Forensics
Files, memory, logs, packet captures, timelines, and evidence handling.
- 001 Evidence handling basics Learn Evidence handling basics through a safe, repeatable forensics workflow.
- 002 File metadata triage Learn File metadata triage through a safe, repeatable forensics workflow.
- 003 Timeline building Learn Timeline building through a safe, repeatable forensics workflow.
- 004 Log source inventory Learn Log source inventory through a safe, repeatable forensics workflow.
- 005 Packet capture triage Learn Packet capture triage through a safe, repeatable forensics workflow.
- 006 Memory image orientation Learn Memory image orientation through a safe, repeatable forensics workflow.
- 007 Browser artifact review Learn Browser artifact review through a safe, repeatable forensics workflow.
- 008 Email header analysis Learn Email header analysis through a safe, repeatable forensics workflow.
- 009 Hashing evidence files Learn Hashing evidence files through a safe, repeatable forensics workflow.
- 010 Writing a forensic summary Learn Writing a forensic summary through a safe, repeatable forensics workflow.
- 011 File carving basics Learn File carving basics through a safe, repeatable forensics workflow.
- 012 Magic bytes and file signatures Learn Magic bytes and file signatures through a safe, repeatable forensics workflow.
- 013 Exif metadata review Learn Exif metadata review through a safe, repeatable forensics workflow.
- 014 Steganography first pass Learn Steganography first pass through a safe, repeatable forensics workflow.
- 015 PNG chunk analysis Learn PNG chunk analysis through a safe, repeatable forensics workflow.
- 016 JPEG metadata and thumbnails Learn JPEG metadata and thumbnails through a safe, repeatable forensics workflow.
- 017 PDF object inspection Learn PDF object inspection through a safe, repeatable forensics workflow.
- 018 Office document macro triage Learn Office document macro triage through a safe, repeatable forensics workflow.
- 019 ZIP structure review Learn ZIP structure review through a safe, repeatable forensics workflow.
- 020 PCAP protocol filtering Learn PCAP protocol filtering through a safe, repeatable forensics workflow.
- 021 HTTP objects from PCAPs Learn HTTP objects from PCAPs through a safe, repeatable forensics workflow.
- 022 DNS tunneling indicators Learn DNS tunneling indicators through a safe, repeatable forensics workflow.
- 023 USB artifact basics Learn USB artifact basics through a safe, repeatable forensics workflow.
- 024 Windows event log timeline Learn Windows event log timeline through a safe, repeatable forensics workflow.
- 025 Linux auth log review Learn Linux auth log review through a safe, repeatable forensics workflow.
- 026 Browser history artifacts Learn Browser history artifacts through a safe, repeatable forensics workflow.
- 027 Memory strings triage Learn Memory strings triage through a safe, repeatable forensics workflow.
- 028 Volatility orientation Learn Volatility orientation through a safe, repeatable forensics workflow.
- 029 Registry hive basics Learn Registry hive basics through a safe, repeatable forensics workflow.
- 030 Disk image mounting workflow Learn Disk image mounting workflow through a safe, repeatable forensics workflow.
- 031 Chain of custody notes Learn Chain of custody notes through a safe, repeatable forensics workflow.
- 032 YARA rule reading Learn YARA rule reading through a safe, repeatable forensics workflow.