SKILL 1: INCIDENT RESPONSE

1. INCIDENT RESPONSE, DIGITAL FORENSIC & ANALYSIS

Intro Paragraph

Incident Response & Digital Forensics is one of my strongest skill areas, developed through hands‑on labs involving evidence extraction, deleted‑file recovery, metadata analysis, and timeline correlation. These artifacts demonstrate my ability to investigate suspicious activity, analyze digital evidence, and produce clear, structured forensic reports. This skill directly aligns with cybersecurity and incident response job roles that require analytical reasoning, attention to detail, and the ability to interpret multi‑source digital information.

Artifact 1 — Mobile Device SMS Recovery (Text Message Analysis)

Description: This artifact shows my skill in mobile device forensics. I extracted SMS data from a phone image, located messages confirming a suspicious meeting, and preserved the recovered text thread as evidence.

Artifact 2 — Email Evidence Extraction (Forensic Analysis)

This artifact demonstrates my ability to extract and analyze email evidence using Magnet AXIOM and the Outlook PST recovered from the laptop image. I processed the PST file to review message content, metadata, and communication patterns relevant to the investigation, identifying emails between the suspect and RedRalph@gmail.com that referenced consulting payments, file uploads, and a meeting scheduled for February 15, 2026. All email content was preserved exactly as recovered and documented through screenshots, supporting the broader findings presented in the full forensic report.

Artifact 3 — Deleted File Recovery (ZIP Archive Metadata Analysis)

Description: This artifact demonstrates deleted‑file recovery and metadata analysis. I recovered deleted ZIP archives from unallocated space, analyzed metadata, and correlated browser logs showing uploads to ShareBoxCloud.net.

Case Identifier: DF‑2026‑1472 Submission Number: 001 Case Investigator: Jacob Asare, Digital Forensic Examiner Submitting Agency: Office of Special Investigations (OSI) Submitter: Assistant U.S. Prosecutor, National Security Division Date of Evidence Receipt: March 12, 2026 Date of Report: April 04, 2026

Artifact #9 — Digital Forensic Investigation Report

 Overview

This artifact demonstrates my ability to conduct a complete digital forensic investigation using industry‑standard tools and methodologies. The case simulates a real‑world scenario involving suspicious communications, deleted files, and potential data exfiltration. The investigation followed proper forensic procedure, including evidence acquisition, chain of custody, examination, analysis, correlation, and reporting.

This artifact aligns directly with job requirements for:

  • Cybersecurity Analyst
  • Digital Forensics Analyst
  • Incident Response Analyst
  • SOC Analyst

1. Evidence Items Examined

  • Item 1 — Laptop Computer
  • Make/Model: Dell Latitude 7420
  • Serial Number: DL 7420 A19X55
  • OS: Windows 10 Enterprise
  • Storage: 1 TB NVMe SSD
  • Condition: Seal intact, powered off
  • Item 2 — Mobile Phone
  • Make/Model: Apple iPhone 12 Pro
  • Serial Number: IP12 PR 9932K
  • iOS Version: 16.3
  • Condition: Powered on, locked; access gained via warrant‑approved biometric unlock

Forensic Objectives

  1. Identify suspicious communications.
  2. Recover deleted files.
  3. Determine whether data exfiltration occurred.
  4. Correlate evidence across devices.
  5. Produce a courtroom‑ready forensic report.

2. Forensic Examination Procedures

2.1 Laptop Examination

  • Forensic Imaging: FTK Imager 4.5; MD5 + SHA‑256 hash verification
  • File System Analysis: Autopsy 4.21, EnCase v8
  • Email Extraction: Outlook PST analyzed using Magnet AXIOM
  • Deleted File Recovery: Scalpel + Bulk Extractor to carve deleted ZIP archives containing fragments of classified material.
  • Browser Artifact Review: Browser History Examiner

2.2 Mobile Phone Examination

  • Logical Extraction: Cellebrite UFED 7.49
  • SMS/iMessage Review: Keyword searches (“Ralph,” “meeting,” “2/15”)
  • Contact List Analysis: AddressBook.sqlitedb
  • Application Data Review: Messaging apps, call logs, location history

3. Examination Results and Findings

3.1 Text Message Evidence (Mobile Phone)

  • Extracted SMS database.
  • Located messages between user and contact labeled “Red Ralph.”
  • Identified message confirming a meeting on 2/15/2026.

All message content is preserved exactly as recovered and is presented as screenshots

Exhibit 3.1 — Text Message Screenshot

3.2 Email Evidence Extraction (Laptop)

  • Loaded email archive into Autopsy.
  • Located messages referencing meetings and payments.
  • Identified sender: RedRalph@gmail.com.
  • Added relevant emails to the case as forensic artifacts.

Exhibit 3.2 — Email Screenshot

Message referencing “consulting payments” and “meeting on 2/15/2026.”

3.3 Deleted File Recovery

During forensic analysis, four deleted ZIP archives including “Briefing_Notes_SECURE.zip” and “Intel_Summary_Restricted.zip” were recovered from unallocated space.

Recovered fragments contained:

  • Classified briefing headers
  • Redacted intelligence summaries
  • Internal government document templates

Browser logs showed uploads to ShareBoxCloud.net on February 14, 2026, with filenames matching the deleted ZIP archives.

It remains unknown whether external parties downloaded the files.

Exhibit 3.3 — Autopsy View of Deleted ZIP Metadata

3.4 Timeline Analysis

  • Correlated email timestamps, text messages, and deleted file activity.
  • Determined that communications and file deletion occurred within the same 24‑hour period.
  • Established a sequence indicating possible data exfiltration prior to the meeting.

4. Chain of Custody Record

Evidence stored in OSI Digital Forensics Lab – Locker 3B. No additional transfers occurred.

5. Tools & Methods Used

  • Forensic Imaging
  • FTK Imager 4.5
  • File System & Artifact Analysis
  • Autopsy 4.21
  • EnCase v8
  • Magnet AXIOM
  • Deleted File Recovery
  • Scalpel
  • Bulk Extractor
  • Mobile Device Forensics
  • Cellebrite UFED 7.49
  • Browser Artifact Analysis
  • Browser History Examiner
  • Methodology
  • Write blocker usage
  • Hash verification
  • Analysis performed only on forensic copies

6. Executive Summary for Prosecutor

The forensic evidence establishes:

  • Direct communication between the suspect and “Red Ralph”
  • Confirmed meeting on February 15, 2026
  • Transfer of sensitive materials via unauthorized ZIP uploads
  • Payment discussions tied to document transfers
  • Intentional concealment, including deleted files and operational‑security instructions

The evidence supports potential charges involving:

  • Unauthorized disclosure of classified information
  • Conspiracy
  • Abuse of official position
  • Unauthorized use of government systems

All findings are supported by validated forensic tools and standard procedures.

7.  Conclusion

The forensic investigation uncovered:

  • Coordinated communication between the suspect and “Red Ralph.”
  • Evidence of deleted classified files.
  • Indicators of possible data exfiltration.

This artifact demonstrates my ability to:

  • Conduct forensic analysis
  • Recover deleted data
  • Analyze communication artifacts
  • Correlate multi‑device evidence
  • Document findings professionally
  • Produce a structured forensic report

These skills directly match job requirements for Cybersecurity Analyst, Incident Response Analyst, and Digital Forensics roles.