Menu
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact
  • Home
  • Brett's Blog
  • My Books
  • Courses
  • About Me
  • Contact

Brett Shavers | forensics & things

Brett's Ramblings

Subscribe to blog
Unsubscribe from blog
Settings
Sign In
If you are new here, Register
  • Forget Username
  • Reset Password
Font size: + –
Subscribe to this blog post Unsubscribe
Report
Print
2 minutes reading time (394 words)

X-Ways Forensics Cheat Sheet and “Three Things”

Digital Forensics
Brett Shavers
Monday, 13 August 2018
13518 Hits
0 Comments

I had the pleasure of talking to a group of high schoolers about digital forensics recently. After showing some neat things to get interest, the fun really started with getting hands-on demonstrations. I decided to use X-Ways Forensics for the hands-on fun (tip: be sure to register your dongles with X-Ways Forensics insurance feature).

Since the talk time was limited, I broke X-Ways Forensics down to three things:

  1. Add the source
  2. Process the data
  3. Find the evidence

Breaking a topic into three parts makes it easier to understand and learn, especially for new, complex, or new and complex topics. X-Ways Forensics can certainly fit in the new and complex area. However, when you look at X-Ways Forensics or any digital forensics application, they all break down into the same three functions of adding the source, processing the data, and finding the evidence. Actually, if you can break down anything you teach into three parts, you'll be more effective in getting your topics across to your audience (be it a supervisor or an auditorium of students).

Based on these three functions, I created a X-Ways Forensics cheat sheet for the students which I think will benefit anyone using X-Ways Forensics. What I wanted to show visually is that there are “x” ways of using X-Ways Forensics. For many of the functions, you can get there in one, two, three, four, or more different routes (via menu, icon, right click, command line, x-tensions, shortcuts, or etc…).

Perhaps this is a reason why X-Ways Forensics seems to be initially overwhelming, but when looked at differently, will is seen as not “how do you make sense of this”, but more as “of course this is how it works”.  This is how I look at any software, especially DFIR software since few are overtly designed to be intuitive, and some appear to be designed intentionally as counter-intuitive.

How to learn X-Ways Forensics

Self-learning can be painful and slow. For anyone thinking about using X-Ways Forensics, or wanting to learn more about it if they are currently using it, here are suggestions ranked from free to not-free to do.

  • Read the manual. Free
  • Read the book.  Inexpensive
  • Take the online practitioner's course. Half price this week at $29.99!
  • Take the official X-Ways Forensics course. 

Half price registration expires August 29, 2018.  (30 day access) Over 13 hours with a certificate of completion! 

Tweet
Share on Pinterest
0
How to Start a Digital Forensic Lab in Your Police...
Brett's opinion on DFIR notes and note-taking

About the author

Brett Shavers

Brett Shavers

 

Comments

No comments made yet. Be the first to submit a comment
Guest
Sunday, 24 September 2023

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://brettshavers.com/

direct link

Find Brett!

 

CounterSocial

DFIR Training

Be sure to check out my DFIR Training website for practically the best resources for all things Digital Forensics/Incident Response related.


Brett's blog

Most popular posts

The truth hurts. But the other option is worse.
56898 Hits
Read More
When Being Self-Taught Goes Wrong
55442 Hits
Read More
RegRipper
53131 Hits
Read More
Game of Thrones, DFIR Style
47983 Hits
Read More
DFIR is a mindset, not a skillset.
43228 Hits
Read More
The Five Stages of the DFIR Career Grief Cycle
41018 Hits
Read More
Should you improve your DFIR skills on your personal time?
38982 Hits
Read More
The spark of a book
36872 Hits
Read More
Well, I didn’t see that coming…
36065 Hits
Read More
Eat your broccoli first
33678 Hits
Read More
The forensic process begins before processing forensics begins
33007 Hits
Read More
Only race cars should burnout.
31148 Hits
Read More
TikTok is like a big, greasy cheeseburger. We know it is bad for us, but don't care.
27722 Hits
Read More
I lived a double life.
27553 Hits
Read More
In this thing of ours, the world of digital forensics, there is one thread that ties us all together
25167 Hits
Read More

© 2023 Brett Shavers