Host & Storage Analysis
Recover, examine, and correlate persistent evidence from disks, file systems, Windows artefacts, browsers, the Registry, and event logs.
Move from image to finding
Select each stage to follow a repeatable host-analysis workflow.
Work from a verified image or controlled copy, retain the original evidence, and record the tools and time settings used.
Ask: Can I return to the same starting point?Find your analysis path
Choose the evidence question that most closely matches your starting point.
Mount or examine an image safely, then identify recoverable files and useful volumes.
Build your foundation
Open the concept guide that matches the evidence you are examining.
Examine images and recover data without changing the source.
Interpret records created by Windows and user activity.
Use metadata and journals to reconstruct file activity.
Connect history, downloads, cookies, and cached content.
Interpret keys and values in their user and system context.
Filter, validate, and correlate Windows event records.
Choose a tool by evidence
Begin with one focused tool and record the version, inputs, settings, and outputs.
Examine a disk image through an integrated case workflow and review multiple artefact types.
Check analysis readiness
Confirm that your working basis and interpretation context are recorded.