FeaturedCybersecurity
Digital Forensics Investigation - Caelus Engineering Case
Investigated a simulated insider data-exfiltration case by correlating disk, memory, registry, browser, email, USB, and network artifacts into an evidence-led incident timeline and remediation plan.

Summary
Project context
A cybersecurity case study focused on reconstructing suspected insider data exfiltration at Caelus Engineering without publishing sensitive evidence files.
Problem / goal
The investigation needed to determine whether data was accessed, staged, concealed, or exfiltrated, then translate technical evidence into defensible actions for a security team.
My role
Digital Forensic Investigator for a simulated cybersecurity case study.
What I personally contributed
- Correlated Windows registry, browser, email, USB, memory, disk, and packet-capture artifacts into a single investigation timeline.
- Used hashing, artifact cross-checking, and timeline analysis to distinguish stronger indicators from background system noise.
- Translated findings into recommendations for identity controls, endpoint monitoring, DLP, log preservation, forensic imaging, and HR or legal follow-up.
Technical approach
- Reviewed SAM and SOFTWARE hives, Chrome artifacts, LNK files, pagefile strings, email evidence, USBSTOR, SetupAPI, and packet captures.
- Correlated timestamps and hashes across sources to test whether independent artifacts supported the same incident narrative.
- Documented findings as a safe case study that communicates indicators and remediation without exposing evidence files.
Key features
- Host, memory, browser, email, USB, and network artifact review.
- Cross-source incident timeline reconstruction.
- Evidence integrity checks using MD5 and SHA256 hashing.
- Actionable remediation plan for identity, endpoint, logging, DLP, and legal follow-up.
Impact / results
- Identified indicators consistent with internal data exfiltration and concealment, including post-loss file access, bulk cloud downloads, USB activity, deleted archives, and monitoring-tool traces.
- Produced prioritized recommendations covering MFA, endpoint USB monitoring, DLP controls, cloud-log preservation, forensic imaging, and hash comparison.
What I learned
- Forensic conclusions are stronger when independent timeline, registry, browser, network, email, and removable-media artifacts support the same story.
- Useful security reporting separates observed evidence, analytical inference, and recommended response actions.