Examiner Resources

External references worth returning to.

A curated library of external digital-forensics references, validation resources, training material, trusted projects, and recommended books.

Research and artifact references

Places to begin when the artifact or behavior is unfamiliar.

Investigator network

INV Network

A practitioner-focused location for investigative and digital-forensics knowledge, references, and community resources.

Why it is here
  • Useful starting point for examiner research
  • Broader investigative context beyond one tool vendor
  • Resource discovery across related disciplines
Consensus guidance

SWGDE

Consensus-based guidance for digital and multimedia evidence, including validation, quality, examination, imaging, video, and forensic-practice topics.

Why it is here
  • Practical professional guidance
  • Useful policy and procedure references
  • Strong starting point for tool-testing expectations
Free references

SANS Posters and Cheat Sheets

Free tactical references covering Windows forensics, memory forensics, SIFT, timelines, malware analysis, and related DFIR workflows.

Why it is here
  • Fast desk-side references
  • Strong visual reminders during analysis
  • Regularly refreshed practitioner material
Training directory

DFIR Training

A broad directory of tools, training, books, events, datasets, challenges, and other digital-forensics and incident-response references.

Why it is here
  • Large discovery index
  • Useful when searching for a niche tool or topic
  • Connects training and practitioner resources
Practitioner education

13Cubed

Clear, technically detailed digital-forensics education with an especially useful body of Windows, memory, timeline, and artifact-focused material.

Why it is here
  • Strong technical explanations
  • Useful demonstrations of real workflows
  • Accessible without sacrificing depth
Reference collection

AboutDFIR

A maintained collection of DFIR resources, tools, training, blogs, datasets, communities, and practitioner references.

Why it is here
  • Useful map of the wider DFIR community
  • Good discovery point for specialized references
  • Organized by practical subject area

ByteCase guides

Original explanations, checklists, and examiner references.

Open the guide hub →

Recommended shelf

Seminal and durable books for forensic examiners.

File systems

File System Forensic Analysis

Brian Carrier

A foundational treatment of file-system structures and the reasoning required to examine them.

Foundations

Digital Evidence and Computer Crime

Eoghan Casey

A broad foundation covering digital evidence, investigative process, interpretation, and legal context.

Memory

The Art of Memory Forensics

Michael Hale Ligh, Andrew Case, Jamie Levy, and AAron Walters

A durable reference for memory-acquisition concepts, operating-system internals, and Volatility-based analysis.

Windows

Windows Forensic Analysis Toolkit

Harlan Carvey

A practical reference for Windows artifacts, investigative thinking, and repeatable analysis approaches.

Mobile

Practical Mobile Forensics

Rohit Tamma and coauthors

A useful reference for understanding mobile acquisition, platforms, artifacts, and examination workflows.

Incident response

Incident Response & Computer Forensics

Jason Luttgens, Matthew Pepe, and Kevin Mandia

A practical bridge between forensic preservation, investigation, response, and organizational process.

Books provide durable foundations, but artifact locations, applications, operating systems, and tool behavior change. Pair foundational reading with current vendor documentation, practitioner research, validation material, and hands-on testing.

Curation over collection

A useful library should explain why the link matters.

This page will grow carefully as references prove useful in real examiner work. Inclusion does not imply affiliation, sponsorship, or a guarantee that an external resource remains current.