← Case index

CASE./002

Digital forensics

NIST CFReDS Hacking Case

A structured examination of a forensic disk image, connecting host, registry, and network artifacts into a defensible investigation record.

Type
Simulated forensic case
Scope
Disk image + host and network artifacts
Tools
FTK Imager, Autopsy, Registry Explorer, Wireshark
Output
Documented findings and evidence trail

Answer the case without losing the evidence trail.

Investigation brief

I examined a NIST CFReDS forensic image to identify relevant system activity, establish a timeline, and support each conclusion with recoverable artifacts rather than assumption.

A repeatable path from image to finding.

PreserveVerify the image and work from a copy.
SurveyReview the file system and build a timeline.
ExamineInspect registry, host, and network artifacts.
CorrelateConnect timestamps and activity across sources.
ReportMap every conclusion back to evidence.

Each tool had a specific investigative job.

FTK Imager
Acquire, verify, and inspect the evidence image.
Autopsy
Search files, metadata, deleted content, and timeline events.
Registry Explorer
Review user, system, and execution artifacts in registry hives.
Wireshark
Examine packet evidence and relate network activity to host events.

Make the reasoning reproducible.

The value of the exercise was not only finding artifacts; it was preserving enough context for another analyst to follow the same path.

Evidence discipline

  • Image integrity and working-copy separation
  • Artifact source and timestamp notes
  • Cross-tool validation

Reporting discipline

  • Observation separated from interpretation
  • Conclusions tied to artifacts
  • Clear limits where evidence was incomplete
Good forensic work is a chain of documented decisions, not a list of tool outputs.

This case developed evidence handling, timeline analysis, Windows artifact review, packet analysis, cross-source correlation, and concise technical reporting.