Practical content from industry professionals on digital forensics · data recovery · cyber security · KVKK compliance.
A tabletop is a scenario-based IR exercise played without touching physical systems. 2-4 hours, 6-12 participants. Four phases: scope, scenario injects, decision-making, lessons learned.
Read moreA Magnet AXIOM license runs in the 5,000 to 12,000 USD per year range depending on the modules. Cloud, Mobile, Computer, Vehicle, and Cyber packages. An academic discount option in Turkey.
Read moreISO/IEC 27037:2012 = the international standard for digital evidence identification, collection, acquisition and preservation. Compatible with CMK 134. 4 stages + chain of custody + hash verification.
Read moreChip-off = a data recovery / forensics method in which the NAND flash memory is desoldered and read with a programmer. JTAG and ISP are alternatives. PC-3000 Flash and Easy JTAG Plus hardware.
Read morePC-3000 = ACE Lab's firmware-level HDD/SSD recovery platform. Service area rewriting, bad sector map reset, family utilities. DSET field use.
Read moreCellebrite UFED = a mobile device digital forensics platform. iOS, Android extraction. EGM Cyber Crimes, Gendarmerie, MASAK as users. Accreditation and license process steps.
Read moreVolatility 3 = Python-based open source memory forensics framework. The windows.pslist, windows.malfind, and windows.cmdline plugins. RAM dump to analysis, step by step.
Read moreKVKK Board administrative fines range from 50,000 TL to 9.5+ million TL. 2026 revaluation. Real decisions: Facebook 2019/144 1.6M, Marriott 2020/173 1.45M. 5 factors.
Read moreA typical digital forensics report is 30 to 80 pages; comprehensive cases reach 150+. ISO 27037 methodology, hash chain, appendices. CMK 67-73 expert opinion format plus example section structure.
Read moreHDD logical recovery 1-3 days, mechanical 3-10 days; SSD/NVMe 2-7 days; RAID simple 3-7 business days, critical case 2-4 weeks. A table plus factors based on DSET's 20+ years of field observation.
Read moreSeparate checklist tables for the 0-1 hour, 1-3 hour, 3-6 hour, 6-12 hour and 12-24 hour windows. USOM 3 hours + KVKK 72 hours integration, the OFAC ransom payment debate, Active Directory compromise analysis.
Read moreConcrete checklists for the 4 phases of NIST SP 800-61 Rev. 2. A Volatility 3 RAM dump workflow, a chain of custody template, an impact criteria table, a tabletop exercise, and a lessons learned form.
Read more