← BACK TO THE LAB

THE KNOWLEDGE BASE / 14 FIELD GUIDES

Knowledge.
Made actionable.

Practical field guides for mobile and computer forensics, malware analysis, privacy and defense. Build a method you can explain.

14 entries
mobile01

iPhone forensics: from backup to supported finding

Define what an iOS backup contains, preserve its provenance and validate app artifacts before building a timeline.

OPEN FIELD GUIDE ↗
mobile02

Android forensics: artifacts, profiles and missing data

Investigate authorized Android exports with attention to encryption state, app versions, profiles and incomplete collection.

OPEN FIELD GUIDE ↗
computer03

Windows forensics: build a timeline you can defend

Correlate acquired event logs, filesystem records and application artifacts without confusing a trace with proof of user intent.

OPEN FIELD GUIDE ↗
computer04

macOS forensics: APFS, logs and application evidence

Plan a Mac examination around encryption, volume coverage, snapshots and the limits of retained logs.

OPEN FIELD GUIDE ↗
malware05

Malware analysis: a careful first examination

Identify and document a suspicious file without executing it. Build a static triage record and a clear escalation decision.

OPEN FIELD GUIDE ↗
mobile06

GrapheneOS hardening baseline

Profiles, app minimization, permission discipline, and a calm baseline that raises exploit cost.

OPEN FIELD GUIDE ↗
mobile07

High-risk phone checklist

Patch strategy, safer workflows, and what to do when you suspect targeting.

OPEN FIELD GUIDE ↗
mobile08

Backups you control

A simple encrypted backup plan with restore tests and minimum third-party exposure.

OPEN FIELD GUIDE ↗
comms09

Secure comms: what E2E does and does not protect

Clear mental model: encryption is strong, but endpoints and metadata still matter.

OPEN FIELD GUIDE ↗
comms10

On-prem messaging: keys, logs, governance

How to own your comms stack without turning it into a liability or a shadow archive.

OPEN FIELD GUIDE ↗
forensics11

Forensic imaging 101: chain of custody

Write blockers, hashing, notes, clean copies, and a defensible workflow.

OPEN FIELD GUIDE ↗
forensics12

SSD reality: TRIM, carving, and what’s recoverable

Why undelete differs on SSDs and what early imaging can still save.

OPEN FIELD GUIDE ↗
web13

Web hardening baseline: cookies + CSP + headers

Practical baseline that reduces common web risks and lowers exploitability.

OPEN FIELD GUIDE ↗
ops14

Incident response: containment-first playbook

Contain, preserve, eradicate, recover, learn. A calm workflow teams can follow.

OPEN FIELD GUIDE ↗

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC