Organization
Northbridge Research Archive
A fictional research-storage and export service used only for this defensive training lab.
Complete a full fictional digital-forensics investigation from authorization through evidence planning, integrity, chain of custody, artifact analysis, volatile-evidence reasoning, network and cloud correlation, timeline versioning, findings, reporting, communication, review, and portfolio-safe closure.
Lesson Progress
High School Intermediate • I12: Digital Forensics Basics • Lesson 8 of 8
Readiness Check
0/5 ready
Lab Mission
A fictional archive owner reports that approved export job 441 created the expected folder and an unexpected approved-copy folder. The supplied evidence includes metadata, process, identity, application, storage, cloud, network, deployment, support, and source-health records. One application source was delayed. One unrelated folder reference is outside scope. Your task is to build a complete, reviewable case package without overstating any artifact or crossing the authorization boundary.
Required safety boundary
Every organization, identity, file, path, process, log, route, record, timestamp, owner, decision, and conclusion in this lab is fictional. Do not substitute real evidence.
Professional standard
Every final claim must trace to approved evidence and preserve source health, alternatives, confidence, limitations, scope, impact boundary, review, and owner decision.
Objective 1
Integrate authorization, evidence-source planning, integrity, chain of custody, artifact analysis, volatile-evidence reasoning, network-and-cloud correlation, timeline versioning, reporting, and case communication in one fictional investigation.
Objective 2
Build a complete fictional evidence register, collection plan, process map, artifact worksheet, normalized timeline, findings matrix, report set, correction record, and portfolio-safe case package.
Objective 3
Separate direct observations from findings, alternatives, confidence, limitations, impact boundaries, owner decisions, and unresolved questions.
Objective 4
Apply fictional privacy, minimization, need-to-know, source-health, evidence-lineage, version-control, and review requirements throughout the case.
Objective 5
Demonstrate that every fictional conclusion can be traced from approved case question to original evidence, working copy, derived artifact, reviewer decision, and final communication.
Case Brief
Organization
A fictional research-storage and export service used only for this defensive training lab.
Case identifier
The fictional case identifier used across evidence, findings, reports, exhibits, and communications.
Primary question
The case must answer the mechanism, scope, supported impact, confidence, limitations, and owner action.
Decision owner
Responsible for approving the case scope, corrective action, communication, and closure.
Approved evidence
Only the supplied fictional evidence on this page may be used.
Privacy boundary
The approved question can be answered without opening fictional file contents.
Stop conditions
Any stop condition requires preservation, documentation, owner review, and an explicit restart decision.
Required outcome
The package must be reproducible, reviewable, privacy-aware, versioned, and portfolio-safe.
Supplied Evidence
Source
Fictional archive owner
Direct record
The approved export completed, but an unexpected approved-copy folder appeared several minutes later.
Case relevance
Defines the original observation and business question.
Limitation
Human report does not prove the technical mechanism.
Source
Fictional archive platform
Direct record
The approved and approved-copy folders each contain five files with matching content hashes and preserved modification values.
Case relevance
Supports duplicate content and later path creation.
Limitation
Copy behavior may reset creation values.
Source
Fictional endpoint custodian
Direct record
The scheduler launched archive-export-worker, which launched copy-worker with target approved-copy and configuration export-legacy.
Case relevance
Provides the strongest runtime mechanism for duplicate creation.
Limitation
Represents one moment rather than the full process history.
Source
Fictional identity platform
Direct record
The approved archive-export service identity opened session SVC-22 before job 441 started.
Case relevance
Connects the approved workflow to the event window.
Limitation
Service identity does not prove human intent.
Source
Fictional archive application
Direct record
The application records the copy operation for job 441, but the event arrived twelve minutes after its source event time.
Case relevance
Confirms the same workflow after source repair.
Limitation
Receipt time must not replace event time.
Source
Fictional archive-storage service
Direct record
Five duplicate-file writes completed under job 441 using the approved service route.
Case relevance
Corroborates file metadata and process target.
Limitation
Storage events do not prove intent.
Source
Fictional cloud platform
Direct record
No public-link, external-share, unrelated-account download, or permission-expansion event appears in verified coverage.
Case relevance
Narrows supported impact.
Limitation
Negative conclusion remains bounded by coverage, retention, account, platform, and time window.
Source
Fictional network service
Direct record
The copy-worker communicated only with archive-storage-api.internal during the observed operation.
Case relevance
Supports an internal-only service route.
Limitation
Flow does not reveal full payload content.
Source
Fictional release platform
Direct record
The runtime used the outdated export-legacy configuration; the approved replacement was deployed after review.
Case relevance
Supports the root condition and corrective action.
Limitation
Repository state requires runtime correlation.
Source
Fictional monitoring service
Direct record
Application delivery lagged by twelve minutes while file, identity, process, storage, cloud, and network sources remained current.
Case relevance
Explains the apparent timeline conflict.
Limitation
Earlier timeline confidence must remain visible.
Source
Fictional archive-review application
Direct record
The approved folder was referenced by the review application and generated preview entries.
Case relevance
Supports application reference to the approved path.
Limitation
Does not prove that a human fully opened or read every file.
Source
Fictional metadata package
Direct record
The export package contains a reference to an unrelated research folder outside current authorization.
Case relevance
Creates a scope and privacy stop condition.
Limitation
No content review or conclusion is permitted.
Collection Plan
Reason
Highest volatility and direct relevance to the active workflow.
Approved method
Preserve the supplied fictional snapshot and verify integrity.
Alternate evidence
Application job, deployment, storage, and identity records.
Stop condition
Do not collect from any real process or system.
Reason
Directly records duplicate paths, hashes, timestamps, and ownership.
Approved method
Preserve the supplied export and create a verified working copy.
Alternate evidence
Storage transactions, backup catalog, and cloud object history.
Stop condition
Do not open fictional file contents.
Reason
Connect the approved service identity to job 441.
Approved method
Use the supplied fictional export with source-health documentation.
Alternate evidence
Application request, process ownership, and storage transactions.
Stop condition
Do not infer human identity or intent.
Reason
Test external sharing, download, destination, and route hypotheses.
Approved method
Use the supplied fictional cloud and flow exports.
Alternate evidence
Application, support, identity, and vendor records.
Stop condition
Do not capture or query any real network or cloud service.
Reason
Confirms the job and copy operation after source repair.
Approved method
Preserve event and receipt times and validate completeness.
Alternate evidence
Process, storage, file, and identity records.
Stop condition
Do not order events by arrival time.
Reason
Tests whether export-legacy was active during the event.
Approved method
Compare supplied repository, rollout, startup, and runtime records.
Alternate evidence
Process arguments and application startup records.
Stop condition
Do not assume repository state equals runtime state.
Reason
Preserve the original observation, expected workflow, and owner decision.
Approved method
Use the supplied fictional report and approval records.
Alternate evidence
Application and storage records.
Stop condition
Do not treat the human report as technical proof.
Reason
Outside scope and unnecessary for the approved case question.
Approved method
Preserve only the existing reference.
Alternate evidence
None required.
Stop condition
Pause and request new approval before any review.
Fake Dashboard
Training dashboard for supplied fictional evidence only.
Approved evidence sources
11
Eleven fictional sources are approved for review; one unrelated-folder reference remains out of scope.
Supported findings
6
Every fictional finding includes evidence, alternatives, confidence, limitation, impact boundary, and decision effect.
Open analytical limits
3
Exact human awareness, full historical process state, and events outside verified coverage remain unsupported.
Fake SOC Alert
Source: Fake Northbridge Forensics Console • Time: 10:24 AM
Fake Log Panel
09:00 CASE id='NRA-DF-2026-012' question='duplicate folder mechanism' 09:06 RECEIVE evidence='NRA-E-002' type='metadata export' 09:11 COPY evidence='NRA-E-002-WORK-01' verification='pass' 09:14 ID session='SVC-22' identity='archive-export-service' 09:15 PROCESS worker='archive-export-worker' config='export-legacy' 09:16 PROCESS child='copy-worker' target='approved-copy' 09:16 FLOW destination='archive-storage-api.internal' 09:17 FILE duplicate_paths='begin' hashes='matching' 09:17 STORAGE writes='5' job='441' 09:20 APP event='copy complete' receipt='09:32' 09:38 HEALTH application_delay='12m' repair='assigned' 09:48 DERIVE artifact_table='NRA-D-006' parent='NRA-E-002-WORK-01' 10:02 RECEIVE application='validated complete' 10:18 TIMELINE version='v2' prior='preserved' 10:24 SCOPE unrelated_folder='reference only' 10:45 REVIEW integrity='pass' custody='complete' lineage='complete' 11:05 FINDING mechanism='approved worker with outdated config' 11:20 IMPACT external_disclosure='not supported within coverage' 12:15 ACTION config='replaced' validation='approved' 15:30 VALIDATE corrected_workflow='pass' recurrence='none observed'
Training note: this is fake data for defensive analysis practice only.
Chain of Custody
09:00
Case opened
Incident Lead
NRA-E-001
Original fictional support request preserved.
Intake identifier assigned.
09:06
Metadata export received
Platform Custodian → Evidence Custodian
NRA-E-002
Original export stored in restricted repository.
Receipt verification passed.
09:11
Metadata working copy created
Evidence Custodian → Forensic Analyst
NRA-E-002-WORK-01
Approved working copy created for artifact review.
Working copy matched preserved reference.
09:23
Process snapshot received
Endpoint Custodian → Evidence Custodian
NRA-E-003
Snapshot and capture context preserved.
Integrity passed; snapshot limitation recorded.
09:34
Identity records received
Identity Owner → Evidence Custodian
NRA-E-004
Approved event window and session records preserved.
Verification passed.
09:41
Cloud and network exports received
Cloud and Network Custodians → Evidence Custodian
NRA-E-007 / NRA-E-008
Original exports preserved with coverage notes.
Verification passed.
09:48
Derived artifact table created
Forensic Analyst
NRA-D-006
Path, hash, timestamp, and ownership comparison table created.
Parent evidence and row counts recorded.
10:02
Delayed application audit received
Application Owner → Evidence Custodian
NRA-E-005
Event and receipt times preserved separately.
Completeness validation passed.
10:18
Timeline version 2 created
Forensic Analyst
NRA-D-014-v2
Delayed application events integrated with preserved version 1.
Changed events and confidence updates reviewed.
10:45
Evidence-handling review completed
Evidence Custodian + Incident Lead
All approved records
Integrity, custody, access, lineage, exceptions, and readiness confirmed.
No unresolved custody gap.
Process and Session Analysis
Parent
service-manager
Owner
archive-platform-service
Arguments
--schedule archive-export-jobs
Evidence relationship
Expected fictional parent for approved export jobs.
Limitation
Snapshot does not show every earlier schedule event.
Parent
scheduler-service
Owner
archive-export-service
Arguments
--job 441 --config export-legacy
Evidence relationship
Connects approved job 441 to the outdated configuration.
Limitation
Runtime path still requires deployment correlation.
Parent
archive-export-worker
Owner
archive-export-service
Arguments
--source approved --target approved-copy
Evidence relationship
Strongest runtime evidence for the duplicate-path mechanism.
Limitation
One snapshot does not show the complete copy lifetime.
Parent
archive-export-worker
Owner
archive-preview-service
Arguments
--target approved
Evidence relationship
Explains preview records for the approved folder.
Limitation
Does not prove full human viewing.
Parent
desktop-session
Owner
research-review-user
Arguments
--case RA-202
Evidence relationship
Supports application reference to the approved folder.
Limitation
Does not prove every file was opened or read.
Parent
service-manager
Owner
archive-sync-service
Arguments
--scope recovery-mirror
Evidence relationship
Alternative automated-copy hypothesis considered and tested.
Limitation
No supplied handle or transaction links it to the duplicate folder.
Artifact Analysis
Direct observation
Five files appear under approved-copy.
Supported finding
A second path exists within the approved job output.
Alternative
Manual copy, retry, synchronization, or restore.
Limitation
Path naming does not prove intent.
Direct observation
Five duplicate files match the approved files by content hash.
Supported finding
The supplied duplicate contents are identical to the approved contents.
Alternative
No alternative changes the content-identity result.
Limitation
Hash match does not prove creator or purpose.
Direct observation
Duplicate paths have later creation values.
Supported finding
The duplicate paths were created after the approved paths within the case window.
Alternative
Copying, extraction, synchronization, or restore may reset creation values.
Limitation
Platform behavior requires correlation.
Direct observation
Both folders list archive-export-service.
Supported finding
Both paths are associated with the approved service context.
Alternative
Ownership may be inherited or assigned by the workflow.
Limitation
Ownership does not identify human intent.
Direct observation
The review application referenced the approved folder.
Supported finding
The application context was aware of the approved path.
Alternative
Automated initialization may create the reference.
Limitation
Full human reading is not proven.
Direct observation
No public-share or unrelated-download event appears.
Supported finding
External disclosure is not supported within verified coverage.
Alternative
Events outside coverage remain outside the conclusion.
Limitation
This is not proof of impossibility.
Versioned Timeline
Original
09:14:36 UTC-04:00
Normalized
13:14:36 UTC
Event
Approved archive-export service session SVC-22 begins.
Relationship
Provides the identity context for job 441.
Limitation
Identity does not prove every later action.
Original
09:15:42 UTC-04:00
Normalized
13:15:42 UTC
Event
Scheduler launches archive-export-worker using export-legacy.
Relationship
Links approved scheduling to the outdated configuration.
Limitation
Application delivery was delayed.
Original
09:16:08 UTC-04:00
Normalized
13:16:08 UTC
Event
Export worker launches copy-worker targeting approved-copy.
Relationship
Strongest runtime link to duplicate creation.
Limitation
Snapshot represents one moment.
Original
09:16:11–09:16:48 UTC-04:00
Normalized
13:16:11–13:16:48 UTC
Event
Copy-worker communicates with archive-storage-api.internal.
Relationship
Supports an internal-only route.
Limitation
Flow does not reveal full payload.
Original
09:17:00 UTC-04:00
Normalized
13:17:00–13:17:59 UTC
Event
Duplicate-folder creation values begin.
Relationship
Consistent with later duplicate-path creation.
Limitation
Source precision requires a range.
Original
09:17:14 UTC-04:00
Normalized
13:17:14 UTC
Event
First duplicate-file write completes under job 441.
Relationship
Corroborates process target and file metadata.
Limitation
Does not prove intent.
Original
09:20:05 UTC event / 09:32:09 UTC receipt
Normalized
09:20:05 UTC event
Event
Application records completion of the job 441 copy operation.
Relationship
Confirms the workflow after source repair.
Limitation
Receipt order is not event order.
Original
09:38 local
Normalized
13:38 UTC
Event
Application-delivery delay is identified and assigned for repair.
Relationship
Explains the apparent timeline conflict.
Limitation
Version 1 had reduced confidence.
Original
10:02 local
Normalized
14:02 UTC
Event
Outdated configuration is replaced and corrected validation is approved.
Relationship
Starts the corrective-action phase.
Limitation
Correction does not prove earlier human intent.
Findings Matrix
Evidence support
Matching hashes, counts, sizes, and preserved modification values.
Alternative
No competing explanation changes content identity within the supplied set.
Limitation
The supplied set may not represent every historical version.
Decision effect
Use the approved folder as the reference output.
Evidence support
Process tree, arguments, application job, storage transaction, file metadata, deployment, and internal flow.
Alternative
Manual copy and synchronization retry receive less support.
Limitation
The process snapshot represents one moment.
Decision effect
Replace the outdated configuration and validate the corrected workflow.
Evidence support
Separate event and receipt times, source-health record, process start, file range, and storage transaction.
Alternative
Clock drift was considered but not supported.
Limitation
Some file events remain within a one-minute range.
Decision effect
Use timeline version 2 and preserve version 1.
Evidence support
Process association, internal destination, DNS, firewall, application mapping, and cloud records.
Alternative
Activity outside verified coverage cannot be completely excluded.
Limitation
Flow records do not reveal full payload.
Decision effect
Report internal-only observed routing.
Evidence support
Cloud, identity, network, application, support, and business records.
Alternative
Events outside retention, account, platform, or time boundaries remain outside the conclusion.
Limitation
This is a bounded no-supported-evidence statement.
Decision effect
Keep impact language limited to verified coverage.
Evidence support
Running application process, recent-item record, preview cache, and support workflow.
Alternative
Automated initialization may create some reference artifacts.
Limitation
No approved content-view evidence is included.
Decision effect
Do not attribute full human review or intent.
Analyze the Evidence
Required Deliverables
Case question, requester, owners, approved sources, exclusions, privacy, methods, stop conditions, and portfolio rule.
Quality standard: Every reviewed source and action is covered by explicit fictional approval.
Source inventory, relevance, volatility, health, integrity risk, privacy, order, method, owner, alternate, limitation, and completion.
Quality standard: The plan protects high-value evidence without crossing scope or touching real systems.
Identifiers, originals, working copies, integrity, transfers, access, storage, lineage, exceptions, and review.
Quality standard: Another fictional reviewer can reconstruct every evidence-handling event.
Paths, hashes, timestamps, ownership, recent items, previews, observations, alternatives, confidence, and limitations.
Quality standard: No artifact is treated as stronger than its real evidence boundary.
Processes, parents, owners, sessions, paths, arguments, handles, routes, baselines, alternatives, and limits.
Quality standard: Runtime evidence is correlated without claiming human intent.
Original times, normalized times, zones, delay, precision, source health, relationships, conflicts, versions, and review.
Quality standard: Timeline version 1 remains preserved after version 2 is created.
Finding, support, conflict, alternative, confidence, limitation, impact boundary, decision effect, and owner.
Quality standard: Every conclusion is traceable, bounded, and reviewable.
Technical report, executive summary, privacy statement, support note, owner brief, exhibits, correction record, and communication log.
Quality standard: Audience detail changes, but the case truth does not.
Fictional overview, safe diagrams, evidence reasoning, lessons learned, limitations, reflection, and portfolio-safety statement.
Quality standard: No real systems, people, files, logs, routes, contacts, owners, credentials, or private records appear.
Common Mistakes
Scenario Decision Lab
The fictional application source is repaired and validated. Its event time confirms the copy operation but changes three event placements from timeline version 1.
Scenario Decision Lab
The fictional evidence supports no observed public sharing or external download within verified coverage, but leadership asks for the statement no disclosure occurred.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a complete fictional Digital Forensics Basics Case Package for the Northbridge Research Archive case. Include authorization, collection plan, evidence register, chain of custody, integrity verification, artifact worksheet, process and session map, source-health register, normalized timeline versions 1 and 2, findings matrix, technical report, executive summary, privacy statement, support note, technical-owner brief, exhibit list, reviewer checklist, correction record, communication log, lessons learned, closure criteria, and a portfolio-safety statement.
Key Takeaways
Navigation