Lot of people asking how to gain forensics skills right off the street now. I got myself into this 🤷🏻‍♀️🍸. Best way to start to learn forensics is to *do it on your own Windows computer* (preferably physical). Start with basic sysinternals tools. @markrussinovich’s books are great.
11
71
7
423
You have a handy piece of evidence to examine right in front of you, and understanding how your own activity appears in memory, registry, caches, and MFT can often be much more memorable and educational than some VM lab. Lots of great free Windows forensics tools out there.
2
3
1
63
The tools we use day to day to do memory forensics are widely free, like Volatility. Disk forensics is still kind of controlled by a few expensive software powerhouses, but just learning how your own computer stores, processes, executes is a huge educational leap forward.
3
3
58
Replying to @hacks4pancakes
Autopsy and TSK are free and get you a long way. Carrier’s “File System Forensic Analysis” is a good spend here.

Jul 31, 2021 · 7:55 PM UTC

1
5
21
I spent an unreasonable amount of time pouring over Carriers book recently when I wrote an MFT parser in emacs lisp (as a distraction, mind you!) and it’s incredible the wealth of information he managed to cover.
3
1
8