THE KNOWLEDGE BASE / 14 FIELD GUIDES
Knowledge.
Made actionable.
Practical field guides for mobile and computer forensics, malware analysis, privacy and defense. Build a method you can explain.
iPhone forensics: from backup to supported finding
Define what an iOS backup contains, preserve its provenance and validate app artifacts before building a timeline.
OPEN FIELD GUIDE ↗mobile02Android forensics: artifacts, profiles and missing data
Investigate authorized Android exports with attention to encryption state, app versions, profiles and incomplete collection.
OPEN FIELD GUIDE ↗computer03Windows forensics: build a timeline you can defend
Correlate acquired event logs, filesystem records and application artifacts without confusing a trace with proof of user intent.
OPEN FIELD GUIDE ↗computer04macOS forensics: APFS, logs and application evidence
Plan a Mac examination around encryption, volume coverage, snapshots and the limits of retained logs.
OPEN FIELD GUIDE ↗malware05Malware analysis: a careful first examination
Identify and document a suspicious file without executing it. Build a static triage record and a clear escalation decision.
OPEN FIELD GUIDE ↗mobile06GrapheneOS hardening baseline
Profiles, app minimization, permission discipline, and a calm baseline that raises exploit cost.
OPEN FIELD GUIDE ↗mobile07High-risk phone checklist
Patch strategy, safer workflows, and what to do when you suspect targeting.
OPEN FIELD GUIDE ↗mobile08Backups you control
A simple encrypted backup plan with restore tests and minimum third-party exposure.
OPEN FIELD GUIDE ↗comms09Secure comms: what E2E does and does not protect
Clear mental model: encryption is strong, but endpoints and metadata still matter.
OPEN FIELD GUIDE ↗comms10On-prem messaging: keys, logs, governance
How to own your comms stack without turning it into a liability or a shadow archive.
OPEN FIELD GUIDE ↗forensics11Forensic imaging 101: chain of custody
Write blockers, hashing, notes, clean copies, and a defensible workflow.
OPEN FIELD GUIDE ↗forensics12SSD reality: TRIM, carving, and what’s recoverable
Why undelete differs on SSDs and what early imaging can still save.
OPEN FIELD GUIDE ↗web13Web hardening baseline: cookies + CSP + headers
Practical baseline that reduces common web risks and lowers exploitability.
OPEN FIELD GUIDE ↗ops14Incident response: containment-first playbook
Contain, preserve, eradicate, recover, learn. A calm workflow teams can follow.
OPEN FIELD GUIDE ↗No matching guides. Try a different topic or search term.