This week, our students had the opportunity to explore digital forensics through a practical and investigation-oriented approach, combining technical knowledge, forensic tools and, most importantly, analytical reasoning.
The training was delivered by Ljuban Petrovic, Reza Elgalai and Marc TEROUANNE, digital forensics specialists, drawing on several years of operational experience in digital investigations and forensic examination.
Throughout the week, participants worked progressively from the fundamentals of digital evidence to a complete forensic investigation.
They learned about evidence preservation, integrity and hashing, before exploring key Windows forensic artefacts such as Prefetch, UserAssist, JumpLists and ShellBags. Rather than simply learning where artefacts are located, the objective was to understand the link between a user action and the digital traces left behind on a system.
The participants first generated activity themselves inside their own virtual machines, then used tools such as Eric Zimmerman's forensic tools, X-Ways Forensics and Magnet AXIOM to identify and interpret the traces they had created.
The second part of the week introduced OperationBlueHarbor, a realistic investigation scenario designed specifically for the course. From a forensic disk image, participants had to work as real analysts: explore the system, recover deleted information, identify relevant evidence, correlate artefacts and distinguish facts from assumptions.
Later in the investigation, a memory dump was introduced as a new source of evidence. Using Volatility 3, participants examined running processes, focused on Tor-related activity, extracted process memory and searched for relevant strings and indicators. Particular attention was given to one of the most important skills in digital forensics: understanding what a trace can prove — and what it cannot prove.
The week concluded with evidence correlation, reporting and discussion around how technical findings can be transformed into clear, understandable and useful information for an investigation.
The philosophy throughout the course was simple:
Digital forensics is not about clicking buttons in a forensic tool. It is about understanding the traces, questioning the results, correlating the evidence and being able to explain your conclusions.
A demanding but very rewarding week, with an engaged group of participants who progressively moved from following demonstrations to conducting their own investigation.
Congratulations to everyone who took part in the course for their dedication throughout the intensive 10 week training — especially for surviving Operation Blue Harbor! What comes next are the final exams, the dissertation defence and the internationally recognised university diploma.