Digital Forensics & Incident Response Investigation
Correlating host and network evidence to reconstruct suspicious activity.
- Context
- Academic investigations and personal practice
- My role
- Host and network evidence analysis; reporting
- Status
- Investigations and written findings completed
- Deliverable
- Correlated activity, likely root cause and remediation notes
Decision & evidence
Separate observations from conclusions
I correlated host artifacts, packet captures and authentication activity rather than treating a suspicious file or reputation result as a complete explanation.
A report should make clear what the evidence shows, what remains an inference and which additional evidence would resolve it.
Overview
Conducted digital forensic investigations across host artifacts and network evidence using FTK Imager, Autopsy, Wireshark and VirusTotal.
Objective
Reconstruct suspicious activity, identify abnormal behavior and likely root cause, and communicate findings in a form that supports remediation.
My contribution
- Examined digital artifacts, packet captures, suspicious files and URLs, authentication activity and indicators of compromise.
- Correlated host and network evidence to reconstruct attack activity.
- Documented investigative findings, likely root cause and remediation actions.
Technical approach
- Used FTK Imager and Autopsy to examine host evidence and Wireshark to investigate network activity.
- Examined suspicious files and URLs with VirusTotal, then correlated these observations with authentication activity and other indicators.
Scope & considerations
Evidence correlation matters more than an isolated alert. Findings distinguish observed abnormal behavior from a likely root cause so that the report communicates the limits of the available evidence.
Outcome
Demonstrates host and network forensics, incident investigation, evidence correlation and structured technical reporting.