Nathaniel Sauer

Cybersecurity and software engineer

All work

forensic-casebook

Five forensic lab investigations, from disk imaging to PCAP reconstruction

securitycoursework

What it is

Five hands-on investigations from CSE 469 Computer and Network Forensics. Together they cover the analyst workflow from acquiring evidence to reporting on it.

What I did

  1. Imaging (lab 1): disk images with dd, then hash verification to prove the copy matches.
  2. Disk artifacts (lab 2): recovered artifacts, including JPEGs, from a disk image in Autopsy.
  3. Memory: analyzed a memory dump with Volatility.
  4. Mobile: triaged phone artifacts with iLEAPP and aLEAPP.
  5. Network (lab 5): reconstructed activity from a PCAP in Wireshark.