# Starting an investigation of a hacked machine 

**URL:** <https://sleuthkit.discourse.group/t/starting-an-investigation-of-a-hacked-machine/478>\
**Category:** Autopsy Development\
**Created:** [February 10, 2020, 12:23pm UTC](https://sleuthkit.discourse.group/t/starting-an-investigation-of-a-hacked-machine/478 "2020-02-10T12:23:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cmann](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@Cmann](https://sleuthkit.discourse.group/u/Cmann)\
**Post date:** [February 10, 2020, 12:23pm UTC](https://sleuthkit.discourse.group/t/starting-an-investigation-of-a-hacked-machine/478/1 "2020-02-10T12:23:38Z")

</div>

I am starting my final year of University in September and have already made a plan for my dissertation.

I am planning to hack into a virtual machine (Windows 10) via an open SSH port, from there I am going to change file extensions, delete files and folders. Then I am going to do an investigation using Autopsy.

From a forensics standpoint, what is the best suggested starting point to see if a machine has been hacked? Obviously I know what has been hacked, but an investigator isn’t going to know that.

Any suggestions would be great thanks

FYI I know how to obtained the evidence in a forensically sound way, I just want to know where to start.

---

<div class="post-metadata">

**Author:** ![used\_word](https://avatars.discourse-cdn.com/v4/letter/u/7ea924/32.png) [@used\_word](https://sleuthkit.discourse.group/u/used_word)\
**Post date:** [February 11, 2020, 7:20am UTC](https://sleuthkit.discourse.group/t/starting-an-investigation-of-a-hacked-machine/478/2 "2020-02-11T07:20:04Z")

</div>

You can check out the Windows Forensics poster from SANS which is a really good starting point in my opinion. [https://www.sans.org/security-resources/posters/windows-forensic-analysis/170/download](https://www.sans.org/security-resources/posters/windows-forensic-analysis/170/download)

---

<div class="post-metadata">

**Author:** ![Cmann](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@Cmann](https://sleuthkit.discourse.group/u/Cmann)\
**Post date:** [February 16, 2020, 11:30am UTC](https://sleuthkit.discourse.group/t/starting-an-investigation-of-a-hacked-machine/478/3 "2020-02-16T11:30:42Z")

</div>

Thank you very much!
