This is going to be my write-up for the first blue team CTF from CyberDefenders, involving investigating a Linux image. The Prompt: We’re provided with a .E01 file, which is an EnCase image format. I used FTK Imager as it was faster for me than Autopsy. …