1 Practice lectures
Storage foundationsBits, bytes, hex, little-endian
numbers, sectors and clusters. Start here if any of these are new.
File systems in hexMBR, GPT, FAT32, ext4 and NTFS,
byte by byte, with interactive hex views.
Multimedia forensicsJPEG, PNG, TIFF/EXIF,
error level analysis, appended payloads, steganography and device attribution.
Mobile forensicsiOS and Android acquisition,
SQLite, deleted chats in freeblocks and the WAL, location history.
Network forensicspcap and pcapng byte by byte,
DNS, HTTP and TLS, NetFlow and Zeek, log formats and time, e-mail headers and the SIEM method.
2 Homework
HW1 · The Parking Lot StickCase CC-2026-017: briefing,
chain of custody, acquisition of a USB stick found on company premises, and the evidence download.
HW2 · The Midnight UploadCase CC-2026-031: a night-time upload
under a colleague's account. Analyse the secured logs, a packet capture and e-mails to reconstruct who did it from
badge, Wi-Fi, VPN, proxy, DNS, flow and mail records.