Technical field guide

The sections below preserve the service-specific depth behind IT Forensics, edited for the current national practice and its documented engagement model. Methods are selected for the source, authorization, system state and assigned specialty. No single tool or artifact establishes a conclusion, and legal, regulatory or certification decisions remain with the responsible authority.

Enterprise IT Forensic Coverage

Enterprise IT environments are complex, heterogeneous, and distributed. Relevant evidence in a single matter may span workstations, servers, email platforms, cloud storage, collaboration tools, access control systems, and application databases spread across multiple physical locations, cloud regions, and organizational units. Enterprise IT forensics must account for distributed systems, different retention windows and shared administrative boundaries. Network traffic analysis can complement endpoint evidence when communications, remote access or data movement are material.

Windows forensics is the core of most enterprise IT forensic engagements. A Windows endpoint or server examination can cover:

  • Registry forensics: NTUSER.DAT, SYSTEM, SOFTWARE, SECURITY, and SAM hive analysis for user activity, program execution history, USB device connections, mapped network drives, and persistence mechanisms
  • Event log examination: Security, System, and Application event logs; PowerShell operational logs; WMI activity logs; Task Scheduler logs; and application-specific event sources, examined for logon events, privilege use, process creation, account management, and security policy changes
  • Prefetch and execution artifacts: Windows Prefetch files, ShimCache (AppCompatCache), Amcache.hve, and BAM/DAM entries documenting program execution history and last run times
  • Shell artifact analysis: LNK files, Jump Lists, and ShellBags documenting recently accessed files, folders, and removable media, including items accessed after deletion
  • Master File Table and journal analysis: NTFS MFT examination for file metadata, creation and modification timestamps, file system journal ($LogFile, $UsnJrnl) for file operation history including deleted file records
  • Memory artifact recovery: hibernation files (hiberfil.sys) and page files (pagefile.sys) examined for residual process memory, network connections, encryption keys, and user activity not recorded in persistent artifacts

Linux and Unix forensics covers server and workstation environments running Red Hat, CentOS, Ubuntu, Debian, SUSE, and other distributions. GDF examines bash history files, system log archives (/var/log), cron job configurations, SSH authorized keys, PAM authentication logs, sudo logs, user account and group files, and kernel audit logs. For Linux servers used in web hosting, database, or application roles, GDF also examines web server access and error logs, application logs, and installed software package histories.

Active Directory forensics is critical in enterprise breach matters, where attackers routinely compromise AD to achieve domain-wide access. GDF examines AD event logs for account creation and modification, group membership changes, privilege escalation, Kerberos ticket activity, LDAP queries indicating reconnaissance, and Golden/Silver Ticket attack indicators. Replication metadata in the AD database (NTDS.DIT) is examined for account history and attribute modification timestamps that survive log rotation.

Email system forensics covers Exchange Server (on-premises), Microsoft 365, Google Workspace, and legacy Lotus Notes and GroupWise environments. GDF performs forensic acquisition and examination of mailbox stores, transport logs, message tracking logs, and administrative audit logs to document sent, received, and deleted messages, forwarding rules, mailbox access by non-owners, and email delivery path reconstruction. For Microsoft 365 environments, GDF performs forensic collection using the Compliance Center and Graph API, examining Unified Audit Log records that capture user and administrator activity across the entire tenant.

Server and storage forensics covers physical and virtual servers, NAS devices, and SAN environments. GDF examines Windows Server and Linux system artifacts, application log files, backup catalogs, and storage system audit logs. For virtualization platforms including VMware vSphere and Microsoft Hyper-V, GDF preserves and examines virtual machine snapshots, vCenter event logs, and ESXi host logs to reconstruct activity in virtualized environments.

Database forensics addresses SQL Server, Oracle, MySQL, PostgreSQL, and MongoDB installations where database records are material to the matter. GDF examines database transaction logs for data modification history, access logs for query activity, backup catalogs to establish what data was present at specific points in time, and replication logs where the data flow between database instances is relevant.

Application log analysis covers enterprise applications including ERP systems (SAP, Oracle E-Business Suite), CRM platforms (Salesforce), document management systems, HR systems, and financial applications. Log records from these applications document user activity, data access, record modification, and administrative changes in terms that are directly meaningful to the legal questions being addressed.

GDF's IT Forensics Methodology

The IT-forensics workflow records material acquisition and examination actions so another qualified examiner can review the method and result. The methodology draws on standards established by NIST Special Publication 800-86 (Guide to Integrating Forensic Techniques into Incident Response), the Scientific Working Group on Digital Evidence (SWGDE), and ISO/IEC 27037 for digital evidence identification, collection, and preservation.

Physical-media acquisition begins with source-condition review and an appropriate write-protection method, with any source changes or limitations recorded. Forensic images may use E01, Ex01 or raw formats. The acquisition record identifies the format and documents one or more cryptographic integrity values appropriate to the source and method. For live systems where shutdown would destroy volatile evidence or business operations require continuity, GDF performs live forensic acquisition of running memory (RAM), active network connections, and running processes before proceeding to disk acquisition. The custody record tracks each source and material transfer from intake through examination and return or approved disposition.

For cloud environments, forensic acquisition uses platform-native collection methods: Microsoft 365 Content Search and eDiscovery collections, AWS CloudTrail export and S3 Object Inventory, Azure Activity Log export and Azure Monitor data collection, and Google Workspace Vault exports. The cloud-collection record should identify method, account, scope, date range, tool or API version, exceptions and available integrity values.

The examination phase is artifact-driven: GDF's analysts identify and prioritize the artifact categories most likely to answer the forensic questions posed by the matter, apply targeted examination to those artifacts, and document each reported finding with the specific artifact, file path or registry key, timestamp, and analyst methodology note. Anti-forensic indicators receive specific attention: file system timestamp manipulation (timestomping), Windows event log clearing, bash history deletion, secure deletion tool usage, and log file modification are all documented where evidence of them exists.

Collaboration with legal teams is a structured part of GDF's engagement process. Before examination begins, GDF works with counsel to define the scope of relevant artifacts in terms of the legal questions at issue, ensuring that the examination is targeted at what matters and that privilege considerations are properly managed. During examination, GDF provides interim findings briefings so that counsel can guide scope adjustments as the evidence picture develops. Final reporting produces both a technical report suitable for expert disclosure and an executive summary suitable for client briefing and settlement discussion.

When expert support is part of the engagement, reporting and workpapers can support deposition, motion practice or trial testimony as directed by counsel. Expert reporting should explain technical artifact behavior in plain language while retaining the detail needed for independent technical review.