Sep 21, 2026  
2026-27 Catalog 
    
2026-27 Catalog
Add to Portfolio (opens a new window)

CIS 370 - Network Forensics and Investigations

5 Credits
This course focuses on tracking down network intruders and the tactics, techniques, and procedures they use. When, what, where, and how they were able to gain access gives an investigator clues to design flaws in the network architecture.

Pre-requisite(s) CIS 150 and CIS 160 min 2.0 
Program Admission Required Yes Admitted Program BAS - CIS
FeesAcademic Technology Fee

Quarters Typically Offered
Fall Evening

Designed to Serve For students admitted to the BAS program in Cybersecurity and Digital Forensics.
Active Date 20260408T14:58:23

Grading Basis Decimal Grade
Class Limit 24
Contact Hours: Lecture 44 Lab 22
Total Contact Hours 66
Degree Distributions:
ProfTech Course Yes
Restricted Elective Yes
Course Outline
  1. Review of networks and infrastructure
  2. Review of network protocols
  3. Network device logging architecture and analysis
  4. Network evidence acquisition and analysis
  5. Threat hunting
    1. Intrusion detection
    2. Malware and indicators of compromise
    3. Reporting events to a security operations center
    4. Threat intelligence
    5. Applicable law and regulations
    6. Collecting evidence


Student Learning Outcomes
Describe network architecture, protocols, and infrastructure, and the role of network design principles in investigations.

Explain tactics, techniques, and procedures of security incidents.

Explain and demonstrate the use of network monitoring tools and where network based evidence can be found.

Effectively perform event and flow analysis.

Analyze intrusion detection system events to generate intelligence.

Configure a collector/analysis stack and analyze events to mirror the responsibilities of a security analyst.

Investigate, analyze, and report on security events through research and open-source intelligence.



Add to Portfolio (opens a new window)