# Disk Image Analysis Template

Use this worksheet only for systems where you have written authorization. Prefer
read-only mounts, forensic images, and a documented chain of custody.

## Case Metadata
- Case ID:
- Analyst:
- Date opened:
- Evidence item ID:
- Source owner / custodian:
- Legal authority or engagement scope:

## Acquisition Notes
- Tool and version used for acquisition:
- Acquisition command:
- Original media serial number:
- Image format: `raw` / `E01` / `AFF4` / other
- Storage location:
- Write-blocker used: yes / no / not applicable

## Integrity Verification
```bash
sha256sum evidence.img > evidence.img.sha256
sha256sum --check evidence.img.sha256
```

Record initial and post-analysis hashes:

| Item | Algorithm | Hash | Timestamp UTC | Analyst |
|---|---|---|---|---|
| evidence.img | SHA-256 |  |  |  |

## Triage Workflow
1. Identify partitions: `mmls evidence.img` or `fdisk -lu evidence.img`.
2. Mount read-only with offset: `mount -o ro,loop,offset=<bytes> evidence.img /mnt/evidence`.
3. Capture filesystem timeline: `fls -r -m / evidence.img > bodyfile.txt`.
4. Convert timeline: `mactime -b bodyfile.txt > filesystem_timeline.csv`.
5. Search user artefacts: browser profiles, downloads, shell history, recent files.
6. Extract indicators: suspicious binaries, autoruns, persistence files, scripts.

## Findings Log
| Timestamp UTC | Artifact | Path / Offset | Finding | Evidence Reference |
|---|---|---|---|---|

## Analyst Notes
- Assumptions:
- Known limitations:
- Follow-up required:
