// Analysis

Explore Digital Forensics

Every deletion, every timestamp, every "clean" wipe leaves something behind — the question is whether you know where to look.

Digital forensics rewards people who don't trust the first answer a tool gives them. Windows Explorer says a file was modified Tuesday at 2 PM — but is that $STANDARD_INFORMATION, which any script can rewrite, or $FILE_NAME, which usually isn't touched? Your tutor won't hand you that distinction as a fact to memorize. It sketches the MFT record structure on the whiteboard and asks you to figure out which timestamp field an attacker forgot.

Sessions here start with the artifact, not the lecture. Your tutor lays out a chain-of-custody log with a gap in it, or plots a partial timeline from MFT, USN Journal, and Event Log entries side by side, and works you through what's consistent and what isn't. You're the one deciding whether the 3 AM login lines up with a machine that was asleep, or whether Event ID 1102 is the attacker's own fingerprint on the cover-up.

None of this replaces the coursework or the certification path — it's the place to actually reason through why hardware write-blockers hold up in court while software ones invite scrutiny, or why pulling the power cord on a BitLocker machine can destroy the only chance at the keys. You bring the question; your tutor brings the scaffold and the follow-up that finds the gap in your thinking.

// What a session feels like

You bring the questions. Your tutor asks the next one.

  • your tutor sketches a disk layout with slack space and unallocated clusters marked out, then asks you to explain where a 'deleted' file's data actually sits — and why overwriting one cluster doesn't erase the rest.
  • In the browser terminal, you run strings and grep against a memory dump your tutor has staged, hunting for the process that was running when the machine was imaged — your tutor only jumps in when you've missed a correlating artifact.
  • your tutor places a super-timeline excerpt on the whiteboard — MFT, Prefetch, and USN Journal entries clustered around one suspicious hour — and asks you which artifact would fall apart first if the suspect's alibi were true.

Start exploring Digital Forensics tonight — a 30-day trial, cancel anytime.

Start your 30-day trial