Thanks to everyone who emailed me in that they completed or had questions about the mini forensics challenge, I’m glad that someone out there reads this blog ;) Here are the answers below. I used Hex Editor Neo in the screenshots.
Over the next wee while I am going to set some small forensic challenges for you to have a go at. The idea is that you don’t need expensive forensic software (i.e. EnCase!) to have a go; all of these are doable by hand using a hex/text editor. If you know how to do it manually, then you can explain what happens when EnCase or FTK do their magic and also be able to verify it.
rabbit nutrition cases Derren Brown blood Highland cow Chilli CSS internet history data flow birthday Hayes commands bacon new Belgium Itiel Dror case management cyber threat models wifi altitude sickness laptop answers nudge theory mentoring cloud dinosaurs promotion chain of custody treats qualitative Opera Strathclyde encryption Tineye cables alternate data streams OCFA etiquette Skye recycle bin Mweke crime scene unicode handmade crime chicken CV sewing exams Barranco camp backup Mesh computers ISACA coasters bibliography security induction insider fraud Pixel Ian Kendall SQLAlchemy