What you will learn
- Handle digital evidence methodically
- Inspect metadata and logs
- Explain findings with reproducible evidence
Investigate files, metadata, logs, memory artifacts, and network captures to reconstruct events from digital evidence.
43 challenges available.
ForensicsLevel 4Analyze AWS CloudTrail logs to detect unauthorized IAM access and data exfiltration. Learn cloud forensics. Provided…
ForensicsLevel 4The startup-generated `image/` directory is a `docker save`-style image layer layout. Analyze its `layer.tar` files…
ForensicsLevel 4Analyze a safe TLS-forensics fixture. traffic.pcap is a text representation of one TLS application-data capture and…
ForensicsLevel 4Analyze the recovered memory-string record `memstrings.txt` and reconstruct the obfuscated second-stage payload.…
ForensicsLevel 4Compare `modules_list.txt` and `sysfs_modules.txt`, two reconstructed views of Linux kernel modules, to identify the…
ForensicsLevel 4Follow the three-stage data trail hidden in `cover.png` and `notes.txt`: decode the PNG pixel-LSB message, the Base64…
ForensicsLevel 4Analyze the fragments and `.meta` sidecars under `fragments/` to reconstruct a fragmented JPEG. Determine the order…
ForensicsLevel 4Reconstruct a three-disk RAID5 scenario as a safe file-level parity fixture. No block device, mdadm, or loop device is…
ForensicsLevel 4Correlate `web.log`, `auth.log`, and `db.log` by session ID to reconstruct the intrusion from the web attack through…
ForensicsLevel 5Correlate `edr_process.log`, `proxy_http.log`, `dns_queries.log`, and `dlp_transfer.log` on their shared campaign ID…
ForensicsLevel 5Learn BitLocker recovery-key verification with a safe metadata fixture. bitlocker.img is not a real volume. Match a…
ForensicsLevel 5Analyze a Bitcoin OP_RETURN using a safe offline transaction fixture. transaction.json is a recorded artefact that…
ForensicsLevel 5Learn IoT firmware extraction using a safe tar-formatted rootfs fixture. firmware.bin is not a real device image.…
ForensicsLevel 5Analyze KVM hypervisor guest state using a safe text VMCS/guest-memory fixture. Without starting or acquiring a VM,…
ForensicsLevel 5Compare `process_list.txt` with `image_regions.txt` to detect process hollowing. The target process has a PRIVATE, RWX…
ForensicsLevel 5Analyze the NTFS-like timeline in `mft_timeline.csv` and compare each file's SI and FN timestamps. The physically…
ForensicsLevel 5Perform encrypted-iOS-backup password verification with a safe iTunes metadata fixture. No real iPhone or backup is…
ForensicsLevel 5Perform custom Linux-kernel memory-profile matching with a safe static fixture. Match the BUILD_ID records in vmlinux,…
ForensicsLevel 5Analyze the endpoint beacon record `beacon.log` and decode the covert channel hidden among decoy traffic.…