Digital › Module 9 › Lesson 4
Lab — Case
Full case lab on $DFIR_LAB — dataset inventory, workflow walk, report from timeline, pitfalls review.
Visual · t26_case_lab
Lab: end-to-end case on YOUR $DFIR_LAB practice dataset. Original Cyberlium.
Opening
Run one practice case intake to handoff — every station documented, every exhibit hashed, every pitfall checked.
On YOUR $DFIR_LAB authorized practice dataset: (1) dataset inventory card with verified hash; (2) workflow diagram with UTC milestones filled; (3) analysis summary linking Modules 4–7 artifacts; (4) Module 8 report lab pack updated or merged; (5) pitfalls checklist with five near-miss fixes; (6) handoff index chmod 600; (7) integrity — no unauthorized sources, no tampering, practice label if brief requires. Minimum one net/logs correlation and one timeline hypothesis with falsification. Revert mounts and snapshot after if brief requires.
1. End-to-end deliverables
Inventory + workflow + report + pitfalls + index — single case ID.
Cross-link all exhibit IDs across modules.
Command guide
Try these commands — End-to-end deliverables
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Autopsy + CFReDS — https://www.autopsy.com/ (ingest authorized NIST images) Volatility samples — https://www.volatilityfoundation.org/ (authorized memory samples literacy) SANS FOR — https://www.sans.org/cyber-security-skills/digital-forensics/ (training path)
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export LAB_DFIR=${LAB_DFIR:-$HOME/cyberlium-lab/t26-dfir}
cat > "$LAB_DFIR/notes/next-lab-steps.txt" <<'EOF'
next steps (authorized only):
- NIST Hacking Case image in isolated VM + write blocker
- digitalcorpora M57-Patents for timeline practice
- Volatility on CFReDS memory sample — not production RAM
- stay in $HOME/cyberlium-lab/t26-dfir/ for course exercises
EOFCommand — copy this
grep -E 'authorized|not production|cyberlium-lab' "$LAB_DFIR/notes/next-lab-steps.txt" curl -sS https://www.volatilityfoundation.org/ | head -5
Primary tools to practice this lesson: curl, grep. Reference sites: Autopsy + CFReDS (https://www.autopsy.com/); Volatility samples (https://www.volatilityfoundation.org/); SANS FOR (https://www.sans.org/cyber-security-skills/digital-forensics/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Quality bar
No station skipped on paper — honest N/A if brief omitted memory branch.
Peer self-review: five pitfalls scanned before seal.
3. Integrity
$DFIR_LAB only; refused sources scan zero hits.
Share-safe export redacts PII — mentor pack complete.
4. What you ship: case lab pack
Full case intake-to-handoff + report + pitfalls — chmod 600.
5. What you record before the next lesson
Case lab pack path.
6. Wrong vs right: tampering evidence vs chain of custody
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Case lab built on leaked enterprise disk without authorization.
Right
Case lab pack on $DFIR_LAB practice dataset. Next: quiz.
Mission: case lab
1) Dataset inventory verified. 2) Workflow milestones UTC. 3) Report pack merged. 4) Pitfalls checklist; chmod 600 index.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Honest N/A for memory branch?”
Knowledge Check
APPLY: Case lab requires:
Multiple choice
Knowledge Check
APPLY: True or False: Unauthorized sources OK if interesting.
True or False
Knowledge Check
APPLY: Handoff index lists:
Multiple choice