Digital forensics depends on preserving evidence before interpreting it. This hands-on course introduces a defensible Linux workflow for identifying a storage source, creating a raw image, recording integrity hashes, recovering files from raw bytes, and turning metadata into concise findings.
You will image a simulated drive with dd, compare SHA-256 values, carve embedded JPEG and PDF artifacts with Foremost, and inspect image and document metadata with ExifTool. A final investigation asks you to hash a supplied image, recover a deleted PDF, extract its author and creator fields, and compile a short evidence report.
What You Will Learn
- Identify a simulated evidence device with
lsblkbefore acquisition - Create a byte-for-byte raw image with
ddand verify its expected size - Hash both the source and acquired image with SHA-256 to confirm matching contents
- Explain how forensic imaging differs from ordinary file copying
- Examine a raw image and recover signature-based JPEG and PDF artifacts with Foremost
- Read a carving audit log and locate recovered files by type
- Extract GPS, camera, author, and creator metadata with ExifTool
- Combine an evidence hash and selected metadata into a concise command-line report
Who This Course Is For
This intermediate course is for cybersecurity learners, incident responders, system administrators, and aspiring forensic analysts who want practical experience with foundational disk-forensics tasks. It focuses on acquisition, integrity, carving, metadata, and basic reporting rather than a complete legal investigation methodology.
Prerequisites: Comfort using a Linux terminal, navigating files and directories, running commands with sudo, and redirecting or filtering output. Basic knowledge of filesystems, hashes, and file formats is helpful; prior forensic-tool experience is not required.
Learning environment: An interactive Ubuntu 22.04 terminal with a simulated loop device, prepared raw evidence images, Foremost, ExifTool, dd, lsblk, and SHA-256 utilities. All evidence is synthetic and contained within the lab.
Frequently Asked Questions
Will I work with a real suspect disk or personal data?
No. The acquisition lab uses a 10 MB simulated loop device, and the analysis images contain purpose-built JPEG and PDF samples. No real user device or personal evidence is involved.
Does the course preserve the original evidence automatically?
The workflow reads from the simulated source, writes analysis outputs to separate files or directories, and compares source and image hashes. It teaches the principle of analyzing a verified copy, but it does not simulate hardware write blockers or a full evidence-storage system.
Is file carving guaranteed to recover every deleted file?
No. The lab uses intact, recognizable file signatures so Foremost can recover prepared artifacts. In real cases, overwritten, fragmented, encrypted, or unsupported data may be incomplete or unrecoverable.
Does the final text report establish a complete legal chain of custody?
No. It records a SHA-256 line and selected metadata to practice traceable reporting. Formal investigations also require documented handling, timestamps, personnel, storage controls, validated procedures, and organization-specific legal requirements.





