Disk Imaging & File System Forensics
Forensic imaging with FTK Imager and dd/dcfldd, file system navigation, MFT analysis, deleted file recovery, and slack space examination.
A structured, foundation-to-professional pathway in disk and memory forensics, from forensic imaging protocols to advanced timeline correlation — following methodology accepted in Australian courts.
Forensic imaging with FTK Imager and dd/dcfldd, file system navigation, MFT analysis, deleted file recovery, and slack space examination.
Live memory capture with WinPmem/LiME, Volatility 3 analysis, process reconstruction, injected code detection, and credential recovery from memory dumps.
Super-timeline buildout with Plaso/log2timeline, event correlation across disk and memory artefacts, and building a coherent narrative of attacker activity.
Practical, operator-grade exercises using forensic images, memory dumps, and real-world investigation scenarios — the same workflows used in AFP digital forensic labs.
Bit-for-bit imaging, EWF/AFF formats, verification hashing, and maintaining forensic soundness throughout the imaging process.
File system internals, MFT record analysis, INDX attributes, USN journal, and how attackers manipulate file system metadata.
File carving with PhotoRec and Foremost, unallocated cluster analysis, and recovering files attackers thought they destroyed.
SAM/SYSTEM/SOFTWARE hive analysis, user activity reconstruction, USB device history, and persistence mechanism detection via registry artefacts.
Process listing, DLL enumeration, network connection recovery, injected code detection, and malware footprint identification from RAM captures.
Rapid triage with Kroll Artifact Parser and Extractor, targeted artefact collection, and building repeatable forensic collection playbooks.
Professional forensics environment. Same tools operated by AFP Digital Forensics and state police forensic units.
This module is built under the express tuteallage of two specialist practitioners who bring together cutting-edge machine learning and the hard-won credibility of the courtroom. You study directly under their guidance.
Machine Learning Specialist
Resident expert providing express tuteallage in ML-driven forensic artefact analysis. Christopher teaches timeline correlation via machine learning, anomaly detection in super-timelines, clustering of related attacker events, and automated confidence-scoring for forensic findings — all tooling built and demonstrated within this module.
ASFDE — Australasian Society of Forensic Document Examiners
Bonafide ASFDE member with deep forensic methodology expertise applicable across all evidence domains. A courtroom-recognised authority whose expert opinions have been accepted in Australian federal and state jurisdictions. Ms. Morrell provides the express tuteallage for forensic methodology, evidence handling, courtroom preparation, and expert-witness conduct — ensuring every digital forensic technique taught meets the admissibility standard she herself upholds under cross-examination.
Directory: www.hacking101.com.au/forensic-analysis-101/disk-memory-forensics/
Parent path: www.hacking101.com.au/forensic-analysis-101/