Cyberster Blue Team Internship – Week 12
This week marked the completion of Phase Two of my DFIR capstone, a full-scale insider threat investigation built around the M57.biz case. Unlike earlier labs, I was given a primary disk image, a raw memory capture, and two USB drive images, and had to work through the investigation from evidence handling to the final forensic report without knowing upfront what had happened.
Here's what I worked on:
• Set up a multi-source Autopsy case, hashed the evidence with MD5 and SHA-256, and ran a full ingest across the disk and both USB images.
• Established a system baseline from the SOFTWARE, SYSTEM, and SAM registry hives, including hostname, timezone, installed software, and user account activity.
• Profiled the subject's normal role and working pattern using file system artefacts, LNK files, and Recent Items.
• Installed and configured Volatility 3 to analyse the raw memory image for processes, process relationships, network connections, and command line activity.
• Correlated memory findings with disk evidence to build a consistent picture of the system's state.
• Examined both USB drives, recovered deleted files, and compared timestamps across disk and USB evidence to trace data movement.
• Reviewed email and browser artefacts, including working around legacy file formats that Autopsy's automated parsers could not process.
• Built a Master Event Sequence normalised to a single timezone to reconstruct the incident from start to finish.
The biggest lesson from this capstone was how little any single piece of evidence tells you on its own. Disk, memory, USB, and email artefacts each answer a different part of the investigation. Correlating them is what allows a more complete and defensible picture to emerge.
I also learned the importance of being honest about investigative limitations. Understanding what the evidence proves, what it suggests, and what remains an open gap is a core part of credible forensic analysis.
Overall, Week 12 strengthened my practical experience with Autopsy, Volatility 3, Registry Explorer, memory forensics, USB and removable media analysis, and cross-artefact timeline correlation.
With the completion of this capstone, I've officially completed my Internship with Cyberster. I'm grateful for the practical experience, challenges, and knowledge I've gained throughout the internship.
A special thank you to my instructor, Sir Abdullah Zia, for his continued guidance and support throughout this internship.
Cyberster
#CyberSecurity #DigitalForensics #DFIR #BlueTeam #MemoryForensics #IncidentResponse #Autopsy #Volatility #RegistryForensics #CybersterInternship #InformationSecurity #DigitalInvestigation