TryHackMe File System Forensics

Job ID: 40509753

Budget: ₹600 – ₹1,500 INR

A filesystem-focused incident lab on the TryHackMe platform is waiting for a clear, evidence-driven investigation. I have set up the room and just need the analysis, documentation, and incident-handling recommendations completed as quickly as possible.

Scope of work
• Access the assigned TryHackMe room (credentials will be shared after award).
• Perform full file system analysis: recover artefacts, extract relevant logs, build a timeline, highlight persistence mechanisms, and identify the root cause of compromise.
• Manage the incident virtually: detail containment, eradication, and recovery steps that flow naturally from your findings.

Deliverables
1. A concise step-by-step walkthrough (commands, reasoning, screenshots where relevant) in PDF or Markdown.
2. An incident report summarising impact, indicators of compromise, and remediation actions.
3. A short debrief call or recorded video (optional but appreciated) to clarify any questions.

Please attach a detailed project proposal that outlines the tools you prefer (e.g., Autopsy, Sleuth Kit, Volatility, or native Linux utilities) and your estimated turnaround time so we can move forward ASAP.