Instructional video coming soon
This reserved space will contain the narrated overview for Policy Family VII. The written policy below remains the controlling text.
Purpose
Courses involving cybersecurity, digital forensics, OSINT, darknet research, surveillance technology, networks, malware, data, cryptography, fraud, or investigative methods require strict boundaries for lawful, ethical, authorized, and safe work.
Course discussion of law, legal requirements, cases, regulations, or hypothetical situations is educational and remains subject to the Legal Information, Not Legal Advice policy in Section I.
Authorization Is Required
Students may conduct technical activity only when authorized by the assignment, approved lab environment, written instructions, or the explicit permission of the owner or operator of the system, account, network, service, dataset, or device involved. Educational interest is not authorization.
Prohibited Activity
Students may not engage in unauthorized access, credential misuse, scanning, exploitation, interception, exfiltration, harassment, doxxing, evasion, circumvention, malware deployment, disruptive testing, or conduct that violates law, College policy, terms of service, or ethical research standards.
Interception and Traffic Capture
Professor Wandt will not authorize interception of live third-party traffic. Packet capture, interception demonstrations, and network-monitoring exercises must remain within approved lab networks, personally controlled systems, synthetic traffic, or another expressly authorized environment.
Controlled Lab Work
Hands-on work must be performed only in the approved environment. Students must isolate experiments, avoid affecting third parties, avoid collecting unnecessary personal data, and stop immediately if unexpected real-world systems, data, or people are implicated.
OSINT, Darknet, and Sensitive Research
Research involving OSINT, darknet markets, social-media investigation, surveillance tools, leaked data, cryptocurrency tracing, extremist content, criminal communities, or vulnerable populations must remain within assignment boundaries and comply with safety instructions, privacy rules, applicable law, and ethical requirements.
Students may not contact targets, purchase contraband, solicit unlawful services, transact with illicit actors, deceive a person, or escalate beyond authorized passive observation unless a lawful and ethically approved protocol expressly permits the conduct.
Malware and Dual-Use Tools
Students may not run malware, exploit code, credential-harvesting tools, phishing infrastructure, or other dual-use capabilities outside a controlled and authorized environment. Possession, transfer, and use must remain limited to legitimate educational purposes and course-approved settings.
Reporting and Stop-Work Duty
A student who encounters suspected unlawful, unsafe, unauthorized, or unexpectedly sensitive activity connected to course work must stop the affected activity, preserve information safely, and promptly notify Professor Wandt or the designated course contact. Immediate threats should be reported first to emergency, public-safety, legal, or institutional authorities as appropriate.
Consequences
Unsafe or unauthorized technical activity may result in a stop-work direction, loss of lab privileges, assignment or course consequences, removal from a course or program where permitted, and referral to College, law-enforcement, or other appropriate authorities.