MuhammadLab
Digital Forensics

Digital Forensics resources and learning tools.

Digital forensics guides and artifact viewers for memory analysis, mobile evidence, databases, metadata, file signatures, logs, email artifacts, and reporting workflows.

Learning area

A focused collection for this topic.

These pages are grouped as a learning collection. More lecture notes, examples, and practical tools can be added without changing the page structure.

12

Available resources

Available resources

Start with these resources

This category combines current MuhammadLab pages that match the topic. More lecture guides and interactive tools can be added here as the lab grows.

Browser resource

Steganography Studio

Hide, extract, and analyse hidden data in images while learning how least significant bit steganography works. Includes forensic image analysis, pixel inspection, entropy checks, and educational reports. All processing happens locally in your browser.

steganography studiolsb steganographyimage steganographydigital forensics teachingpng hidden message
Browser resource

Image Privacy Inspector — Safe to Share?

Check whether an image exposes GPS coordinates, device details, timestamps, software tags, or other metadata before sharing.

image privacyphoto privacy checkgps photo checksafe to share imageexif privacy
Browser resource

ADB Android Debug Bridge Guide - Android Forensics

Learn ADB installation, Android device connection, Android auditing commands, and forensic acquisition workflows.

ADBAndroid Debug BridgeAndroid forensicsAndroid auditingAPK
Browser resource

Log Redactor — Redact Sensitive Data from Logs

Automatically redact IPs, emails, tokens, API keys, JWTs, and secrets from log files.

log redactorredact logslog sanitizerremove sensitive datalog privacy
Browser resource

SMS and MMS Database Viewer

Inspect Android mmssms.db messaging artifacts locally with thread views, timestamps, participants, SMS, MMS, and CSV export.

SMS database viewerMMS database viewermmssms.db viewerAndroid forensicsAndroid SMS forensics
Browser resource

macOS and iPhone Forensics Guide

Learn how macOS fits into iPhone evidence handling, local backups, MobileSync folders, plist files, and iOS artifact review.

iPhone forensicsiOS forensicsmacOS forensicsMobileSynciTunes backup
Browser resource

SQLite Database Viewer — Frontend Forensic Inspector

Upload and inspect SQLite databases directly in your browser.

SQLite database viewersqlite browsermobile forensics sqlitedb viewersql.js viewer
Browser resource

File Signature Inspector — Magic Bytes Viewer

Inspect a file's magic bytes to detect its real type — regardless of the extension.

file signaturemagic bytesfile type detectorfile header inspector
Browser resource

Volatility Visualizer

Visualise Volatility 3 JSON outputs from Windows memory dumps with browser-local process, file, image, text, network, registry, malfind, recovery-helper, and report views.

Volatility VisualizerVolatility 3 JSONmemory forensicsWindows memory dumppslist
Browser resource

Windows Phone Forensics Guide

Learn Windows Phone evidence handling basics, Lumia device notes, backups, app data, and historical mobile artifact considerations.

Windows Phone forensicsLumia forensicsWindows MobileWPInternalsmobile forensics
Browser resource

Wearable Forensics Guide — WHOOP, Health Data & Timestamps

Beginner-friendly wearable forensics guide: WHOOP data architecture, evidence sources (device/app/cloud), timestamp pitfalls, device sync, and chain of custody.

wearable forensicsWHOOP forensicshealth data forensicsbiometric evidencesleep data forensics
Browser resource

Email Forensic Viewer

Inspect an email with a structured forensic view: routing/auth headers, MIME info, anomalies, and parse diagnostics — without a noisy raw dump.

email forensic viewereml forensicmsg forensicemail header analysisauthentication-results