Alex and Marcus dig into how digital forensics turns slippery, volatile data into courtroom evidence. They move from incident response and the order of volatility to memory, logs, file systems, cryptography, and the sneaky art of steganography — all with the kind of wonder that makes computers feel strangely alive.
Alex and Marcus start with the core job of a digital forensic investigator, why chain of custody matters, and how a lab is built to protect fragile evidence from the moment it is touched.
The conversation shifts to incident response, especially the REACT, RESPOND, RECOVER framework and the order of volatility — the idea that the most fragile evidence has to be collected first or it disappears forever.
Alex and Marcus dive into memory dumps, file signatures, file carving, and log analysis — the stuff investigators use to reconstruct what a machine was doing while it was still alive.
The hosts explore the operating system, boot process, file allocation, and metadata. The big idea is that file systems are not just storage — they are structured memory, full of clues about what was created, modified, moved, and hidden.
Alex and Marcus break down symmetric and asymmetric cryptography, hashes, and password salting. The focus is on why encryption protects users and why it simultaneously frustrates investigators trying to verify integrity and recover truth.
The episode ends with steganography and watermarking: hiding messages inside ordinary-looking media, and trying to tell the difference between secrecy, ownership, and integrity. Alex and Marcus close by tying everything back to the central forensic challenge — seeing what is meant not to be seen.