Lesson Plan (Grades 9-12): Digital Forensics Lab - Recovering Deleted Files, Metadata, and the Story Behind the Device

Engage grades 9-12 students in simulated digital forensics with metadata, timestamps, file traces, timelines, ethics, and evidence-based reporting.

Lesson Plan (Grades 9-12): Digital Forensics Lab - Recovering Deleted Files, Metadata, and the Story Behind the Device

Focus: Engage students in a safe, simulated digital forensics investigation where they analyze file traces, timestamps, metadata, storage records, and digital footprints to reconstruct what happened on a fictional device. Students work from teacher-created forensic evidence rather than real personal devices, evaluate the reliability of different clues, distinguish evidence from inference, and produce an evidence-based incident timeline or forensic case report.

Grade Level: 9-12

Subject Area: Computer Science • Cybersecurity • Data Analysis • Digital Citizenship/Ethics • Technical Writing

Total Unit Duration: 1 core lesson with 2 optional extension lessons


I. Introduction

Students enter a Digital Forensics Lab where a fictional device contains the pieces of an unfinished story. A file appears to have been deleted. Several documents have unusual timestamps. An image contains metadata. A folder history suggests that files were created, renamed, moved, or accessed in a particular sequence. Students must determine what the available evidence can—and cannot—prove.

The lesson introduces authentic digital-forensics reasoning without requiring students to access real devices, accounts, passwords, or private information. Students work only with teacher-created evidence, simulated forensic copies, exported metadata, and fictional user activity. The emphasis is not on “hacking” a device but on understanding how computers store information, how digital traces persist, and how investigators construct careful claims from incomplete evidence.

Essential Questions

  • What kinds of digital traces can remain after people use a computing device?
  • What can metadata reveal about a file?
  • Why might deleting a file not immediately erase every trace of it?
  • How can timestamps and file relationships help reconstruct a sequence of events?
  • What is the difference between evidence, inference, and speculation?
  • What ethical and privacy responsibilities come with digital forensic analysis?

II. Objectives and Standards

Learning Objectives — Students will be able to:

  1. Identify common types of digital evidence, including filenames, timestamps, file paths, metadata, logs, and simulated deleted-file traces.
  2. Organize multiple digital artifacts into a logical timeline.
  3. Analyze patterns across evidence sources to develop and test an explanation of what happened on a fictional device.
  4. Distinguish direct evidence from reasonable inference and unsupported speculation.
  5. Explain privacy, authorization, and ethical considerations involved in examining digital information.
  6. Present a forensic conclusion supported by specific evidence and clearly stated limitations.

Standards Alignment

  • CSTA 3A-DA-10
  • CSTA 3A-IC-29
  • CSTA 3A-IC-30
  • CSTA 3B-DA-05
  • CSTA 3B-NI-04
  • CCSS.ELA-LITERACY.RST.9-10.7 / RST.11-12.7
    • Translate and integrate technical information presented in words, visual displays, tables, diagrams, or other formats.
  • CCSS.ELA-LITERACY.WHST.9-10.1 / WHST.11-12.1
    • Write arguments focused on discipline-specific content using valid reasoning and relevant and sufficient evidence.
  • CCSS.ELA-LITERACY.SL.9-10.4 / SL.11-12.4
    • Present information, findings, and supporting evidence clearly, concisely, and logically.

Success Criteria — Student Language

  • I can identify useful digital evidence in a simulated forensic case.
  • I can interpret timestamps, metadata, file locations, and other digital traces.
  • I can construct a timeline supported by multiple pieces of evidence.
  • I can separate what the evidence proves from what I am only inferring.
  • I can explain why authorization and privacy matter in digital forensics.
  • I can defend my conclusion while acknowledging uncertainty.