Lesson Plan (Grades 9-12): Digital Forensics Lab - Recovering Deleted Files, Metadata, and the Story Behind the Device
Engage grades 9-12 students in simulated digital forensics with metadata, timestamps, file traces, timelines, ethics, and evidence-based reporting.
Focus: Engage students in a safe, simulated digital forensics investigation where they analyze file traces, timestamps, metadata, storage records, and digital footprints to reconstruct what happened on a fictional device. Students work from teacher-created forensic evidence rather than real personal devices, evaluate the reliability of different clues, distinguish evidence from inference, and produce an evidence-based incident timeline or forensic case report.
Grade Level: 9-12
Subject Area: Computer Science • Cybersecurity • Data Analysis • Digital Citizenship/Ethics • Technical Writing
Total Unit Duration: 1 core lesson with 2 optional extension lessons
I. Introduction
Students enter a Digital Forensics Lab where a fictional device contains the pieces of an unfinished story. A file appears to have been deleted. Several documents have unusual timestamps. An image contains metadata. A folder history suggests that files were created, renamed, moved, or accessed in a particular sequence. Students must determine what the available evidence can—and cannot—prove.
The lesson introduces authentic digital-forensics reasoning without requiring students to access real devices, accounts, passwords, or private information. Students work only with teacher-created evidence, simulated forensic copies, exported metadata, and fictional user activity. The emphasis is not on “hacking” a device but on understanding how computers store information, how digital traces persist, and how investigators construct careful claims from incomplete evidence.
Essential Questions
- What kinds of digital traces can remain after people use a computing device?
- What can metadata reveal about a file?
- Why might deleting a file not immediately erase every trace of it?
- How can timestamps and file relationships help reconstruct a sequence of events?
- What is the difference between evidence, inference, and speculation?
- What ethical and privacy responsibilities come with digital forensic analysis?
II. Objectives and Standards
Learning Objectives — Students will be able to:
- Identify common types of digital evidence, including filenames, timestamps, file paths, metadata, logs, and simulated deleted-file traces.
- Organize multiple digital artifacts into a logical timeline.
- Analyze patterns across evidence sources to develop and test an explanation of what happened on a fictional device.
- Distinguish direct evidence from reasonable inference and unsupported speculation.
- Explain privacy, authorization, and ethical considerations involved in examining digital information.
- Present a forensic conclusion supported by specific evidence and clearly stated limitations.
Standards Alignment
- CSTA 3A-DA-10
- Evaluate trade-offs in how data elements are organized and where data are stored. (Computer Science Teachers Association)
- CSTA 3A-IC-29
- Explain privacy concerns related to the collection and generation of data through automated processes that may not be evident to users. (Computer Science Teachers Association)
- CSTA 3A-IC-30
- Evaluate the social and economic implications of privacy in the context of safety, law, or ethics. (Computer Science Teachers Association)
- CSTA 3B-DA-05
- Use data analysis tools and techniques to identify patterns in data representing complex systems. (Computer Science Teachers Association)
- CSTA 3B-NI-04
- Compare ways software developers protect devices and information from unauthorized access. (Computer Science Teachers Association)
- CCSS.ELA-LITERACY.RST.9-10.7 / RST.11-12.7
- Translate and integrate technical information presented in words, visual displays, tables, diagrams, or other formats.
- CCSS.ELA-LITERACY.WHST.9-10.1 / WHST.11-12.1
- Write arguments focused on discipline-specific content using valid reasoning and relevant and sufficient evidence.
- CCSS.ELA-LITERACY.SL.9-10.4 / SL.11-12.4
- Present information, findings, and supporting evidence clearly, concisely, and logically.
Success Criteria — Student Language
- I can identify useful digital evidence in a simulated forensic case.
- I can interpret timestamps, metadata, file locations, and other digital traces.
- I can construct a timeline supported by multiple pieces of evidence.
- I can separate what the evidence proves from what I am only inferring.
- I can explain why authorization and privacy matter in digital forensics.
- I can defend my conclusion while acknowledging uncertainty.