72
D+67–69D60–66
F59 or less

Forensic Reporting Expectations

Technical submissions should be reproducible and evidence-driven. Unless an assignment states otherwise, reports should include appropriate elements such as an executive summary, case background, scope, methodology, evidence identifiers and hashes, findings, analysis and interpretation, limitations, conclusion, references, and appendices containing supporting logs, commands, screenshots, or artifact details. A sample report will be provided during class.

Students whose research demonstrates particularly strong quality, novel ideas, useful empirical findings, or clear publication potential may be invited to continue developing the work with the instructor after the course. Any conference or journal submission is a separate research activity requiring additional revision, validation, and appropriate authorship and venue practices. Publication is not guaranteed and is not required for the course grade.

Required Materials, Technical Environment & Tools

Readings & Course Resources

Required readings, laboratory guides, assignment instructions, and supplemental technical resources will be provided or linked through Canvas. Students are responsible for completing assigned readings and preparation before class.

Primary course references:

  • Monnappa K A. Learning Malware Analysis: Explore the Concepts, Tools, and Techniques to Analyze and Investigate Windows Malware. Packt.
  • Gerard Johansen. Digital Forensics and Incident Response, 2nd edition. Packt.

These texts may be used selectively alongside current documentation, standards, research papers, and instructor-provided materials. Current official documentation and instructor materials may supersede procedures or screenshots in older references.

Technical Environment

The course is vendor-neutral. Specific products may change based on University licensing, laboratory availability, operating-system compatibility, and current tool support. Students should expect a combination of free/open-source tools and, where available, commercial forensic platforms.

Area Likely Free or Open Tools License-Dependent Examples
Virtualization / LabVMware Workstation/Fusion, VirtualBox where appropriate, REMnuxUniversity-provided virtualization platforms if available
Acquisition / DiskFTK Imager where licensing permits, Autopsy / Sleuth Kit, dd-compatible imaging toolsFTK, EnCase, Magnet AXIOM, or equivalent
Windows ArtifactsEric Zimmerman tools, Registry Explorer, Timeline Explorer, KAPE where appropriateCommercial suite artifact parsers
MemoryVolatility 3Commercial memory-analysis features
NetworkWireshark, tcpdump, NetworkMiner Community where appropriateCommercial network-forensic tools
Malware TriageDetect It Easy, FLOSS, PEStudio or equivalent, hashing and string utilitiesCommercial malware-analysis or sandbox platforms
Dynamic Malware AnalysisSysinternals Procmon, Process Explorer, Autoruns, TCPView; Regshot; FakeNet-NG; REMnuxCommercial sandbox or EDR tools
Reverse EngineeringGhidraIDA Pro or other licensed disassemblers
Threat HuntingYARA, Sigma concepts and tooling, MITRE ATT&CKCommercial SIEM or EDR platforms
MobileMobile backups/images, SQLite viewers, and artifact-analysis utilitiesCellebrite, Magnet, or equivalent

Students should not purchase commercial forensic software unless specifically instructed. Equivalent tools may be substituted when licensing or technical constraints require a change.

Recommended Student Computer Capability

  • A computer capable of running at least one virtual machine.
  • 16 GB RAM recommended; more may help with memory-analysis exercises.
  • Approximately 100 GB of free storage for virtual machines, forensic images, memory captures, and working copies.
  • Hardware virtualization enabled where required.
  • Administrator rights for local laboratory setup, or access to a University-managed laboratory environment.
  • Reliable Internet access for course resources and approved software/documentation downloads.

Malware & Laboratory Safety

Course exercises may involve suspicious files, malware samples, forensic images, memory captures, packet captures, and other security-related artifacts. Malware-related work must be performed only within the isolated environment and procedures authorized by the instructor.

  • Do not execute course malware samples directly on a personal or production computer.
  • Do not disable required isolation controls or connect an environment containing active malware to an unauthorized network.
  • Do not redistribute malware samples, course evidence, or restricted case materials.
  • Do not upload course evidence, suspicious binaries, or sensitive data to public services unless the instructor explicitly authorizes it.
  • Do not use course techniques or tools against systems, accounts, networks, or data without explicit authorization.

Failure to follow laboratory safety procedures may result in removal from the exercise and may be addressed under applicable University policies.

Responsibilities & Policies

Attendance

Because this course meets only once each week and includes demonstrations, guided investigations, and technical discussion, attendance is important. Students are expected to attend every scheduled meeting, arrive on time, and remain engaged for the full class period.

One documented/excused absence may be accommodated without an attendance-related penalty. Additional absences will be reviewed individually in light of documented circumstances and applicable University policies. Students remain responsible for all readings, demonstrations, announcements, assignments, and deadlines missed because of absence and should contact the instructor as early as possible.

Class Participation

Participation includes preparation for class, contribution to technical discussions, engagement during demonstrations, professional collaboration, appropriate questions, evidence-based reasoning, and responsible use of the laboratory environment. It is not measured by speaking frequently; thoughtful preparation and professional engagement are the standard.

Classroom Etiquette

  • Arrive on time, prepared, and ready to participate.
  • Complete assigned preparation before class so that scheduled time can focus on analysis, application, and discussion rather than basic terminology.
  • Laptops are expected for technical work but should be used for course-related activities during lecture and discussion.
  • Phones should be silenced and should not interfere with class activities.
  • Respect classmates, guest speakers, and differing technical approaches. Critique evidence and methodology rather than individuals.
  • Do not photograph, record, copy, or distribute restricted evidence, malware samples, credentials, or other sensitive course materials unless authorized.

Limited Use of Generative AI

You may use generative artificial intelligence (GAI) tools on a limited basis. Permitted uses include generating ideas, summarizing complex concepts for study, developing practice questions or study aids, critiquing your understanding, and receiving suggestions for improving work you have already written.

You may not submit GAI-generated material as your own, use GAI to develop answers for assignments or exams, fabricate references, automate discussion participation, analyze assigned cases or simulations for you, rewrite your work, or bypass the learning process.

Whenever you use GAI, you must identify the tool and explain how it was used. Failure to disclose its use will be considered academic misconduct. You are responsible for evaluating the validity, accuracy, and reliability of all GAI output and for any errors introduced through its use. Do not enter sensitive, confidential, personally identifying information, course evidence, malware samples, restricted case data, or University-owned course materials into an external GAI tool unless specifically authorized. When in doubt, consult the instructor before using GAI.

AI detectors or “AI checkers” will not be treated as proof of misconduct. Where authorship or learning is in question, the instructor may review drafts, notes, version histories, source verification, inconsistencies in a submission, technical artifacts, and/or ask the student to explain the work and investigative process.

Academic Integrity

All St. John's University students are expected to abide by the Academic Honor Pledge. Cases of academic misconduct will be addressed in accordance with University and College procedures and may result in loss of credit for the work, loss of credit for the course, or additional disciplinary action.

Review the University's Academic Honor Pledge.

Intellectual Property & Copyright

As a course professor, I may make recorded sessions or related contents available to students to meet ADA, accreditation, or other needs. Under no circumstances should recordings, lectures, laboratory guides, evidence sets, malware samples, or other course materials be sold and/or otherwise transferred for someone else's use. Students are prohibited from distributing recordings or other course materials without permission.

Materials in this course—unless otherwise indicated—are protected by United States copyright law [Title 17, U.S. Code]. Materials are presented in an educational context for personal use and study and should not be shared, distributed, or sold in print or digitally outside the course without permission. Students' ability to post or link to copyrighted material is also governed by United States copyright law.

Health Notification Accommodation

In addition to contacting Student Health Services, students are responsible for sharing any health issues with the professor, including the need to self-isolate or quarantine, when those issues affect course participation.

Services for Students with Disabilities

Services for students with a documented disability are available through the Office of Disability Services. All documentation is kept confidential and should be submitted directly to the Office of Disability Services. Students requesting accommodation should identify their needs as early as possible. A student with verified disabilities will be provided with an accommodation letter to present to the professor.

Designated contact: Luis Manzo, Assistant Vice President for Student Wellness, 8000 Utopia Parkway, Queens, NY 11439 · [email protected] · 718-990-6911.

Notice of Non-Discrimination & Equal Opportunity

St. John's University does not discriminate on the basis of race, color, national or ethnic origin, sex (including sexual harassment and sexual violence), sexual orientation, gender identity, disability, religion, age, status in the uniformed services of the United States (including veteran status), marital status, status as a victim of domestic violence, citizenship status, genetic predisposition, or carrier status in its programs and activities as required by applicable law and University policy.

Title IX Coordinator: Esther Hutchinson, Director of Equal Opportunity, Compliance and Title IX Coordinator, 8000 Utopia Parkway, Queens, NY 11439 · [email protected] · 718-990-1448 · Title IX information.

Class Cancellation & Weather

  • The course will be taught in the modality officially assigned by the University. Modality changes require appropriate University approval.
  • Class periods will begin and end at the scheduled time.
  • If an unplanned instructor absence is necessary, the department and students will be notified as soon as possible and alternative arrangements will be provided where required.
  • Planned absences require prior approval through the appropriate University process and an alternative learning experience may be assigned.
  • If the instructor is more than fifteen minutes late without notice, students may follow the University policy described in the current course-outline template.
  • If the University closes the campus for weather-related reasons, the course may move to remote instruction when feasible; otherwise required instructional time will be made up in accordance with University policy.

Professional & Ethical Use of Course Skills

Digital-forensic and malware-analysis techniques can expose sensitive information and can be misused if applied without authorization. All work in this course must be performed on instructor-approved evidence, systems, accounts, or environments. Students are expected to follow applicable law, University policy, professional ethics, privacy requirements, and the scope of authorization provided for each exercise.

Syllabus Change Statement

This syllabus represents the planned structure of the course. The instructor may make reasonable changes to readings, tools, evidence sets, assignment sequencing, due dates, or topic emphasis to respond to student progress, University requirements, software/tool changes, licensing, security considerations, or developments in digital forensics and malware analysis. Material changes will be communicated through Canvas.

University Academic Support

The University Learning Commons (ULC) provides free tutoring and academic support. Students should consult current University and Canvas resources for available in-person and online services, schedules, and NetTutor support.

Use Canvas for current course materials, readings, laboratory guides, assignment instructions, due dates, submissions, announcements, and changes. Do not upload restricted evidence, malware samples, or University-owned course materials to public services.

Course Updates

  • September 6, 2026 — Fall 2026 web syllabus published from the instructor-developed campus syllabus.

Last updated: