OWL SECTORCyber Security - Freemont Starfire Cadet Squadron
Lesson 03 / 05 · 15–20 minutes

Digital Forensics

Digital forensics examines digital evidence to understand what happened while preserving the evidence.

What you’ll learn

  • Identify common sources of digital evidence.
  • Build a timeline from a log.
  • Describe why originals, hashes, and documentation matter.

Look for traces

Logs record events. Metadata describes a file, such as its format or timestamps. Browser history, emails, and network captures may also contain evidence. A file extension is only a label: a file called photo.jpg is not automatically a JPEG. File signatures can help identify the actual format.

Preserve before investigating

Document the source and who handled it. Use an appropriate forensic copy and work on that copy; avoid changing the original. A cryptographic hash helps check whether bytes changed. Keep an evidence handling record, called a chain of custody. Real device collection should be done by trained personnel because interacting with a device can alter evidence.

Build a timeline

Put events in order, note the time zone, and distinguish successful actions from failed attempts. Device clocks may differ. Match logs with other evidence rather than treating a single event as the whole story.

Evidence has limits

A username or IP address is a clue, not proof of a person’s identity. Shared devices, shared networks, and compromised accounts complicate attribution. A timestamp alone does not prove who changed a file. Explain what your evidence supports and what remains uncertain.

Try it

Case: the missing club notes

These fictional events are from one server, all in UTC. Which event first records a successful login? What happened afterward?

14:01  account=club_admin  login FAILED
14:02  account=club_admin  login FAILED
14:04  account=club_admin  login SUCCESS
14:05  account=club_admin  downloaded notes.pdf
14:07  account=club_admin  deleted notes.pdf

Review the investigator’s explanation

The successful login was at 14:04 UTC, followed by a download at 14:05 and deletion at 14:07. The log associates the events with an account. It does not identify the person using it or prove the earlier failures were an attack.

Check your understanding

Choose one answer for each question, then check your answers. You can retry as often as you like.

1. Where should an investigator normally analyze files?
2. An IP address alone proves…
3. Why record the time zone?

Keep learning

NIST: digital evidence preservation (opens a new tab)