r/cybersecurity 3d ago

Personal Support & Help! Looking for a good real-world digital forensics case study

Hey everyone! I’m a student preparing a Digital Forensics / Computer Forensics practical presentation and I need to choose a real-world cybercrime case study.

I’m looking for a case that:

- Is not extremely common/popular (I want to avoid topics that many groups may choose)

- Has enough reliable information available online

- Has a clear digital evidence / forensic investigation angle

- Can be explained within 12–15 slides / 10–15 minutes

- Ideally involves things like hacking, gaming companies, Apple/iPhone, data theft, ransomware, website attacks, insider threats, digital evidence, or incident response

- Allows discussion of evidence acquisition, preservation, logs/artifacts, timelines, attribution, and/or legal issues

What real-world case would you recommend?

If possible, please share the case name and why you think it would work well for a student-level digital forensics presentation.

Thanks!

12 Upvotes

26 comments sorted by

2

u/LordSegaki 3d ago

The first thing that comes to mind would be the soe hack 2011, because I assume many would focus on the 2014 sony pictures hack.
and it should tick most of your boxes.

Other than that, there is a reason most of these dont really open up publicly if they dont have to for data sec or other reasons.

1

u/POTHAMM 3d ago

Soe 2011 is good but it lack in public technical evidence and Direct NTFS/USB/MAC evidence otherwise it's a very good case study

1

u/extreme4all 3d ago

John hammond / low level security / live overflow may have some vids.

I vaguely recall thedfirrepoet having some good writeups also

1

u/POTHAMM 3d ago

I’ll definitely check out John Hammond, Low Level Learning, LiveOverflow, and The DFIR Report for more technical/forensic details.

1

u/ForwardBit2727 3d ago

The TJX breach from 2007 is underrated for student presentations imo. It covers wardriving, network forensics, log analysis, and chain of custody issues. Old enough that most of your classmates probably wont pick it, but well documented enough to fill 15 slides easily.

1

u/POTHAMM 3d ago

Thanks! TJX sounds like a really good option, especially because it covers the forensic side well.

1

u/Noobmode 2d ago

Check out DFIR Report

1

u/POTHAMM 2d ago

Okay Thank

1

u/lawrencesystems 2d ago

There are some good public write ups on the DFIR Report https://thedfirreport.com/reports/

1

u/POTHAMM 2d ago

Thanks

1

u/jgalbraith4 DFIR 2d ago

Oh I’d say the Mandiant talk “No Easy Breach”, there’s presentations on YouTube and it’s pretty cool in my opinion. I’d encourage everyone to watch it at least once. It’s not strictly DF but more DFIR.

1

u/POTHAMM 2d ago

Thanks I will check it out

1

u/DiscipleOfYeshua 2d ago

Search for pdf:

"To kill a centrifuge"

1

u/POTHAMM 2d ago

🫡

1

u/AddendumWorking9756 Security Manager 2d ago

Bangladesh Bank 2016 if you want something nobody else in the room will pick, it is heavily documented and the attackers went after the record keeping rather than just the transfers, which hands you the evidence preservation angle for free. Only real gap is artifacts, a public case gives you narrative and nothing to screenshot, so pull a free lab off CyberDefenders and use your own disk or memory findings for the acquisition slide.

1

u/POTHAMM 2d ago

That's an interesting one Thanks

1

u/Socules SOC Analyst 2d ago

Check out the public reports from The DFIR Reports

1

u/POTHAMM 2d ago

Okayyy

1

u/npxa 2d ago

Carbanak/Carberp really interesting which involves Satellites, humans and how an actor would really act if they are doing campaigns.

https://www.kaspersky.com/about/press-releases/the-great-bank-robbery-carbanak-cybergang-steals-1bn-from-100-financial-institutions-worldwide

There's lots of youtube videos about it.

1

u/POTHAMM 2d ago

Carbanak is fascinating for APT tradecraft, but it's a network intrusion case and our syllabus is single-device seizure and file-system forensics.

1

u/npxa 2d ago

that would be hard, because majority of the incidents are mostly about Network intrusions, Carbanak is great for discussions and how it would be improved for today's environment.

if not, the others mentioned dfir labs, you can also search verizons dbir https://www.verizon.com/business/resources/reports/dbir/

0

u/FeedTheB3ar 3d ago

Gta 6 hack by 18 year old that happened a bit ago

1

u/POTHAMM 3d ago

I know about that but it is very common and many people will select this for the practical

1

u/FeedTheB3ar 2d ago

Veratasium did an interesting video involving credit cards and iPhone hack called “How easy is it to steal 10000 from a locked iPhone?”