Legal Cyber Academy
Blog or channelFreeSuperseded or dormant

Hacking Exposed Computer Forensics Blog

David Cowen

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Superseded or dormant

Superseded, replaced or no longer being updated. The archive may still be worth reading, but do not cite it as current practice.

What it is

David Cowen's daily-blog project, running to over 800 numbered posts plus the Sunday Funday challenges, Solution Saturday write-ups and the Forensic Lunch video series, covering Windows artifacts, NTFS internals, cloud logging and DFIR programming.

Who it is for, and when

Dormant — the last post is #815, dated 21 April 2025, about seventeen months old — but the archive is unusually valuable because the daily format captured working-out rather than polished conclusions. The NTFS and USN journal series and the Sunday Funday answer threads are still the clearest public treatment of several file-system questions you will be asked to explain on the stand.

What it does not cover

Nothing published since April 2025, so no coverage of current tool versions or recent Windows and cloud changes; the archive is also heavily Windows-focused with little mobile or macOS content.

Go to the source

Open at hecfblog.com (opens in a new tab)

https://www.hecfblog.com/

Details

Type
Blog or channel
Written for
Working examinerAdvancedWorking examiner, Advanced
Author
David Cowen
Topics
windows, file-systems, registry, timeline, cloud, scripting
Checked at source
  • An open-source Python framework that extracts timestamps from hundreds of artefact types across a disk image or directory and writes them into a single normalised storage file. log2timeline is the extraction front end; psort and psteal filter, sort, and export the result.

  • An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.

  • A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.

  • An open-source Perl tool that runs a library of plugins against Windows registry hives and reports the values that matter forensically, with each plugin documenting the key it read. RegRipper 3.0 is the current line and the repository remains actively updated.

  • A download library of reference posters and cheat sheets, of which 37 are filed under Digital Forensics and Incident Response — artifact maps, timestamp reference tables, tool command references and filter syntax sheets. Download requires a free SANS account rather than payment.