TryHackMe Walkthrough: AI Forensics
This walkthrough explores how Artificial Intelligence and Machine Learning can be applied to Digital Forensics and Incident Response (DFIR), while also highlighting the limitations and risks of relying on AI during forensic investigations.
Task 2 - The AI Forensics Landscape
Task Overview
This task explores how AI/ML can be applied to Digital Forensics and Incident Response (DFIR). It focuses on how AI can process large volumes of forensic data, detect anomalies, scale analysis across modern environments, and assist with tasks such as phishing detection, malware classification, alert triage, and timeline reconstruction.
It also covers important AI limitations, including probabilistic behaviour, accuracy vs. precision and recall, and the "Garbage In, Garbage Out" principle.
Questions & Answers
1. What ability of AI helps turn a DFIR investigator by recognizing patterns they might not have been able to comprehend?
Anomaly Detection
2. Which metric tells you the proportion of positively flagged results that were actually correct
Precision
3. What term describes the AI characteristic where the same input may yield different outputs across different runs?
Probabilistic
Task 3 - AI & DFIR
Task Overview
This task explores how AI/ML capabilities such as pattern recognition, anomaly detection, NLP, and user behaviour analysis are applied across four key areas of DFIR:
- Image & Video Forensics - Using CNNs, ELA, and GANs to detect image manipulation and deepfakes.
- Communication Analysis - Using NLP and transformer models to detect phishing and analyze chat or social media data.
- Timeline Reconstruction & User Behaviour - Correlating logs, timestamps, network records, and other events to reconstruct incidents and identify anomalies.
- Malware Detection & Analysis - Using ML to classify malicious files and analyze program behaviour through techniques such as API-call analysis.
Questions & Answers
1. What type of neural network is commonly used in image and video forensics due to its ability to learn spatial patterns in visual data?
CNN (Convolutional Neural Network)
2. What kind of analysis can be performed on social media or chat logs to assess the emotional tone of messages?
Sentiment Analysis
3. What type of data do AI systems correlate to reconstruct the timeline of an incident automatically?
Time-sequenced data
4. What type of analysis observes how a program behaves to determine whether it is malicious, e.g., using its API call sequence?
Dynamic Analysis
Task 4 - AI Legal & Ethical Implications
Task Overview
This task explores the legal and ethical challenges of using AI in Digital Forensics and Incident Response (DFIR). It focuses on four key areas:
- Explainability & Transparency - Understanding how AI reaches its conclusions and ensuring findings can be defended.
- Bias & Fairness - Identifying and mitigating biases that may affect forensic investigations.
- Accountability & Chain of Custody - Maintaining evidence integrity, traceability, and proper documentation of AI processing.
- Privacy & Data Protection - Protecting sensitive forensic data when using AI systems and applying privacy-preserving techniques such as federated learning.
The key takeaway is that AI can enhance forensic investigations, but human oversight, validation, legal compliance, and ethical responsibility remain essential.
Questions & Answers
1. What legal test used in the U.S. assesses whether expert or scientific testimony is admissible in court?
Daubert Test
2. What term describes AI models whose internal decision-making processes are difficult to interpret?
Black Box
3. What real-world technology used by law enforcement has been shown to produce racially biased results in identifying suspects?
Facial Recognition
4. What technique allows machine learning to be performed without transferring sensitive data to a central server, helping preserve privacy?
Federated Learning
Task 5 - Practical: The Digital Trail
Task Overview
This task provides a practical DFIR investigation where AI/ML is used as a guiding tool to process large amounts of forensic data and identify suspicious patterns and anomalies. The investigation follows a suspected breach at RobbCo, where proprietary source code may have been accessed.
The investigation demonstrates how AI findings must be validated by human analysis. The investigation follows the attack through:
-
Initial Access - Phishing email and malicious
.odsattachment. - Tooling & Infrastructure - Deployment of a second-stage payload and reverse shell.
-
Privilege Escalation - Abuse of
sudoto modify SSH keys and accessr.house. - Disguise & Persistence - Malicious tools disguised as legitimate system-monitoring components.
- Source Code Theft - RobbCo's proprietary source code being compressed and staged for exfiltration.
An important lesson is that AI can produce false positives, demonstrated when legitimate RobbCo source code was incorrectly flagged as suspicious. Human validation was therefore essential.
Questions & Answers
1. At what time does the attacker successfully log in as j.morgan?
Check the flagged auth.log entries.
2. What attack method was used to gain initial access?
Phishing
3. Can you find the attacker's email address?
Check the phishing email identified during the investigation.
4. What command did the attacker run as j.morgan to gain access to the r.house account?
sudo nano /home/r.house/.ssh/authorized_keys
5. What is the full path of the archive used to steal RobbCo's source code?
/dev/shm/.core_dump_2025.tgz.enc
End