Mission Bharti Logo Mission BhartiGovt Job Alerts
Home » Online Bharti » HPPSC Scientific Officier Syllabus 2026 - Download Unit-Wise Topics and Exam Pattern at hppsc.hp.gov.in
Last Updated:

HPPSC Scientific Officier Syllabus 2026 - Download Unit-Wise Topics and Exam Pattern at hppsc.hp.gov.in

The Himachal Pradesh Public Service Commission (HPPSC) has released the syllabus for the Descriptive Subject Aptitude Test (SAT) for the post of Scientific Officer (Digital Forensic), Group-B, in the Directorate of Forensic Services, Home Department, Himachal Pradesh. The paper is of 120 marks and 3 hours, and it covers 12 units split across two parts. This page explains the full HPPSC Scientific Officer syllabus, the exam pattern, the topics that are excluded and the details that the syllabus document does not mention.

HPPSC Scientific Officer Syllabus 2026 - Quick Overview

Particulars Details
Organisation Himachal Pradesh Public Service Commission (HPPSC)
Post Name Scientific Officer (Digital Forensic), Group-B
Department Directorate of Forensic Services, Home Department, Himachal Pradesh
Test Name Descriptive Subject Aptitude Test (SAT)
Duration 3 Hours
Maximum Marks 120
Number of Parts 2 (Part-I and Part-II)
Marks in Each Part 60 marks each
Total Units 12 (Unit I to Unit XII)
Official Website hppsc.hp.gov.in

HPPSC Scientific Officer Digital Forensic Exam Pattern

The syllabus describes the test as a descriptive paper. The pattern given in the document is below.

Advertisement
Part Marks Units Covered Broad Area
Part-I 60 Unit I to Unit VI Forensic foundations, digital evidence law, quality and lab administration, acquisition, operating systems and memory, mobile, IoT and video systems
Part-II 60 Unit VII to Unit XII Network and web, cloud and database, malware and incident response, multimedia and AI, cryptography and blockchain, tools and expert reporting
Total 120 12 Units Duration: 3 Hours

Unit-Wise Syllabus for HPPSC Scientific Officer (Digital Forensic)

Unit Title Part
Unit I Foundations of Forensic Science and Evidence Part-I
Unit II Law Relating to Digital Evidence Part-I
Unit III Quality Assurance, Ethics, Reporting and Lab Administration Part-I
Unit IV Digital Evidence Foundations: Acquisition and Preservation Part-I
Unit V Operating Systems, File Systems and Memory Forensics Part-I
Unit VI Mobile, IoT, Embedded and Video-System Forensics Part-I
Unit VII Network, Web and Communication Forensics Part-II
Unit VIII Cloud, Virtualisation and Database Forensics Part-II
Unit IX Malware, Cyber Threats and Incident Response Part-II
Unit X Multimedia, Artificial Intelligence and Synthetic Media Forensics Part-II
Unit XI Cryptography, Blockchain and Cryptocurrency Forensics Part-II
Unit XII Forensic Analysis Tools, Case Management and Expert Reporting Part-II

Part-I Syllabus (60 Marks)

Unit I: Foundations of Forensic Science and Evidence

  • Definition, nature, scope, history and development of forensic science in India and abroad
  • Organisation and functions of State Forensic Science Laboratories, Central Forensic Science Laboratories, Directorate of Forensic Science Services, National Crime Records Bureau and related national and international agencies
  • Principles of forensic science: Locard's Exchange Principle, natural variation, comparison, probability, individualisation and continuous change
  • Sydney Declaration and its principles
  • Types of evidence, with emphasis on physical, trace, electronic and digital evidence
  • Duties and responsibilities of forensic experts
  • Frye Standard and Daubert Standard; scientific validity, reliability, limitations and interpretation of forensic findings
  • Scene security, documentation, photography, videography, search, identification, collection, packaging, sealing, preservation, forwarding and continuity of possession
  • Overview of the interaction between digital evidence and other evidence at a crime scene

Excluded: detailed bloodstain-pattern analysis, accident reconstruction, glass, soil, paint, ballistics and instrumental chemical analysis.

Advertisement

Unit II: Law Relating to Digital Evidence

  • Bharatiya Sakshya Adhiniyam, 2023
  • Bharatiya Nagarik Suraksha Sanhita, 2023
  • Bharatiya Nyaya Sanhita, 2023
  • Information Technology Act, 2000, as amended
  • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended
  • CERT-In directions under section 70B of the IT Act
  • Digital Personal Data Protection Act, 2023 and its rules, to the extent in force and relevant to digital investigation
  • Legal provisions on identification, search, seizure, preservation, production, certification, proof, admissibility and appreciation of electronic and digital records
  • Primary and secondary electronic evidence, integrity and authenticity, hash values, chain of custody
  • Expert opinion; examination-in-chief, cross-examination and re-examination
  • Lawful access, privacy, proportionality, confidentiality and handling of personal data during investigation

Central legislation and nationally applicable rules and directions form the principal legal syllabus. Himachal Pradesh-specific rules, standing orders, notifications and procedures can be asked only where they directly govern the functioning of the State Forensic Science Lab or the handling of digital evidence within the State.

Unit III: Quality Assurance, Ethics, Reporting and Lab Administration

  • Quality management in forensic labs: ISO/IEC 17025:2017 and relevant parts of ISO 21043
  • Accreditation, document control, competence, method selection, verification and validation, measurement uncertainty where applicable, calibration
  • Proficiency testing, blind testing, inter-lab and intra-lab comparison, internal audit, corrective action, risk management and continual improvement
  • Laboratory Information Management Systems (LIMS): access control, data protection, audit trails, traceability, evidence storage, retention, disposal and transparency
  • Preparation, technical review and authorisation of digital-forensic examination reports; expression of findings, limitations and uncertainty; scene-of-crime and lab reports; expert testimony
  • Ethics: impartiality, independence, confidentiality, conflict of interest, competence and responsible use of forensic tools
  • Lab leadership, case allocation, workload and turnaround-time management, validation and change control for tools, procurement and maintenance of equipment, competence management, supervision, health and safety, inter-agency coordination
  • Research design, sampling, statistical interpretation, literature review, plagiarism and scientific writing

Excluded: detailed citation indices and impact factors.

Unit IV: Digital Evidence Foundations: Acquisition and Preservation

  • Definition, scope and importance of digital forensics; digital-evidence lifecycle; sources and characteristics of digital evidence
  • Order of volatility, forensic readiness, incident triage, live and dead-box acquisition, legal authority and documentation before acquisition
  • Storage fundamentals: memory hierarchy, volatile and non-volatile memory, HDD and SSD architecture, sectors, clusters, partitions, volumes, GUID Partition Table, Master Boot Record, storage interfaces, wear levelling, TRIM, RAID and encrypted storage
  • Acquisition and imaging: physical, logical and sparse acquisition; RAW/DD, E01 and AFF formats; write blockers; cloning; imaging; verification; wiping; acquisition logs and chain of custody
  • Hashing and integrity: SHA-256 as part of SHA-2, SHA-3 and HMAC
  • MD5 and SHA-1 are treated as legacy algorithms with known collision weaknesses and should not be relied upon alone for new integrity assurance

Excluded: detailed CD/DVD writing architecture and application-specific internal buffers.

Unit V: Operating Systems, File Systems and Memory Forensics

  • Forensically relevant features of Windows, GNU/Linux, UNIX and macOS: boot process, user accounts, permissions, timestamps, time zones and clock drift
  • File systems: FAT, exFAT, NTFS, ext family, APFS and other common systems; allocation, metadata, journalling, slack space, unallocated space, deleted and hidden data, alternate data streams, symbolic links
  • Windows artefacts: Registry, event logs, prefetch, link files, jump lists, recycle bin, browser and application artefacts
  • Linux and macOS logs and persistence artefacts
  • Timeline analysis, metadata analysis, file signatures, file and data carving, recovery of deleted data, anti-forensic techniques and countermeasures
  • Volatile-memory acquisition and analysis: processes, threads, loaded modules, network connections, command history, credentials and encryption keys in memory
  • Page files, swap and hibernation files; code injection, rootkits and other malicious activity in memory
  • BitLocker and other full-disk or file-level encryption; lawful acquisition and recovery considerations

Unit VI: Mobile, IoT, Embedded and Video-System Forensics

  • Mobile-device architecture; Android and iOS security models and artefacts; SIM, USIM, eSIM and removable-media evidence
  • Manual, logical, file-system and physical acquisition; backup and cloud-synchronised artefacts
  • Call logs, messages, contacts, email, application data, browser data, media, notifications and location artefacts
  • Locked and damaged devices, mobile malware, JTAG, ISP and chip-off techniques, limitations and validation of mobile-forensic tools
  • IoT and embedded systems: device architecture, firmware, flash storage, sensors, wearables, smart devices, network and cloud dependencies, correlation of device, gateway and cloud artefacts
  • Microprocessors, memory devices, interfaces and firmware only to the extent needed for digital acquisition and interpretation
  • DVR, NVR and CCTV architecture; proprietary formats, export, playback, timestamps, transcoding and integrity; recovery and analysis of video-system evidence
  • CDR and IPDR fundamentals and their correlation with device, location and network evidence, subject to lawful authorisation and stated limitations

Excluded: detailed Boolean algebra, K-maps and circuit-design exercises.

Part-II Syllabus (60 Marks)

Unit VII: Network, Web and Communication Forensics

  • TCP/IP and OSI concepts; IPv4 and IPv6 addressing, ports, routing, DNS, DHCP, NAT, VPNs, proxies and common application protocols
  • Packet capture, flow records, firewall, router, VPN, proxy, DNS, authentication, endpoint and intrusion-detection logs
  • Session reconstruction, timestamp correlation, attribution limitations and encrypted traffic analysis
  • Email forensics: headers, message identifiers, routing, authentication results, attachments, webmail and server artefacts, phishing and spoofing investigation
  • Web and browser forensics: history, cache, cookies, local storage, downloads, credentials, sessions, web-server and application logs
  • Dark web and anonymisation technologies at an overview level; lawful collection and operational-security considerations
  • Network intrusion and cyber-incident investigation: lateral movement, persistence, exfiltration and command-and-control indicators
  • IoT and industrial/SCADA network evidence at an introductory level
  • Preservation and interpretation of logs as per applicable CERT-In directions

Unit VIII: Cloud, Virtualisation and Database Forensics

  • Virtual machines and hypervisors; virtual-disk, snapshot, memory and configuration artefacts
  • Acquisition of powered-on and powered-off virtual machines; virtual networking; isolated virtual environments for examination
  • Cloud service and deployment models; multi-tenancy, shared responsibility and jurisdiction
  • Evidence from SaaS, PaaS and IaaS: cloud storage, audit logs, identity and access records, API records, object versions and provider-generated evidence
  • Legal process, preservation requests, service-provider liaison and limitations of cloud acquisition
  • Database and application forensics: relational and NoSQL concepts, transaction and audit logs, deleted records, access histories, application logs, and correlation across endpoints, servers and cloud services

Unit IX: Malware, Cyber Threats and Incident Response

  • Malware types and behaviour: viruses, worms, trojans, ransomware, spyware, botnets and fileless malware
  • Cyber threats and crimes: phishing, social engineering, credential theft, identity theft, unauthorised access, cyberstalking, online impersonation, financial fraud, website compromise and cyber terrorism
  • Static and dynamic malware analysis: executable structure, strings, hashes, packers, persistence, process and network behaviour, sandboxing, indicators of compromise and safe handling
  • Basics of reverse engineering sufficient to interpret forensic findings; anti-analysis and evasion techniques
  • Incident-response lifecycle: preparation, identification, containment, eradication, recovery and lessons learned
  • Forensic acquisition during incident response, preservation of volatile evidence, log and timeline correlation, documentation, reporting and coordination with CERT-In, law-enforcement agencies, service providers and affected organisations

Unit X: Multimedia, Artificial Intelligence and Synthetic Media Forensics

  • Image, audio and video formats, metadata, compression and acquisition; authentication and integrity examination
  • Common manipulation: splicing, copy-move, frame insertion or deletion, re-encoding, voice alteration and metadata tampering
  • Limitations of enhancement and the need to preserve the original evidence
  • AI and machine learning concepts for digital forensics: data preparation, feature extraction, supervised and unsupervised learning, anomaly detection
  • Model evaluation using accuracy, precision, recall and F1-score
  • Applications to image, video, audio, text and multimodal analysis
  • Synthetic and AI-generated content, deepfakes and emerging manipulation techniques: provenance, detection, model and dataset limitations, false positives, explainability, validation and responsible reporting
  • AI-assisted triage must not replace examiner verification or validated forensic procedure

Unit XI: Cryptography, Blockchain and Cryptocurrency Forensics

  • Cryptographic objectives and systems; symmetric and asymmetric cryptography
  • AES and modes of operation; legacy DES and RC4; RSA, Diffie-Hellman, digital signatures, elliptic-curve cryptography
  • Key management, public-key infrastructure and digital certificates
  • Password storage, salting, key derivation, password recovery and lawful decryption; forensic implications of encryption and secure deletion
  • Blockchain fundamentals: public and private networks, blocks, transactions, addresses, wallets, keys, consensus and smart contracts
  • Cryptocurrency evidence: Bitcoin and representative blockchain ecosystems, custodial and non-custodial wallets, transaction tracing, address attribution limitations, exchange records, seed phrases, hardware wallets
  • Seizure and preservation of digital assets; common fraud, laundering and obfuscation techniques

Unit XII: Forensic Analysis Tools, Case Management and Expert Reporting

  • Forensic workstation preparation and security: trusted toolsets, access control, patch and configuration management, time synchronisation, network isolation and evidence storage
  • Commercial and open-source tools for acquisition, authentication, indexing, search, recovery, carving, timeline generation and artefact analysis
  • Tool testing, validation, verification, known-error documentation, repeatability and independent corroboration
  • ISO/IEC 27037, ISO/IEC 27041, ISO/IEC 27042 and ISO/IEC 27043
  • Case strategy, examination planning, triage, prioritisation, peer review, interpretation of conflicting artefacts and reconstruction of events across devices, networks, cloud services and communication records
  • Clear, reproducible and legally defensible reports: statement of authority, items received, condition and seals, methods and tools, hash values, observations, results, limitations, conclusions, exhibits and chain of custody
  • Presenting findings to investigating officers, courts and non-technical decision-makers; expert testimony and defence of methods under cross-examination

Topics Excluded from the HPPSC Scientific Officer Syllabus

The syllabus names the following topics as excluded.

Unit Excluded Topics
Unit I Detailed bloodstain-pattern analysis, accident reconstruction, glass, soil, paint, ballistics and instrumental chemical analysis
Unit III Detailed citation indices and impact factors
Unit IV Detailed CD/DVD writing architecture and application-specific internal buffers
Unit VI Detailed Boolean algebra, K-maps and circuit-design exercises

Important Points to Note in the Syllabus

  • The test is descriptive, so answers need to be explained, not just recalled.
  • Law questions mainly come from central legislation and nationally applicable rules. Himachal Pradesh-specific rules matter only where they directly govern the State Forensic Science Lab or handling of digital evidence in the State.
  • MD5 and SHA-1 are to be treated as legacy hash algorithms. SHA-256 (SHA-2), SHA-3 and HMAC are the main hashing topics.
  • The new criminal laws (BSA 2023, BNSS 2023 and BNS 2023) are listed by name, so study the digital-evidence provisions under these laws.
  • Several units use limiting phrases such as "overview level", "introductory level" and "only to the extent necessary". Study these topics for understanding, not for deep technical depth.
  • AI-assisted triage cannot replace examiner verification or validated forensic procedure.

How to Prepare for the HPPSC Scientific Officer Digital Forensic Exam

The syllabus does not give a preparation plan. The following approach is based only on its structure.

  1. Divide your time by the two parts: Part-I (Units I to VI) and Part-II (Units VII to XII) carry 60 marks each.
  2. Start with Unit II and Unit IV, as legal provisions, hash values and chain of custody connect to many other units.
  3. Practise writing structured answers, since the paper is descriptive and has a 3-hour limit.
  4. Learn the named standards properly: ISO/IEC 17025:2017, ISO 21043, ISO/IEC 27037, 27041, 27042 and 27043.
  5. Revise artefact lists (Windows, mobile, browser, email, cloud) in tabular notes, as they are repeated across units.
  6. Skip the excluded topics so that time is not wasted.

Frequently Asked Questions

What is the exam pattern for HPPSC Scientific Officer (Digital Forensic)?

The Descriptive Subject Aptitude Test (SAT) is a 3-hour paper of 120 marks. It has two parts of 60 marks each: Part-I covers Units I to VI and Part-II covers Units VII to XII.

How many units are there in the HPPSC Scientific Officer syllabus?

There are 12 units, from Unit I (Foundations of Forensic Science and Evidence) to Unit XII (Forensic Analysis Tools, Case Management and Expert Reporting).

Is the HPPSC Scientific Officer (Digital Forensic) paper objective or descriptive?

The syllabus calls it a Descriptive Subject Aptitude Test. The number of questions and the marking scheme per question are not given in the syllabus.

Which laws are included in the syllabus?

Bharatiya Sakshya Adhiniyam 2023, Bharatiya Nagarik Suraksha Sanhita 2023, Bharatiya Nyaya Sanhita 2023, the Information Technology Act 2000, the IT Intermediary Guidelines and Digital Media Ethics Code Rules 2021, CERT-In directions under section 70B and the Digital Personal Data Protection Act 2023 are listed.

Is AI and deepfake detection included in the syllabus?

Yes. Unit X covers AI and machine learning concepts, model evaluation (accuracy, precision, recall and F1-score), deepfakes, synthetic media and their detection limitations.