Writing Python Functions and Recursion Basics
# Writing Python Functions and Recursion Basics ## Defining a simple function A function packages reusable logic under a name. You define it with `def`, give it parameters, and …
21 published notes
# Writing Python Functions and Recursion Basics ## Defining a simple function A function packages reusable logic under a name. You define it with `def`, give it parameters, and …
# Synthesis: Core Forensic Principles in Practice Today's session connected the foundational **[[Core Principles of Forensic Science]]** with the procedural **[[The 5 Principles …
# Regex Fundamentals A foundational reference for regex syntax, with emphasis on practical application in digital forensics, log analysis, and tooling like [[Burp Suite]]. ## 1.…
# PowerShell as an Acquisition Engine PowerShell is described in Hosmer's book as a powerful **acquisition engine** for digital investigations. Its role is to gather raw informat…
# PowerShell Cross-Platform PowerShell was originally **Windows-only** because it was built on the .NET Framework. In 2016, Microsoft open-sourced PowerShell and rebuilt it on .N…
PowerShell ISE (Integrated Scripting Environment) is a free Windows application that provides a workspace for experimenting with and writing [[PowerShell CmdLets]] and scripts. It…
In network forensics, the **footprint** is the impact an investigator leaves on the systems under examination. Every interaction with a live system modifies it in some way—just as…
**Direct evidence** is testimony from a **direct witness** who personally observed the act or event in question. It is based on firsthand human perception rather than inference fr…
**Hearsay** is an out-of-court statement offered to prove the truth of the matter asserted. Under the **U.S. Federal Rules of Evidence (FRE)**, hearsay is generally **not admissib…
**Business records** are documents or data that an enterprise routinely generates and retains as part of its normal operations, and that are considered accurate enough to guide ma…
**Network-based digital evidence** is digital evidence produced as a result of **communications over a network**. It is a subset of **[[Digital Evidence]]**, but it is distinguish…
**Real evidence** is a physical, tangible object that played a relevant role in the event being investigated. It is the kind of evidence a jury can see and touch, such as the murd…
[[Circumstantial Evidence]] is evidence that does **not directly prove a conclusion**, but can be linked with other evidence to **deduce** what happened. It requires inference and…
**[[Best Evidence]]** is the **best available evidence that can be produced in court** to prove the content of a writing, recording, or photograph. Under the **U.S. Federal Rules …
# Investigative Event Log Discovery Strategy When you need to find events in Windows but do not yet know the exact log, event ID, or provider, follow a repeatable discovery proce…
# PowerShell Get-Help Parameter Discovery Use `Get-Help` with the `-Parameter` switch to learn about a specific parameter of a CmdLet. ```powershell Get-Help Get-ChildItem -Para…
This section introduces three PowerShell CmdLets used to examine network settings on a Windows system. Unlike the legacy Windows Command Line, PowerShell exposes network configura…
A **Service Filter** in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of ap…
# Get-Member CmdLet `Get-Member` is a PowerShell discovery CmdLet that reveals the **members** (properties, methods, events, and other object attributes) of any object piped into…
# PowerShell + Python Acquisition Pipeline A practical exercise pattern from the book's philosophy: use **PowerShell** for acquiring raw data from Windows systems and **Python** …
PowerShell provides several ways to replace strings inside files using the standard **verb-noun** [[CmdLet]] pairs `Get-Content` and `Set-Content`, plus the `-replace` operator. …