Digital forensics & incident research

Follow the
evidence.

Reconstruct the incident.
Understand what happened.

Digital evidence. Device artifacts. Incident timelines.
Research at the intersection of forensics, privacy and defense.

EVIDENCE ACQUISITION/ARTIFACT ANALYSIS/INCIDENT RECONSTRUCTION

THE LATEST PUBLISHED STORIES

News & insights.

View all news ↗

Evidence first.

The details
make the
difference.

What happened. When it happened. What the evidence can actually support.

01 / HDD

Magnetic media. Mechanical precision.

HDD, SATA SSD, M.2 NVMe and managed flash: different storage architectures, one principle. Preserve the original source.

Inside digital forensics ↗
01 Preserve the source02 Verify integrity03 Correlate the traces04 Explain the findings

Every connection.
A trail to follow.

01 — The signal

Map the signal.
Establish the scope.

Trace relationships between endpoints, network records and infrastructure. Map what is known, record uncertainty, and preserve context before drawing conclusions.

ScopeTelemetryContext
Explore incident response ↗

02 — The acquisition

Preserve the source.
Work from a copy.

Use documented acquisition, verified hashes and a recorded chain of custody. Keep source media separate from analysis and account for the limits of each method.

AcquisitionHash verificationChain of custody
Explore forensic acquisition ↗

03 — The reconstruction

Reconstruct events.
Test every inference.

Correlate timestamps, filesystem artifacts and network evidence. Separate observations from interpretation and build a timeline another analyst can examine.

Artifact correlationTimeline analysisReporting
Inside the analysis ↗

FOLLOW THE INVESTIGATION ↓

LOOK BEYOND THE SURFACE

Every byte.
In context.

The device is the beginning. A defensible finding connects the source, its artifacts and the limits of what they can tell us.

  1. 01

    Preserve the original.

    Document the source and the collection boundary.

  2. 02

    Verify the working copy.

    Keep integrity checks and the handling record together.

  3. 03

    Reconstruct with context.

    Correlate artifacts. Test alternative explanations.

Build an evidence timeline ↗
PRESERVE / VERIFY / EXPLAIN

Forensic rigor.
Defensive depth.

Understand the artifact.
Understand the system that produced it.

THE DEFENSE PLAYBOOK

Turn your threat model into a plan.

Prioritise the defenses that fit your reality.

Build your baseline ↗

Field methods.
Practical evidence.

All 14 field guides ↗

ASK BETTER QUESTIONS OF THE EVIDENCE.

Beyond the incident.
Into the evidence.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC