File System Forensic Analysis
A foundational treatment of file-system structures and the reasoning required to examine them.
Examiner Resources
A curated library of external digital-forensics references, validation resources, training material, trusted projects, and recommended books.
Research and artifact references
A practitioner-focused location for investigative and digital-forensics knowledge, references, and community resources.
Why it is hereConsensus-based guidance for digital and multimedia evidence, including validation, quality, examination, imaging, video, and forensic-practice topics.
Why it is hereFree tactical references covering Windows forensics, memory forensics, SIFT, timelines, malware analysis, and related DFIR workflows.
Why it is hereA broad directory of tools, training, books, events, datasets, challenges, and other digital-forensics and incident-response references.
Why it is hereClear, technically detailed digital-forensics education with an especially useful body of Windows, memory, timeline, and artifact-focused material.
Why it is hereA maintained collection of DFIR resources, tools, training, blogs, datasets, communities, and practitioner references.
Why it is hereValidation and test data
Testing methodologies, specifications, test plans, reports, and raw material organized by forensic function.
NISTDocumented forensic reference datasets for tool testing, examiner training, and proficiency work.
NIST / DHSA searchable catalog for locating tools by forensic function and technical capability.
SWGDEA useful baseline for reasoning about the testing of commercial, open-source, and custom forensic tools.
ByteCase guides
A practical guide to recording forensic sources, destinations, methods, tools, versions, write protection, timestamps, hashes, errors, and outputs.
Read guide → WorkflowA practical local folder model for keeping intake, acquisition, verification, examiner notes, timelines, exhibits, reports, and supporting records predictable.
Read guide → IntakeThe information a forensic examiner should receive about the case, requestor, authority, scope, devices, accounts, urgency, credentials, and delivery needs.
Read guide → DocumentationA practical approach to recording examiner actions, observations, interpretations, questions, timestamps, tools, sources, screenshots, and report-ready facts.
Read guide → Integrity and HashingA practical explanation of file hashes, saved manifests, later re-verification, comparison results, and the limits of what a matching hash establishes.
Read guide → ValidationA plain-language guide to validation, verification, known-value testing, expected and observed results, versions, environments, limitations, and revalidation triggers.
Read guide →Recommended shelf
A foundational treatment of file-system structures and the reasoning required to examine them.
A broad foundation covering digital evidence, investigative process, interpretation, and legal context.
A durable reference for memory-acquisition concepts, operating-system internals, and Volatility-based analysis.
A practical reference for Windows artifacts, investigative thinking, and repeatable analysis approaches.
A useful reference for understanding mobile acquisition, platforms, artifacts, and examination workflows.
A practical bridge between forensic preservation, investigation, response, and organizational process.
Books provide durable foundations, but artifact locations, applications, operating systems, and tool behavior change. Pair foundational reading with current vendor documentation, practitioner research, validation material, and hands-on testing.
Tools and projects
Curation over collection
This page will grow carefully as references prove useful in real examiner work. Inclusion does not imply affiliation, sponsorship, or a guarantee that an external resource remains current.