Lot of people asking how to gain forensics skills right off the street now. I got myself into this 🤷🏻♀️🍸. Best way to start to learn forensics is to *do it on your own Windows computer* (preferably physical). Start with basic sysinternals tools. @markrussinovich’s books are great.
11
71
7
423
You have a handy piece of evidence to examine right in front of you, and understanding how your own activity appears in memory, registry, caches, and MFT can often be much more memorable and educational than some VM lab. Lots of great free Windows forensics tools out there.
2
3
1
63
Autopsy and TSK are free and get you a long way. Carrier’s “File System Forensic Analysis” is a good spend here.
Jul 31, 2021 · 7:55 PM UTC
1
5
21


