Reading paths
Four ordered sequences through the reference library, each with a reason for every step and an honest note on what the path itself will not give you.
A bibliography tells you what exists; it does not tell you what to read first. These paths do. Each step names one entry in the library, says why it comes at that point, and can be read on its own — so you can stop after step three and still have gained something coherent rather than a third of a syllabus.
New to digital forensics
You have no forensics background and want the shape of the whole field before you specialise.
This is the order that gets you from nothing to genuinely useful without wasting money. It goes breadth first, then the rules you will be held to, then one mechanism deep enough to defend, then a tool, then real practice data. Reckon on three to six months of evenings if you are working full time; the first three steps are free and take a fortnight.
Why here: One pass over the entire field — lab, acquisition, artefacts, reporting, testimony — so that every later step has somewhere to attach. Read it for the map, not for the tool walkthroughs.
The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.
Why here: Four principles on a page. Whatever jurisdiction you end up in, this is the shortest statement of what handling evidence properly means, and it is free.
The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.
Electronic Crime Scene Investigation: A Guide for First Responders, Second Edition
Standard or guidanceFreeWhy here: Turns those principles into what someone actually does at a scene — what to photograph, what to unplug, what never to touch. Step two is theory, step three is hands.
NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.
Why here: The process model you will keep reusing: collect, examine, analyse, report, with the reasoning for each phase. This is where you learn why the order matters.
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.
Why here: Now go deep once. Understanding a single file system at byte level is what separates someone who reads tool output from someone who can say why the tool is right.
A byte-level reference to volume and file system structures: DOS/MBR, GPT, Apple, BSD and Solaris partitioning, then the on-disk layout and recovery behaviour of FAT, NTFS, Ext2/Ext3 and UFS. Each file system gets both a conceptual model and the actual data structure field listings.
Why here: A real tool, free, that implements the model you just read. Run it against the images in the next two steps rather than against your own laptop.
An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.
Why here: Practice data with known ground truth, from NIST. The point is that you can check your answer — practising on data whose contents you do not know teaches you nothing about whether you were right.
A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.
Why here: Scenario images with published write-ups. Work the case, then compare your reasoning with the author's; the gap between the two is the actual lesson.
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
Why here: Subscribe now and keep reading it. This field moves through blog posts and tool releases far faster than through books, and one weekly digest is the cheapest way to not fall behind.
A weekly roundup of everything published in digital forensics that week — blog posts, tool releases, presentations, podcasts and job listings — with links and one-line summaries.
What this path will not do: It makes you literate, not qualified. None of this is a credential, none of it lets you sign a report, and it deliberately teaches one file system rather than all of them — depth in mobile, cloud and memory comes after, from the paths and entries those subjects have of their own.
A lawyer who has to cross-examine an examiner
You are a litigator facing a digital forensics expert and you need to know where the soft ground is.
You are not trying to become an examiner. You are trying to know, precisely, what a competent one should have done, what the record should show, and which of their conclusions the science will not carry. Two focused days gets you through the free material; the paid items matter only if the case turns on method.
Why here: Start where the judge starts. The fourth edition added a computer-science reference guide, and knowing the framework the bench is reading from is worth more than any single technical fact.
The judiciary's own reference work on scientific and technical evidence, produced jointly by the Federal Judicial Center and the National Academies, made up of reference guides written by scientists and judges on individual fields plus chapters on the judge's gatekeeping role. The fourth edition rewrites every guide carried over from 2011 and adds new guides on eyewitness identification, computer science, and artificial intelligence.
Why here: The 2023 amendment made the proponent's burden explicit and told courts to police overstatement. Read the rule text and the amendment date — a surprising number of experts have not.
The federal admissibility rule for expert testimony. The 2023 amendment moved the burden into the rule text — the proponent must demonstrate to the court that it is more likely than not that each of the four requirements is met — and rewrote subsection (d) so that the opinion must reflect a reliable application of the principles and methods to the facts of the case.
Federal Rules of Evidence 902(13) and 902(14): self-authentication of machine-generated records and copied electronic data
Standard or guidanceFreeWhy here: Learn how machine-generated and copied data get in without a witness, and therefore what the certification has to say. Half of digital-evidence authentication fights are decided here.
Two subsections of Rule 902 that let a party authenticate electronic evidence by written certification instead of live testimony: 902(13) covers a record generated by an electronic process or system that produces an accurate result, and 902(14) covers data copied from an electronic device, storage medium, or file when authenticated by a process of digital identification. Both borrow the certification and pretrial notice machinery of Rule 902(11).
Why here: Written by a judge and two evidence scholars specifically on authenticating digital evidence, and free. This is the piece that connects the rules above to what the exhibits in your case actually are.
A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.
Why here: The free statement of what collection should have looked like. Compare it line by line against the other side's report and note every step the report does not mention.
SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.
Why here: NIST's own scientific-foundation review of digital investigation techniques. Cite it when you need an authoritative statement of what the discipline can and cannot support.
NIST's scientific foundation review of digital forensics, examining the peer-reviewed literature, academic material and practitioner guidance behind digital investigation techniques. It concludes the techniques rest on established computer science methods and are reliable when properly applied, while naming specific limits.
Why here: The paper that named error, uncertainty and loss in digital evidence. It gives you the vocabulary to ask about confidence in a way the witness cannot dismiss as a layman's question.
Eoghan Casey's paper in IJDE 2002, Volume 1, Issue 2, which took apart the then-common claim that digital evidence is exact and argued that error, uncertainty and data loss are intrinsic to it and must be stated. It proposed expressing a level of certainty in conclusions rather than asserting them flatly.
Standardization of forming and expressing preliminary evaluative opinions on digital evidence
Paper or reportPaywalledWhy here: How a forensic opinion should be expressed and bounded. Useful precisely when the opposing expert has stated a conclusion more strongly than their method allows.
Eoghan Casey's paper in Forensic Science International: Digital Investigation on how digital forensic practitioners should form and state evaluative opinions, importing the strength-of-evidence reasoning used elsewhere in forensic science into digital evidence and proposing a standardised scale for preliminary opinions.
Why here: The other side of the table: what the expert was trained to do under cross. Read it last, as reconnaissance.
A book for technologists who are about to testify: how the gatekeeping standards work, how to establish and defend qualifications, how to present technical material to a lay fact-finder, and where technical witnesses habitually lose credibility.
What this path will not do: It is US-federal in its legal spine and says nothing about state rules of evidence or non-US procedure. It also will not make you technical enough to argue about an artefact on your feet — it tells you which questions to ask, not how to answer them.
Moving from IT into DFIR
You already run systems and know Windows, networks and logs. You want to do incident response and forensics.
Your administration background is worth more than you think and it will also mislead you: the habits that keep systems running — reboot it, patch it, clear the log — destroy the evidence. This path re-points what you know at the question of what happened, and it is deliberately tool-heavy because that is how the work is actually done. Three to four months alongside a day job.
Why here: First, unlearn the operations reflex. This is the process that keeps evidence intact while you still fix the incident, and the phase order is the whole point.
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.
Why here: The end-to-end investigation, written for people who will be doing it under time pressure with management asking for an answer.
The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.
Why here: Windows artefacts as an examiner sees them, from someone who documents his reasoning rather than just his findings. The analysis process chapters matter as much as the artefact lists.
An artifact-by-artifact working guide to Windows examination: Volume Shadow Copies, file metadata, registry analysis, malware detection on a dead box, timeline construction and artifact correlation. Written as a bench manual rather than a textbook.
Why here: The parsers that turn those artefacts into evidence. Start with the shellbag, jumplist and LNK parsers and learn what each artefact proves and does not prove.
A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.
Why here: Then build a super-timeline. Correlating many artefact sources on one clock is the skill that most distinguishes DFIR from log reading.
An open-source Python framework that extracts timestamps from hundreds of artefact types across a disk image or directory and writes them into a single normalised storage file. log2timeline is the extraction front end; psort and psteal filter, sort, and export the result.
Why here: Memory is where the malware you cannot find on disk lives. Learn the plugins against a known-good sample before you need them on a live incident.
An open-source memory analysis framework that parses RAM images into processes, network state, loaded modules, injected code, registry hives resident in memory, and command history. Volatility 3 is the actively developed line; Volatility 2 is legacy and should not be the basis of new work, though its documentation is still used for plugin comparison.
The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory
BookPaidWhy here: Read this alongside the tool, not before it. It is the book that explains the operating-system structures the plugins are walking.
Memory acquisition and analysis across Windows, Linux and macOS, written by the people who built Volatility: process and kernel structures, code injection, rootkit detection, registry and event logs recovered from RAM, the GUI subsystem, network state, and case studies.
Why here: Scale it. Collecting the same artefacts across a fleet and hunting on them is the difference between examining one machine and handling an incident.
An open-source endpoint visibility and DFIR platform built around VQL, a query language for collecting artefacts, monitoring events, and hunting across a fleet of agents. Development is sponsored by Rapid7, with the code still published under the Velocidex organisation.
Why here: Keep it open while you work. Watching one artefact taken end to end on video is the fastest way to close a specific gap, and the channel is free.
A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.
What this path will not do: It is Windows-endpoint-centric, which is where the volume of work is, and covers mobile and cloud barely at all. It also teaches response, not litigation — a path that gets you competent at finding the answer still leaves the reporting and testimony side untouched.
Preparing for a certification
You have an exam booked — vendor or vendor-neutral — and want the underlying knowledge rather than a cram deck.
Certification exams test procedure, artefact knowledge and tool competence, in roughly that order, and they are unforgiving about the parts most people skip: hashing, write-blocking, documentation, and being able to say why a result is reliable. This path builds the substance an exam draws on. Allow two to three months, and time yourself on the practice material.
Why here: Exam-shaped breadth across the whole field, with end-of-chapter questions. Use it to find the topics you cannot currently explain out loud.
The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.
Why here: Procedure questions are where candidates lose easy marks. Four principles, memorised, answer a surprising number of them.
The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.
Why here: Acquisition is the most heavily examined single topic: write-blocking, verification, hashing, documentation. This is the free authority on it.
SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.
Why here: The file-system section of any serious exam comes straight from here — allocation, deletion, slack, metadata. Learn it once at depth rather than as flashcards.
A byte-level reference to volume and file system structures: DOS/MBR, GPT, Apple, BSD and Solaris partitioning, then the on-disk layout and recovery behaviour of FAT, NTFS, Ext2/Ext3 and UFS. Each file system gets both a conceptual model and the actual data structure field listings.
Why here: Registry questions are specific and memorisable, and this is where the specifics are correct and explained rather than listed.
The standing treatment of the Windows registry as evidence: hive file structure, the tools and process for parsing it, then separate analysis passes over the system hives and the user hives, with case studies and RegRipper.
Why here: Mobile now carries real weight in most syllabi, and the acquisition-method distinctions — logical, file system, physical — are exactly what gets asked.
A device-by-device walkthrough of mobile acquisition and analysis: iOS and Android internals and file systems, logical and physical extraction, app and SQLite artifacts, cloud extraction, mobile malware and reporting.
Why here: Practical components require tool fluency under time pressure. Autopsy is free, so you can build that fluency before you sit in front of the suite the exam uses.
An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.
Why here: Timed, graded scenario labs. The point of this step is not learning new artefacts but finding out how you perform when the clock is running.
A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
Why here: Last two weeks only. Free posters are the right density for revision once the understanding is already there — and exactly the wrong place to start.
A download library of reference posters and cheat sheets, of which 37 are filed under Digital Forensics and Incident Response — artifact maps, timestamp reference tables, tool command references and filter syntax sheets. Download requires a free SANS account rather than payment.
What this path will not do: It deliberately lists no certification and no exam guide, because a body's own objectives are the only reliable syllabus and they change between versions — read those first and use this for the underlying knowledge. Nothing here is affiliated with or endorsed by any certifying body.