Activity 01
Stations Rotation: Forensics Phases
Create five stations for preparation (tool setup), identification (log review), containment (network isolation sim), eradication (malware scan), and recovery (backup restore). Small groups rotate every 8 minutes, documenting actions and evidence at each. Debrief as a class on chain of custody.
Explain the steps involved in a typical digital forensics investigation.
Facilitation TipDuring the Station Rotation, circulate and ask guiding questions to ensure students connect each phase to real-world consequences, such as, 'What happens if you skip containment?'
What to look forPresent students with a scenario: 'A company server shows signs of unauthorized access. List the first three steps a digital forensics investigator should take, and briefly explain why each is important.'