Two self-contained, browser-based forensic investigation environments designed for students who do not have access to a prepared Windows or Mac forensic image.
Investigate EVTX, Registry, Prefetch, USBSTOR, LNK/Jump Lists, browser history, Recycle Bin, SRUM, $MFT and USN evidence.
Investigate Safari, quarantine, TCC, Unified Logs, LaunchAgents, FSEvents, Spotlight, recent items, zsh history, APFS and FileVault context.
Students review artifact concepts and complete the knowledge check.
Students work the case, query the simulated console, correlate artifacts and build a timeline.
Students export the examiner report and defend which conclusions are facts, inferences, or unsupported.