Eight chapters from legal process and chain of custody through disk imaging, Windows artifacts, memory forensics, timeline analysis, network forensics, mobile and cloud evidence, and closing with anti-forensics detection and forensic report writing. Built for analysts who need evidence-grade collection and analysis skills beyond SOC-scoped triage and incident-lifecycle ownership.
No chapters match “”.
The branches of digital forensics, the legal and ethical framework for evidence collection, the order of volatility, chain of custody essentials, and the forensic investigation process.
Forensic acquisition and imaging, write blockers, MBR versus GPT partitioning, NTFS/FAT32/exFAT internals, and deleted file recovery and data carving.
Registry hives as evidence, execution and usage artifacts like Prefetch and Shellbags, NTFS filesystem metadata, and event log forensics.
Why memory-only evidence matters, memory acquisition methods, analysis with the Volatility framework, and process injection and hidden process artifacts.
Understanding MACB timestamps, building a super timeline, timeline analysis technique and pivot points, and detecting timestomping.
Sources of network evidence, packet analysis fundamentals, protocol and session reconstruction, and identifying C2 traffic in captures.
Mobile acquisition tiers, iOS and Android artifact categories, cloud forensics fundamentals, and cloud provider evidence sources like M365, Entra ID, and AWS CloudTrail.
Common anti-forensic techniques and their detection tells, writing a defensible forensic report, and expert testimony basics.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
Parses 18 forensic artifact types, a direct fit for the disk and Windows artifact work covered in Chapters 2 and 3.
Multi-source IOC analysis across VirusTotal, Shodan, OTX, and AbuseIPDB, useful for pivoting on indicators recovered during network forensics in Chapter 6.
Passive DNS and domain history lookups, a direct fit for corroborating domain evidence found during network and timeline analysis in Chapters 5 and 6.
Bring-your-own-key IOC triage across the same source set as X-VERDIKT, useful for verifying indicators surfaced during an investigation without a shared API budget.