Illustration

Device Information

Operating System

Network

Internet Histories

Volatile Memory Examination

Use The Volatility Framework to extract the below information from physical memory samples:

File Recovery / Carving

Use Foremost to recover file types. Including the below:

Sensitive Data Audit

Misc