Detailed student guidance
Build a stronger Autopsy submission
Plan the work around what is actually assessed
Rewrite the autopsy brief in plain language. Identify what must be designed, analysed, compared, evaluated or recommended; this separates essential discussion of case creation and image context from background material that adds words without adding marks.
Plan disk image labs at the same time as the report. If a screenshot, table or calculation will be needed later, know why you are collecting it and which sentence or section it will support.
Make technical evidence readable and purposeful
Build each evidence paragraph around a claim rather than around an image. Introduce what you are trying to show, present the figure or data, and explain how hash and integrity concepts changes the interpretation.
During deleted file analysis, preserve original evidence before cropping or formatting it for readability. Redact identifiers, credentials or unrelated personal data that are not required for assessment.
Turn observations into a defensible evaluation
Critical analysis compares what should happen with what the evidence shows. Define the expected condition around file system artefacts, explain the observed difference and discuss why that difference matters in this scenario.
Check the draft for opening original evidence in write mode outside controlled workflow. If confidence is limited, say what remains uncertain and which additional test, source or dataset would strengthen the conclusion.
Use Germany specific context only when it improves the answer
The .de context should sharpen the analysis, not decorate it. International literature may be the best source for the technical core of autopsy, while German or EU guidance becomes useful when it changes obligations, baseline controls or assumptions.
Use copies or images supplied by the course. Treat local guidance as evidence to interpret rather than a paragraph to insert automatically.
Review the report from the marker’s perspective
The final revision should improve coherence, not simply add more content. Trace every major conclusion back to evidence and remove repeated definitions or screenshots that do not help the reasoning between objective and scope and remediation or conclusion.
Finish with presentation details: readable figures, consistent terminology, defined acronyms and complete references. Revisit failing to record image/hash details before export and make sure the report handles it explicitly.