Modern investigations often require capturing volatile data (data that disappears when the computer is turned off).
| Lab # | Topic | Key Skills | |-------|-------|-------------| | 1 | Disk imaging and hashing | Creating forensic images (DD, E01), verifying SHA-256 | | 2 | File carving | Recovering deleted files using Scalpel/PhotoRec | | 3 | Memory forensics | Analyzing RAM dumps with Volatility | | 4 | Network forensics | Packet analysis with Wireshark | | 5 | Mobile device forensics | Extracting data from Android/iOS images | | 6 | Log analysis | Windows/Linux event log correlation | | 7 | Anti-forensics detection | Identifying steganography and data hiding | | 8 | Report writing | Drafting expert forensic reports | a detective handling child exploitation cases
Whether you are a student preparing for the CHFI or CISSP exam, a detective handling child exploitation cases, or an IT manager responding to a breach, a structured lab manual is your compass. a detective handling child exploitation cases
4.5/5