01 / Objective
Answer the case without losing the evidence trail.
Investigation brief
I examined a NIST CFReDS forensic image to identify relevant system activity, establish a timeline, and support each conclusion with recoverable artifacts rather than assumption.
02 / Method
A repeatable path from image to finding.
PreserveVerify the image and work from a copy.
SurveyReview the file system and build a timeline.
ExamineInspect registry, host, and network artifacts.
CorrelateConnect timestamps and activity across sources.
ReportMap every conclusion back to evidence.
03 / Tool-to-question map
Each tool had a specific investigative job.
- FTK Imager
- Acquire, verify, and inspect the evidence image.
- Autopsy
- Search files, metadata, deleted content, and timeline events.
- Registry Explorer
- Review user, system, and execution artifacts in registry hives.
- Wireshark
- Examine packet evidence and relate network activity to host events.
04 / Evidence record
Make the reasoning reproducible.
The value of the exercise was not only finding artifacts; it was preserving enough context for another analyst to follow the same path.
Evidence discipline
- Image integrity and working-copy separation
- Artifact source and timestamp notes
- Cross-tool validation
Reporting discipline
- Observation separated from interpretation
- Conclusions tied to artifacts
- Clear limits where evidence was incomplete
05 / Skills demonstrated
Good forensic work is a chain of documented decisions, not a list of tool outputs.
This case developed evidence handling, timeline analysis, Windows artifact review, packet analysis, cross-source correlation, and concise technical reporting.