Forensic investigation · disk, memory, network, 2026
Reconstructing an insider theft across disk, memory, and network
The case: an admin account creates a second user, researches steganography, hides a stolen file of bank details inside an ordinary JPEG, then spends several minutes covering their tracks before the machine is seized. None of the individual artefacts were hard to find. The harder problem was deciding how much to trust each one before writing a single sentence of conclusion.
The most useful row in the entire investigation is the one that says nothing happened: a batch script’s metadata looked suspicious at first glance, touched during the exact anti-forensics window, but a hash check against a known-clean template showed it was benign. Ruling that out took the same rigor as confirming anything else did, and it’s the difference between an investigation and a story that only ever confirms what it already suspected.
Approach
Phase 1
Establish the timeline
Windows Event Logs pinned the exact second a security log was cleared and a second account was created, both by the same admin session, minutes apart.
Phase 2
Correlate three independent sources
Every attribution-critical claim was checked against disk, memory, and network evidence rather than accepted from a single source, including recovering the stolen data directly from plaintext memory.
Phase 3
Rate every finding honestly
A corroboration matrix rated each finding conclusive only when two or more independent sources agreed, and marked the rest indicative rather than quietly upgrading their confidence.
Phase 4
Write the conclusion the evidence actually supports
The final report states its own limitations directly: TLS traffic that couldn't be decrypted, and memory pages already paged out before acquisition, rather than claiming a completeness the evidence didn't have.
18
Findings put through the corroboration matrix
15
Rated conclusive on two or more independent sources
1
Finding that flipped from suspicious to cleared