What it is
Five hands-on investigations from CSE 469 Computer and Network Forensics. Together they cover the analyst workflow from acquiring evidence to reporting on it.
What I did
- Imaging (lab 1): disk images with
dd, then hash verification to prove the copy matches. - Disk artifacts (lab 2): recovered artifacts, including JPEGs, from a disk image in Autopsy.
- Memory: analyzed a memory dump with Volatility.
- Mobile: triaged phone artifacts with iLEAPP and aLEAPP.
- Network (lab 5): reconstructed activity from a PCAP in Wireshark.