Forensics Basics

Collin Dewey

10/03/2024

Presentation Slides

Forensics Basics

For CTF Competitions


What is forensics?

Identify/Obtain Evidence


Carving

binwalk

strings

photorec


Filesystem Forensics

RAW Image - A copy of the raw bytes that are stored on a hard drive.


Windows Registry

Where Windows stores a lot of configuration


RAM Forensics

Volatility


Steganography


Steganography Methods


Steganography Tools

Any advanced photo editor (Paint.NET, Krita, GIMP, Photoshop, Photopea)

Digital Invisible Ink Toolkit

OpenStego

Sherloq

StegOnline Checklist


Unredacter

De-pixelate Text

bg right contain

>> Home