> For the complete documentation index, see [llms.txt](https://0xmedhat.gitbook.io/medhat/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xmedhat.gitbook.io/medhat/useful-resources.md).

# Useful Resources

* DFIR hub Channel

{% embed url="<https://www.youtube.com/@DFIRHub/playlists>" %}

* Introduction to Digital Forensics

{% embed url="<https://www.youtube.com/playlist?list=PLJu2iQtpGvv-2LtysuTTka7dHt9GKUbxD>" %}

* دورة اساسيات التحقيق الجنائي الرقمي CHFI

{% embed url="<https://www.youtube.com/playlist?list=PLs6emGC4vqRITMh6cfnHO5FXmm9EOre6V>" %}

Memory Forensics Course

{% embed url="<https://www.youtube.com/playlist?list=PLDyW0GpJbH0tARjxMpeM4n6Ix5GRxcwwo>" %}

* Practical Windows Forensics (book)
* Memory Samples

  \
  <https://github.com/volatilityfoundation/volatility/wiki/Memory-Samples?fbclid=IwAR1cAu3C3GDmnLRggfhqSdtqlvXL7m5Cdgv68QMoQcfFhfP3NfK8nxf5rcw>
* <http://www.invoke-ir.com/2015/05/ontheforensictrail-part2.html>
* <https://tldp.org/HOWTO/Partition-Mass-Storage-Definitions-Naming-HOWTO/x190.html>
* ctf  "Digital Forensics cyber talents بالعربي"\
  <https://www.youtube.com/playlist?list=PLddY4WiCoE_yGbnRk3Z0c4ItmQpNml_uf>
* Windows Forensics Methodology

  1- Gathering Volatile Information

  <https://bit.ly/3DqDcTQ>

  2- Collecting Non-volatile Information

  <https://bit.ly/3XGy7yF>

  3- Memory Analysis

  <https://bit.ly/3I8YA2v>

  4- Registry Analysis

  <https://bit.ly/3IhzVYf>

  5- Cache, Cookies, and History Analysis

  <https://bit.ly/3T4whGq>

  6.7- Windows Files and Metadata analysis

  <https://bit.ly/40IhBPT>

  8- Event Logs Analysis

  <https://bit.ly/3zPpfwn>
* <https://tryhackme.com/room/windowsforensics1><br>
* <https://tryhackme.com/room/windowsforensics2>
* <https://tryhackme.com/room/memoryforensics><br>
* <https://tryhackme.com/room/linuxforensics><br>
* <https://tryhackme.com/room/linuxserverforensics><br>
* <https://tryhackme.com/room/forensics><br>
* <https://tryhackme.com/room/iosforensics><br>
* <https://github.com/dfircheatsheet/dfircheatsheet.github.io>
