HPPSC Syllabus 2026 – Scientific Officer
HPPSC has released the Scientific Officer syllabus. Check the complete details below, including Unit-Wise Topics and Exam Pattern, important dates, and official links.
HPPSC Scientific Officer 2026 – Overview
| Organization | HPPSC |
| Post Name | Scientific Officier |
| Qualification | Any Graduate |
| Location | Shimla, Himachal Pradesh |
| Official Website | hppsc.hp.gov.in |
Eligibility Criteria
Candidates applying for the HPPSC Scientific Officer syllabus must have the following educational qualification:
- Any Graduate.
Candidates must check the official notification for detailed eligibility requirements.
Important Links
| Official Notification | Download PDF |
| Official Website | hppsc.hp.gov.in |
SYLLABUS FOR DESCRIPTIVE SUBJECT APTITUDE TEST (SAT) FOR
RECRUITMENT TO THE POST OF SCIENTIFIC OFFICER (DIGITAL
FORENSIC), GROUP-B IN THE DIRECTORATE OF FORENSIC SERVICES,
HOME DEPARTMENT, H.P. THIS PAPER SHALL BE OF THREE HOURS’
DURATION HAVING 120 MARKS. THE SAT PAPER SHALL CONSIST OF TWO
PARTS I.E. PART-I AND PART-II AND WILL COVER THE FOLLOWING TOPICS.
Duration: 3 Hours Max. Marks 120
Part-I (60 Marks)
Unit I (Foundations of Forensic Science and Evidence)
Definition, nature, scope, history and development of forensic science in India and abroad;
organisation and functions of State Forensic Science Laboratories, Central Forensic Science
Laboratories, Directorate of Forensic Science Services, National Crime Records Bureau and
relevant national and international agencies.
Principles of forensic science, including Locard’s Exchange Principle, natural variation,
comparison, probability, individualisation and continuous change; Sydney Declaration and its
principles; types of evidence, with emphasis on physical, trace, electronic and digital
evidence; duties and responsibilities of forensic experts; Frye Standard and Daubert Standard;
scientific validity, reliability, limitations and interpretation of forensic findings.
Common principles of scene security, documentation, photography, videography, search,
identification, collection, packaging, sealing, preservation, forwarding and continuity of
possession. Overview of the interaction between digital evidence and other evidence at a
crime scene. Detailed bloodstain-pattern analysis, accident reconstruction, glass, soil, paint,
ballistics and instrumental chemical analysis are excluded.
Unit II (Law Relating to Digital Evidence)
Bharatiya Sakshya Adhiniyam, 2023; Bharatiya Nagarik Suraksha Sanhita, 2023; Bharatiya
Nyaya Sanhita, 2023; Information Technology Act, 2000, as amended; Information
Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as
amended; directions issued by CERT-In under section 70B of the Information Technology
Act; Digital Personal Data Protection Act, 2023 and the rules made thereunder, to the extent
in force and relevant to digital investigation.
Relevant legal provisions governing identification, search, seizure, preservation, production,
certification, proof, admissibility and appreciation of electronic and digital records; primary
and secondary electronic evidence; integrity and authenticity; hash values; chain of custody;
expert opinion; examination-in-chief, cross-examination and re-examination; lawful access,
privacy, proportionality, confidentiality and handling of personal data during investigation.
Central legislation and nationally applicable rules and directions shall form the principal legal
syllabus. Himachal Pradesh-specific rules, standing orders, notifications and procedures may
be examined only where they directly govern the functioning of the State Forensic Science
Lab or the handling of digital evidence within the State.
Unit III (Quality Assurance Ethics Reporting and Lab Administration)
Quality management systems applicable to forensic laboratories: ISO/IEC 17025:2017 and
relevant parts of ISO 21043; accreditation, document control, competence, method selection,
verification and validation, measurement uncertainty where applicable, calibration,
proficiency testing, blind testing, inter-Lab and intra-Lab comparison, internal audit,
corrective action, risk management and continual improvement.
Lab Information Management Systems; access control, data protection, audit trails,
traceability, evidence storage, retention, disposal and transparency of Lab operations.
Preparation, technical review and authorisation of digital-forensic examination reports;
expression of findings, limitations and uncertainty; scene-of-crime and Lab reports; expert
testimony.
Ethics in forensic science and digital investigation; impartiality, independence,
confidentiality, conflict of interest, competence and responsible use of forensic tools. Lab
leadership, case allocation, workload and turnaround-time management, validation and
change control for tools, procurement and maintenance of equipment, competence
management, supervision, health and safety, and inter-agency coordination. Fundamentals of
research design, sampling, statistical interpretation, literature review, plagiarism and scientific
writing; detailed citation indices and impact factors are excluded.
Unit IV (Digital Evidence Foundations: Acquisition and Preservation)
Definition, scope and importance of digital forensics; digital-evidence lifecycle; sources and
characteristics of digital evidence; order of volatility; forensic readiness; incident triage; live
and dead-box acquisition; legal authority and documentation before acquisition.
Computer architecture and storage fundamentals relevant to examination: memory hierarchy,
volatile and non-volatile memory, HDD and SSD architecture, sectors, clusters, partitions,
volumes, GUID Partition Table, Master Boot Record, storage interfaces, wear levelling,
TRIM, RAID and encrypted storage. Detailed CD/DVD writing architecture and applicationspecific internal buffers are excluded.
Digital storage acquisition and imaging; physical, logical and sparse acquisition; RAW/DD,
E01 and AFF formats; write blockers; cloning; imaging; verification; wiping; acquisition logs
and chain of custody. Cryptographic hashing and integrity verification: SHA-256 as a member
of SHA-2, SHA-3 and HMAC. MD5 and SHA-1 shall be treated as legacy algorithms with
known collision weaknesses and shall not be relied upon alone for new integrity assurance;
their evidential use, if encountered, should be corroborated with a collision-resistant hash.
Unit V (Operating Systems File Systems and Memory Forensics)
Forensically relevant features of Windows, GNU/Linux, UNIX and macOS; boot process,
user accounts, permissions, timestamps, time zones and clock drift. FAT, exFAT, NTFS, ext family, APFS and other commonly encountered file systems; allocation, metadata, journalling, slack space, unallocated space, deleted and hidden data, alternate data streams, symbolic links and file-system artefacts.
Windows Registry, event logs, prefetch, link files, jump lists, recycle bin, browser and
application artefacts; Linux and macOS logs and persistence artefacts; timeline analysis,
metadata analysis, file signatures, file and data carving, recovery of deleted data, anti-forensic
techniques and countermeasures.
Volatile-memory acquisition and analysis; processes, threads, loaded modules, network
connections, command history, credentials and encryption keys in memory; page files, swap
and hibernation files; identification of code injection, rootkits and other malicious activity in
memory. BitLocker and other full-disk or file-level encryption systems; lawful acquisition
and recovery considerations.
Unit VI (Mobile IoT Embedded and Video-System Forensics)
Mobile-device architecture; Android and iOS security models and artefacts; SIM, USIM,
eSIM and removable-media evidence. Manual, logical, file-system and physical acquisition;
backup and cloud-synchronised artefacts; call logs, messages, contacts, email, application
data, browser data, media, notifications and location artefacts; locked and damaged devices;
mobile malware; JTAG, ISP and chip-off techniques; limitations and validation of mobileforensic tools.
IoT and embedded systems: device architecture, firmware, flash storage, sensors, wearables,
smart devices, network and cloud dependencies, acquisition and correlation of device,
gateway and cloud artefacts. Fundamentals of microprocessors, memory devices, interfaces
and firmware only to the extent necessary for digital acquisition and interpretation; detailed
Boolean algebra, K-maps and circuit-design exercises are excluded.
DVR, NVR and CCTV architecture; proprietary formats, export, playback, timestamps,
transcoding and integrity; recovery and analysis of video-system evidence. CDR and IPDR
fundamentals and correlation with device, location and network evidence, subject to lawful
authorisation and stated limitations.
Part II (60 Marks)
Unit VII (Network Web and Communication Forensics)
TCP/IP and OSI concepts relevant to forensic analysis; IPv4 and IPv6 addressing, ports,
routing, DNS, DHCP, NAT, VPNs, proxies and common application protocols. Packet
capture, flow records, firewall, router, VPN, proxy, DNS, authentication, endpoint and
intrusion-detection logs; session reconstruction, timestamp correlation, attribution limitations
and encrypted traffic analysis.
Email forensics: headers, message identifiers, routing, authentication results, attachments,
webmail and server artefacts; phishing and spoofing investigation. Web and browser
forensics: history, cache, cookies, local storage, downloads, credentials, sessions and web-
server/application logs. Dark web and anonymisation technologies at an overview level;
lawful collection and operational-security considerations.
Network intrusion and cyber-incident investigation; lateral movement, persistence,
exfiltration and command-and-control indicators; IoT and industrial/SCADA network
evidence at an introductory level. Preservation and interpretation of logs in accordance with
applicable CERT-In directions.
Unit VIII (Cloud Virtualisation and Database Forensics)
Virtual machines and hypervisors; virtual-disk, snapshot, memory and configuration artefacts;
acquisition of powered-on and powered-off virtual machines; virtual networking; use of
isolated virtual environments in forensic examination.
Cloud service and deployment models; multi-tenancy, shared responsibility and jurisdiction;
identification, preservation and collection of evidence from SaaS, PaaS and IaaS
environments; cloud storage, audit logs, identity and access records, API records, object
versions and provider-generated evidence; legal process, preservation requests, serviceprovider liaison and limitations of cloud acquisition.
Database and application forensics: relational and NoSQL concepts, transaction and audit
logs, deleted records, access histories, application logs and correlation across endpoints,
servers and cloud services.
Unit IX (Malware Cyber Threats and Incident Response)
Malware types and behaviour, including viruses, worms, trojans, ransomware, spyware,
botnets and fileless malware; phishing, social engineering, credential theft, identity theft,
unauthorised access, cyberstalking, online impersonation, financial fraud, website
compromise and cyber terrorism.
Static and dynamic malware-analysis fundamentals; executable structure, strings, hashes,
packers, persistence, process and network behaviour, sandboxing, indicators of compromise
and safe handling. Basics of reverse engineering sufficient to interpret forensic findings; antianalysis and evasion techniques.
Incident-response lifecycle; preparation, identification, containment, eradication, recovery and
lessons learned; forensic acquisition during incident response; preservation of volatile
evidence; log and timeline correlation; documentation, reporting and coordination with
CERT-In, law-enforcement agencies, service providers and affected organisations.
Unit X (Multimedia Artificial Intelligence and Synthetic Media Forensics)
Image, audio and video formats, metadata, compression and acquisition; authentication and
integrity examination; common forms of manipulation, including splicing, copy-move, frame
insertion or deletion, re-encoding, voice alteration and metadata tampering; limitations of
enhancement and the requirement to preserve the original evidence.
Artificial intelligence and machine learning concepts relevant to digital forensics: data
preparation, feature extraction, supervised and unsupervised learning, anomaly detection,
model evaluation using accuracy, precision, recall and F1-score. Applications to image, video,
audio, text and multimodal forensic analysis.
Synthetic and AI-generated content, deepfakes and emerging manipulation techniques;
provenance, detection, model and dataset limitations, false positives, explainability, validation
and responsible reporting. AI-assisted triage shall not replace examiner verification or
validated forensic procedure.
Unit XI (Cryptography Blockchain and Cryptocurrency Forensics)
Cryptographic objectives and systems; symmetric and asymmetric cryptography; AES and
modes of operation; legacy DES and RC4; RSA, Diffie-Hellman, digital signatures, ellipticcurve cryptography, key management, public-key infrastructure and digital certificates.
Password storage, salting, key derivation, password recovery and lawful decryption; forensic
implications of encryption and secure deletion.
Blockchain fundamentals; public and private networks, blocks, transactions, addresses,
wallets, keys, consensus and smart contracts. Cryptocurrency evidence: Bitcoin and
representative blockchain ecosystems; custodial and non-custodial wallets; transaction
tracing, address attribution limitations, exchange records, seed phrases, hardware wallets,
seizure and preservation of digital assets; common fraud, laundering and obfuscation
techniques.
Unit XII (Forensic Analysis Tools Case Management and Expert Reporting)
Preparation and security of forensic workstations; trusted toolsets, access control, patch and
configuration management, time synchronisation, network isolation and evidence storage.
Selection and use of commercial and open-source tools for acquisition, authentication,
indexing, search, recovery, carving, timeline generation and artefact analysis; tool testing,
validation, verification, known-error documentation, repeatability and independent
corroboration.
Application of ISO/IEC 27037, ISO/IEC 27041, ISO/IEC 27042 and ISO/IEC 27043 to
identification, collection, acquisition, preservation, method suitability, analysis and incident
investigation. Case strategy, examination planning, triage, prioritisation, peer review,
interpretation of conflicting artefacts and reconstruction of events across devices, networks,
cloud services and communication records.
Preparation of clear, reproducible and legally defensible forensic reports; statement of
authority, items received, condition and seals, methods and tools, hash values, observations,
results, limitations, conclusions, exhibits and chain of custody. Presentation of technical
findings to investigating officers, courts and non-technical decision-makers; expert testimony
and defence of methods under examination and cross-examination.


