Ravindra BagaleCourses & study guides

28. Introduction to Digital Forensics

Chala mitrano, Part 10 cha shevatcha chapter – digital forensics. Aataparyant aapan attack ani defence shiklo. Pan ghatna ghadun geli tar? Koni kela, ksa kela, kay gela – he shodhne mhanje forensics. He mhanje digital detective cha kaam: purava (evidence) gola karne, to kharab na hou deta tapasne, ani report banavne jo court madhe suddha chalel. Ha ek changla career marg pan aahe. Aaj basics baghu – concepts ani Autopsy tool. Sagle fakt tumchya swatahchya lab data var. Samjla ka? Chala!

What you will learn in this chapter

  • What digital forensics is and where it is used
  • The core principles: preserve, chain of custody, work on copies
  • Types: disk, memory, network and mobile forensics
  • Key ideas: disk images, hashing for integrity, write blockers
  • Autopsy and The Sleuth Kit (introduction)
  • Where forensics fits in incident response and a note on Indian law

Lab scope for this whole chapter

Practise only on your own disks, images and files, or on deliberately shared practice images. Examining someone else's device or data without authorisation breaches privacy law and the IT Act. Real investigations are done by authorised people following legal process.

Concepts in this chapter

  1. 28.1What Digital Forensics Is
  2. 28.2Core Principles
  3. 28.3Types of Forensics
  4. 28.4Making and Verifying a Disk Image
  5. 28.5Autopsy and The Sleuth Kit
  6. 28.6Forensics, Incident Response and the Law
  7. 28.7Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.