Collect, analyze, and report, real-world forensic investigation exercises
Investigate a terminated employee suspected of exfiltrating proprietary data via USB and cloud uploads before departure.
Trace a multi-stage malware infection from initial dropper through payload deployment, persistence mechanisms, and C2 communications.
Investigate a ransomware attack on a corporate file server, trace the encryption timeline, identify the variant, recover artifacts, and determine if data was exfiltrated before encryption.
Investigate a disgruntled system administrator who sabotaged production systems by deleting logs, tampering with configurations, covering tracks, and abusing privileged access.
Extract and analyze artifacts from a suspect's Android device including SQLite databases, app data, GPS location history, and messaging records tied to a fraud scheme.
Analyze a business email compromise (BEC) attack by examining PST mailbox archives, email headers, attachment metadata, and phishing indicators to trace the attacker's methods.
Analyze a volatile memory dump from a compromised server to identify hidden processes, DLL injection artifacts, rootkit indicators, and reconstruct the attacker's in-memory toolkit.
Investigate a web server compromise by analyzing Apache access logs, identifying webshell uploads, tracing the attacker's file operations, and reconstructing the full intrusion timeline.
Trace cryptocurrency transactions linked to a ransomware payment by analyzing browser artifacts, exchange login records, wallet addresses, and blockchain transaction histories from a suspect's workstation.
Investigate unauthorized data sharing from a corporate OneDrive account by analyzing sync client artifacts, deleted file recovery metadata, sharing activity logs, and cloud access tokens.
Track USB device connections on a corporate workstation to determine which removable storage devices were used, when they were connected, and what files were copied during an unauthorized data transfer.
Perform deep network forensic analysis on captured PCAP data, DNS cache dumps, ARP tables, and firewall logs to reconstruct a sophisticated multi-stage network intrusion with lateral movement and data exfiltration.