DFIR / Analysis

Digital Forensics Investigation

Digital forensics investigation utilizing Autopsy for user tracking, file recovery, and deep artifact analysis.

Digital Forensics Investigation

Project Details

Performed a comprehensive forensic investigation using the Autopsy toolset to track user activity, recover deleted files, and extract network and registry artifacts.

The Challenge

Extract, synthesize, and correlate reliable user activity timelines and data from incomplete digital footprints and host evidence.

Implementation & Solution

Conducted deep-dive recovery of files, meticulously analyzed registry traces, and mapped system network artifacts to reconstruct actionable evidence.

Key Outcome & Metrics

Successfully identified malicious tools including Mimikatz and Lazagne, and extracted IP/MAC address logs to produce a strong investigation workflow and evidence trail.

Assessment Toolkit

Technologies and stack used in this case study

AutopsyRegistry AnalysisFile RecoveryNetwork Artifacts

Visual context

Project Imagery & Artifacts

A parallax scrollable media collection adding visual depth to the project's timeline and milestones.

thumbnail
thumbnail
thumbnail
thumbnail
thumbnail
thumbnail