2026-10-03 –, WORKSHOP 1 (Neon Genesis Exploitation) Language: English
The growing reliance on heterogeneous computing environments in both personal and enterprise contexts has made cross-platform forensic acquisition a critical competency for digital investigators. Yet the adoption of rigorous forensic workflows remains uneven, particularly in resource-constrained settings where commercial tools may be inaccessible. This workshop addresses that gap by offering a structured, hands-on introduction to forensic data extraction from Windows and macOS systems using exclusively free tools.
The session opens with a foundational module covering the core principles of digital forensics as they apply to forensic imaging: bit-by-bit acquisition, cryptographic hash verification (MD5, SHA-256), write-blocking procedures, chain of custody documentation, and legal admissibility requirements.
The practical component introduces a curated toolkit of free acquisition and analysis solutions. Guymager is presented as a reliable, GUI-based imaging platform offering multi-format output (DD, EWF/E01, AFF), real-time hash calculation, and parallel acquisition support. Fuji is introduced as a modern imager optimized for macOS environments, particularly suited for APFS volumes and Apple Silicon hardware, featuring automated image verification workflows. For analysis, FTK Imager is demonstrated for forensic extraction from Windows hosts, while Autopsy provides participants with an open-source platform for analysis, data recovery and case management.
So, who actually is Alessandro? Catch him on a weekend and you'll probably find him knee-deep in malt and hops, brewing his own craft beer, or hunting for the perfect shot with his camera. But don't let the chill vibes fool you — in his spare time he moonlights as an information systems designer and developer, with a quiet but serious streak in cybersecurity and digital forensics.
A true veteran of the digital world (let's just say he's been around the block), his experience is anything but textbook. He's spent years "in the trenches," digitizing business processes and leading complex projects for both small and medium-sized companies and public sector organizations.
He's played around with pretty much everything — classic Client/Server architectures, cloud setups on Azure and AWS, all the way to high-availability (HA) configurations.
He's also been spotted hanging out with the LE on more than one occasion — but somehow always made it home perfectly fine. Rumor has it he's committed every cybercrime you can think of (and some you can't).
Oh, and fair warning — his passion for digital forensics is contagious. Once he starts "playing," he has a way of dragging even complete strangers along into his world of bits and investigations.