<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_Forensics</id>
	<title>Draft:Introduction to Forensics - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikicyber.org/index.php?action=history&amp;feed=atom&amp;title=Draft%3AIntroduction_to_Forensics"/>
	<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Forensics&amp;action=history"/>
	<updated>2026-09-24T04:43:33Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_Forensics&amp;diff=150&amp;oldid=prev</id>
		<title>MigrationBot: Backfill (v3.0 review queue): added to the review queue</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Forensics&amp;diff=150&amp;oldid=prev"/>
		<updated>2026-09-22T05:42:29Z</updated>

		<summary type="html">&lt;p&gt;Backfill (v3.0 review queue): added to the review queue&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 05:42, 22 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l97&quot;&gt;Line 97:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 97:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows Forensics|001]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Windows Forensics|001]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Migrated from cypat.guide]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Pending review]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wikicyber:diff:1.41:old-70:rev-150:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
	<entry>
		<id>https://wikicyber.org/index.php?title=Draft:Introduction_to_Forensics&amp;diff=70&amp;oldid=prev</id>
		<title>MigrationBot: Import from cypat.guide: docs/windows/forensics/intro_forensics.md</title>
		<link rel="alternate" type="text/html" href="https://wikicyber.org/index.php?title=Draft:Introduction_to_Forensics&amp;diff=70&amp;oldid=prev"/>
		<updated>2026-09-18T17:05:24Z</updated>

		<summary type="html">&lt;p&gt;Import from cypat.guide: docs/windows/forensics/intro_forensics.md&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Submit}}&lt;br /&gt;
&amp;lt;!-- Migrated from https://cypat.guide/docs/windows/forensics/intro_forensics (source: docs/windows/forensics/intro_forensics.md) --&amp;gt;&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
Author(s): a_person&lt;br /&gt;
&lt;br /&gt;
Last Updated: 05-30-2026&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! Recommended Prerequisites (click to expand)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
None&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Digital Forensics ==&lt;br /&gt;
&lt;br /&gt;
Think about a physical crime scene. An investigator would examine the scene, look for evidence, document their findings, and reconstruct what happened. Digital forensics is very similar. Instead of physical evidence, forensic analysts investigate logs, file systems, network traffic, and other artifacts to:&lt;br /&gt;
&lt;br /&gt;
* identify evidence&lt;br /&gt;
* reconstruct exactly what happened&lt;br /&gt;
* determine the cause of an incident&lt;br /&gt;
* support legal investigations&lt;br /&gt;
&lt;br /&gt;
Digital forensics is also a vital part of incident response (IR), which is the process an organization uses to detect, respond to, and recover from cyberattacks.&lt;br /&gt;
&lt;br /&gt;
== What are forensics questions? ==&lt;br /&gt;
&lt;br /&gt;
Forensics Questions are questions that ask about the current system, logs of attacks, or general information that has some relationship to the current system. These can ask you anything from CVEs, using logs to find indicators of compromise, or reversing a binary. They can also include file attachments which include, but are not limited to: network captures, images, and malware. They are usually located on the Desktop.&lt;br /&gt;
&lt;br /&gt;
== Practice! ==&lt;br /&gt;
&lt;br /&gt;
Here are some example, easy forensics questions that do not require much work:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! &amp;#039;&amp;#039;&amp;#039;Find the CVEs fixed in Notepad++ v8.5.7&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Fixed CVEs:&amp;#039;&amp;#039;&amp;#039; CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166&amp;lt;br /&amp;gt; &amp;#039;&amp;#039;&amp;#039;Reference:&amp;#039;&amp;#039;&amp;#039; [https://notepad-plus-plus.org/downloads/v8.5.7/ Notepad++ v8.5.7 Release Notes]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! &amp;#039;&amp;#039;&amp;#039;Decode the encrypted message&amp;#039;&amp;#039;&amp;#039;: &amp;lt;code&amp;gt;5a 47 39 75 61 32 56 35 49 47 6c 7a 49 47 35 76 64 43 42 7a 61 32 6c 69 61 57 52 70&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Decoded:&amp;#039;&amp;#039;&amp;#039; donkey is not skibidi&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can decode it by decoding from hex, then decoding the result from Base64. Cyberchef link: https://cyberchef.org/#recipe=From_Hex(&amp;#039;Auto&amp;#039;)From_Base64(&amp;#039;A-Za-z0-9%2B/%3D&amp;#039;,true,false)&amp;amp;input=NWEgNDcgMzkgNzUgNjEgMzIgNTYgMzUgNDkgNDcgNmMgN2EgNDkgNDcgMzUgNzYgNjQgNDMgNDIgN2EgNjEgMzIgNmMgNjkgNjEgNTcgNTIgNzA&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! &amp;#039;&amp;#039;&amp;#039;What is the publication timestamp (ISO 8601) for CVE-2025-4561?&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Timestamp:&amp;#039;&amp;#039;&amp;#039; 2025-05-12T06:44:29.959Z&amp;lt;br /&amp;gt; &amp;#039;&amp;#039;&amp;#039;Source:&amp;#039;&amp;#039;&amp;#039; [https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/4xxx/CVE-2025-4561.json CVE Record on GitHub]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Here is an example of conducting forensics on Windows Event Logs. This was a scrapped challange for a CTF. You may want to do some research if you are not familiar with them.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;[https://cypat.guide/FQPractice.evtx Click here to download the file]&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;mw-collapsible mw-collapsed wikitable&amp;quot; style=&amp;quot;width:100%&amp;quot;&lt;br /&gt;
! &amp;#039;&amp;#039;&amp;#039;Find the following information: the executable file downloaded and ran that was the malware, the name of the executable that abused an unquoted service path, the sensitive file that was accessed, the command that led the attacker to discover it, the registry value created for persistence of the PowerShell script uploading user data, and the FTP server port number.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Answers:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;update.exe&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;My.exe&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;passwords.txt&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;netshare&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;SysmonAgent&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;2222&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== What can I use for extra practice? ==&lt;br /&gt;
&lt;br /&gt;
CTFs, practice images, and Hack the Box are great for forensics practice. Here are some websites you can use to practice them:&lt;br /&gt;
&lt;br /&gt;
* https://picoctf.org/&lt;br /&gt;
* https://github.com/alphyos/CyberStart-2024&lt;br /&gt;
* https://imaginaryctf.org/&lt;br /&gt;
* https://images.cypat.guide&lt;br /&gt;
* https://www.hackthebox.com/&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows Forensics|001]]&lt;br /&gt;
[[Category:Migrated from cypat.guide]]&lt;/div&gt;</summary>
		<author><name>MigrationBot</name></author>
	</entry>
</feed>