Riddle Me This
Artifact Double Meanings
In The Palm of Your Hand
ATT&CK Mindset
The Rich and Famous
100

I have a pair of charged poles and a pair of forensic tools, what am I?

What is Magnet Axiom?

100

Easy deleted file recovery and a good way to take care of the planet

What is Recycle Bin?

100

One small step for man, one free iOS parser for mankind. 

What is iLEAPP?

100

Just like this perfectly legal pass in Football, there's no forward gain on this technique.

What is Lateral Movement?

100

I've gone by Sherlock, Batman, and BinaryZ0ne.

Who is Ali Hadi?

200

I am free and open-source and performed by a mortician. 

What is Autopsy?

200

Logs the 8 most recent program executions and something you do before playing with your dog

What is Prefetch?

200

Aside from being the worst trilogy, this collection of Star Wars movies is also a language commonly used or storing data on Android devices.

What is SQL or SQLite?

200

I Startup in the morning, I RunOnce, I Schedule my Tasks, and I never give up.

What is Persistence? 

200

I share a last name with the composer responsible for movies such as Interstellar and Pirates of the Caribbean.

Who is Eric Zimmerman?

300

I save you form manual CDR mapping and also make up 16.4% of Earth's atmosphere, what am I?

What is Oxygen?

300

I track file system changes and you can use me to travel from Texas to Arkansas

What is $I30?

300

You need me to make calls and texts, just don’t remove the pool ladder or I’ll get stuck.

What is SIM?
300

Gone ______; for Initial Access.

What is Phishing?

300

Take AIM! This forensic expert from Chelsea has worked on cases in Turkey and India.

Who is Mark Spencer?

400

This Japanese sword slices through Linux investigations with ease

What is Tsurugi?

400

Stores password hashes on Linux and something that follows you everywhere you go

What is /etc/shadow?

400

Push me, pull me, but don't call me a database.

What is ADB?

400

These two C’s are all I need. 

What is Command & Control?

400

A pigeons job and the founder of SluethKit.

Who is Brian Carrier? 

500

Picture a double-helix, fighting CSAM, with Bill Gates.

What is PhotoDNA?

500

A successful logon and a perfect square.

What is Event ID 4624?

(68 Squared)

500

What started as a routine traffic stop, this case changed the ability of prosecutors to preserve mobile evidence, or rather the lack thereof.

What is Riley v. California

500

Pet me, feed me, just don’t run me.

What is Mimikatz?

500

I'm an expert in mobile forensics and my last name is a neighborhood in Boston, where I’m not very popular.

Who is Jessica Hyde?