Authors: Akash Thakar

DFRWS APAC 2026

Abstract

Modern adversaries don’t just compromise systems—they actively manipulate evidence to obscure their actions and evade detection. Anti-forensic techniques such as timestomping, log tampering, and artifact suppression are increasingly common, forcing defenders to go beyond traditional forensic approaches.
This hands-on workshop equips analysts with practical techniques to uncover and investigate anti-forensic tradecraft. Participants will learn how attackers alter timelines through timestomping and how to detect inconsistencies using cross-artifact correlation. We will demonstrate how to recover deleted event logs and browser history using Volume Shadow Copies.
The workshop also dives into lesser-discussed artifacts that often survive anti-forensic attempts. Attendees will explore how Alternate Data Streams (ADS) can reveal hidden metadata such as download source URLs, and how USN Journal ($UsnJrnl) analysis can uncover file creation, deletion, renaming, and movement—even when attackers attempt to erase their tracks. We will further investigate program execution artifacts (such as Prefetch, Amcache, and related traces) to identify the use of anti-forensic tools, and examine how ShimCache (AppCompatCache) entries can help reconstruct file execution patterns and detect file renames or relocations.
Throughout the session, real-world scenarios and hands-on demonstrations will highlight how seemingly erased evidence can be reconstructed by correlating multiple data sources. By the end of this workshop, participants will be able to identify anti-forensic activity, recover hidden or deleted artifacts, and build resilient investigative workflows to counter adversaries attempting to stay invisible.

Learning Objectives

  • Explain common anti-forensic strategies employed by adversaries to hinder forensic investigations.
  • Assess the strengths and limitations of various forensic data sources during evidence reconstruction.
  • Identify and investigate indicators of evidence manipulation and artifact suppression.
  • Correlate information across multiple forensic artifacts to establish ground truth during investigations.
  • Reconstruct attacker activity through systematic analysis of surviving forensic evidence.

Target experience level

3-5 years in Digital Forensic Investigation

Workshop description

Modern adversaries increasingly employ anti-forensic techniques to manipulate or remove digital evidence, making investigations significantly more challenging. This hands-on workshop explores common anti-forensic tradecraft—including timestomping, event log tampering, browser artifact removal, and registry cleaning—and demonstrates how investigators can detect these techniques through artifact correlation and evidence recovery. Participants will perform practical exercises using NTFS artifacts, Volume Shadow Copies, the USN Journal, transaction logs, memory artifacts, and execution traces to reconstruct attacker activity and validate forensic timelines. By combining live demonstrations with hands-on labs, attendees will gain practical methodologies for identifying anti-forensic activity, recovering hidden or deleted evidence, and conducting resilient investigations against adversaries attempting to evade forensic analysis.

Preparation details

Nothing is required as of now

 

Biography

Dr. Akash Thakar is an Assistant Professor at Rashtriya Raksha University (RRU), an Institution of National Importance under the Ministry of Home Affairs, Government of India. He specializes in Digital Forensics, Incident Response (DFIR), and Cyber Security Operations. He holds a Ph.D. in Forensic Science and industry certifications including CEH, CHFI, and CEI, and received the EC-Council Global Best Academia Instructor Award in 2023. Dr. Thakar has led DFIR training, adversary simulations, and cyber defense exercises for national initiatives such as the Bharat National Cyber Security Exercise, CII SECEx (NCIIPC), and SOC RATS. His research focuses on anti-forensics, artifact correlation, and detection-driven threat hunting, with an emphasis on bridging offensive tradecraft and forensic investigation through practical, hands-on methodologies.

Downloads