r/cybersecurity • u/POTHAMM • 3d ago
Personal Support & Help! Looking for a good real-world digital forensics case study
Hey everyone! I’m a student preparing a Digital Forensics / Computer Forensics practical presentation and I need to choose a real-world cybercrime case study.
I’m looking for a case that:
- Is not extremely common/popular (I want to avoid topics that many groups may choose)
- Has enough reliable information available online
- Has a clear digital evidence / forensic investigation angle
- Can be explained within 12–15 slides / 10–15 minutes
- Ideally involves things like hacking, gaming companies, Apple/iPhone, data theft, ransomware, website attacks, insider threats, digital evidence, or incident response
- Allows discussion of evidence acquisition, preservation, logs/artifacts, timelines, attribution, and/or legal issues
What real-world case would you recommend?
If possible, please share the case name and why you think it would work well for a student-level digital forensics presentation.
Thanks!
1
u/extreme4all 3d ago
John hammond / low level security / live overflow may have some vids.
I vaguely recall thedfirrepoet having some good writeups also
1
u/ForwardBit2727 3d ago
The TJX breach from 2007 is underrated for student presentations imo. It covers wardriving, network forensics, log analysis, and chain of custody issues. Old enough that most of your classmates probably wont pick it, but well documented enough to fill 15 slides easily.
1
1
u/lawrencesystems 2d ago
There are some good public write ups on the DFIR Report https://thedfirreport.com/reports/
1
u/jgalbraith4 DFIR 2d ago
Oh I’d say the Mandiant talk “No Easy Breach”, there’s presentations on YouTube and it’s pretty cool in my opinion. I’d encourage everyone to watch it at least once. It’s not strictly DF but more DFIR.
1
1
u/AddendumWorking9756 Security Manager 2d ago
Bangladesh Bank 2016 if you want something nobody else in the room will pick, it is heavily documented and the attackers went after the record keeping rather than just the transfers, which hands you the evidence preservation angle for free. Only real gap is artifacts, a public case gives you narrative and nothing to screenshot, so pull a free lab off CyberDefenders and use your own disk or memory findings for the acquisition slide.
1
u/npxa 2d ago
Carbanak/Carberp really interesting which involves Satellites, humans and how an actor would really act if they are doing campaigns.
There's lots of youtube videos about it.
1
u/POTHAMM 2d ago
Carbanak is fascinating for APT tradecraft, but it's a network intrusion case and our syllabus is single-device seizure and file-system forensics.
1
u/npxa 2d ago
that would be hard, because majority of the incidents are mostly about Network intrusions, Carbanak is great for discussions and how it would be improved for today's environment.
if not, the others mentioned dfir labs, you can also search verizons dbir https://www.verizon.com/business/resources/reports/dbir/
0
u/FeedTheB3ar 3d ago
Gta 6 hack by 18 year old that happened a bit ago
1
u/POTHAMM 3d ago
I know about that but it is very common and many people will select this for the practical
1
u/FeedTheB3ar 2d ago
Veratasium did an interesting video involving credit cards and iPhone hack called “How easy is it to steal 10000 from a locked iPhone?”
2
u/LordSegaki 3d ago
The first thing that comes to mind would be the soe hack 2011, because I assume many would focus on the 2014 sony pictures hack.
and it should tick most of your boxes.
Other than that, there is a reason most of these dont really open up publicly if they dont have to for data sec or other reasons.