{"areas":[{"lat":29.3759,"lon":47.9774,"name":{"ar":"مدينة الكويت","en":"Kuwait City"}},{"lat":29.3833,"lon":47.9967,"name":{"ar":"شرق","en":"Sharq"}},{"lat":29.3712,"lon":47.9746,"name":{"ar":"المباركية","en":"Mubarakiya"}},{"lat":29.35,"lon":47.93,"name":{"ar":"الشويخ","en":"Shuwaikh"}},{"lat":29.3346,"lon":48.0715,"name":{"ar":"السالمية","en":"Salmiya"}},{"lat":29.3328,"lon":48.0286,"name":{"ar":"حولي","en":"Hawalli"}},{"lat":29.318,"lon":48.02,"name":{"ar":"الجابرية","en":"Jabriya"}},{"lat":29.2775,"lon":47.958,"name":{"ar":"الفروانية","en":"Farwaniya"}},{"lat":29.2266,"lon":47.9689,"name":{"ar":"مطار الكويت الدولي","en":"Kuwait International Airport"}},{"lat":29.256,"lon":48.068,"name":{"ar":"صباح السالم","en":"Sabah Al Salem"}},{"lat":29.185,"lon":48.06,"name":{"ar":"مبارك الكبير","en":"Mubarak Al Kabeer"}},{"lat":29.0769,"lon":48.0838,"name":{"ar":"الأحمدي","en":"Ahmadi"}},{"lat":29.0825,"lon":48.1303,"name":{"ar":"الفحيحيل","en":"Fahaheel"}},{"lat":29.3375,"lon":47.6581,"name":{"ar":"الجهراء","en":"Jahra"}},{"lat":29.56,"lon":47.85,"name":{"ar":"الصبية","en":"Subiya"}},{"lat":29.4386,"lon":48.3333,"name":{"ar":"جزيرة فيلكا","en":"Failaka Island"}},{"lat":28.639,"lon":47.93,"name":{"ar":"الوفرة","en":"Wafra"}},{"lat":28.66,"lon":48.38,"name":{"ar":"الخيران","en":"Khiran"}},{"lat":29.97,"lon":47.72,"name":{"ar":"العبدلي","en":"Abdali"}}],"author":{"ar":"علي العنزي مهندس معمارية أمن أول في الكويت يقود معمارية الأمن في أكبر مؤسسة مالية في البلاد ويرأس لجنة المخاطر والأمن السيبراني التي تخدم الكويت والخليج وكان عضواً في مجلس إدارة إحدى أكبر شركات تقنية المعلومات في الكويت ويرعى مجموعة من أدوات الأمن مفتوحة المصدر للمنطقة.","en":"Ali AlEnezi is a senior security architect in Kuwait. He leads security architecture at the largest financial institution in the country, chairs the Cyber Risk and Security Committee serving Kuwait and the Gulf, served on the board of one of the largest information technology companies in Kuwait, and maintains a portfolio of open source security tools for the region."},"case":{"brief":[{"ar":"خسرت شركة دار السنبوك للتجارة وهي شركة خيالية في شرق التسعيرة النهائية لمناقصة 2026 لصالح منافس في 4 أكتوبر 2026.","en":"Dar Al Sanbouk Trading, a fictional company in Sharq, lost the final pricing of its 2026 tender to a competitor on 4 October 2026."},{"ar":"وفي صباح ذلك اليوم وصلت إلى مسؤول المشتريات فهد رسالة تطلب منه إعادة تعيين كلمة مرور بوابة المناقصات ثم لاحظ فريق تقنية المعلومات بعد قليل خدمة جديدة على حاسوبه.","en":"That morning the procurement officer Fahad received an email asking him to reset his tender portal password, and soon after the IT team saw a new service on his laptop."},{"ar":"فتحفّظت المستجيبة للحوادث نورة على الحاسوب ثم أخذ الفاحص الجنائي يوسف صورة جنائية لقرصه وجمع سجلات خادم الملفات والتقاطاً لحركة شبكة المكتب.","en":"The incident responder Noura seized the laptop, and the forensic examiner Yousef imaged its drive and collected logs from the file server and a capture from the office network."},{"ar":"ومهمتك أن تعيد بناء ما حدث بترتيبه وأن تثبت كل خطوة من الأدلة.","en":"Your task is to reconstruct what happened, in order, and to prove each step from the evidence."}],"evidence":[{"ar":"صورة خام للمساحة غير المخصصة من قرص الحاسوب","en":"Raw image of unallocated space from the laptop drive","path":"evidence/laptop.img"},{"ar":"مجلد المستندات من ملف المستخدم","en":"Documents folder from the user profile","path":"evidence/Documents/"},{"ar":"مجلد الصور من ملف المستخدم","en":"Pictures folder from the user profile","path":"evidence/Pictures/"},{"ar":"اختصارات العناصر المفتوحة مؤخراً","en":"Recent items shortcuts","path":"evidence/Recent/"},{"ar":"قاعدة بيانات سجل متصفح Chromium","en":"Chromium browser history database","path":"evidence/Browser/History"},{"ar":"سجل SSH لخادم الملفات وأحداث الأمان في الحاسوب","en":"File server SSH log and laptop security events","path":"evidence/Logs/"},{"ar":"التقاط لحركة شبكة المكتب من منفذ الحاسوب","en":"Office network capture from the laptop port","path":"evidence/Network/capture.pcap"},{"ar":"سجل سلسلة الحيازة ونسخة مؤرشفة منه","en":"Chain of custody log and an archived copy","path":"custody/"},{"ar":"بصمات كل ملفات الأدلة لحظة الحصول عليها","en":"Hashes of every evidence file at acquisition","path":"manifest.json"}],"id":"case-01","questions":[{"answer_sha256":["7c3af5c945b3a299c074b6b233a7e8c79789582fb6002c33961b4ccfa2792411"],"ar":"ما بصمة SHA-256 للملف laptop.img وهل تطابق سجل الحيازة؟","command":"qassas hash evidence/laptop.img","en":"What is the SHA-256 of laptop.img, and does it match the custody log?","id":"q01","module":"acquisition"},{"answer_sha256":["8302cb886d44515f4e82612e293f26c90dc0658c60de5a32b767ae15cfd2cb3a","d5896727c6b5faa2698707aa65b2dfa4c11bcdd4de5aa9dbbec0204dc0b49ed7"],"ar":"أي ملف في الأدلة يكذب اسمه بشأن نوعه؟","command":"qassas identify evidence --recursive","en":"Which file in the evidence has a name that lies about its type?","id":"q02","module":"filesystems"},{"answer_sha256":["1743a7be5c6ca12c8cdb31be54acc56193857cb1ba948c9b3f02b15cea15fde2","2f8097e320fbc3c8a1d8aa5b0727ee74d6fdc41b1c3c9580e26ea9fff712bd83","41b5c354140569e325b2215d21024cb59dbeed90762151e3bd88d32212f3edad","53cfb329a68bf278a88fd6d1773a40ef43c1790719f0df53f7b1a01950dbcf83","80a178b8abb18ff175709de651b3086df185a07918bdc026365f19550179007f","971040efefc0aea98c98ff247ef40e8484ead2a29f558057a0115ce8f3d4f784"],"ar":"توجد صورة محذوفة في laptop.img فما المنطقة في الكويت التي التُقطت فيها؟","command":"qassas carve evidence/laptop.img out && qassas meta out/<file>","en":"A deleted photo survives in laptop.img. In which area of Kuwait was it taken?","id":"q03","module":"metadata"},{"answer_sha256":["a658c44ad245065df8eb9165b0f31b1bae366ec9974f00e17e8913fbbc8218d4"],"ar":"ما نطاق التصيد الذي زاره فهد قبل التنزيل؟","command":"qassas browser evidence/Browser/History","en":"Which phishing domain did Fahad visit before the download?","id":"q04","module":"browser"},{"answer_sha256":["1e758416c0a85fca47bd8b6d73548eea4d4712c8dc07851447d943c33bdec95f","66bbb0f993941c3ca0b30948678b566b7183d41c5058270fead130fa054d7a31","81bbc545e25a94e0b045a20f7f52a72612ac7d61008d31c5fb40f9756f851fb6","eeaba751269a4ee3055454cd2c8b9b746c6b9561f3573bb02eb4cb57fa0468f5"],"ar":"في أي ساعة ودقيقة بتوقيت الكويت دخل المهاجم إلى خادم الملفات أول مرة؟","command":"qassas logs evidence/Logs/srv-files_auth.log --year 2026","en":"At what time, Kuwait time (HH:MM), did the attacker first log in to the file server?","id":"q05","module":"logs"},{"answer_sha256":["26821d222133a3104d49d6c4c1463a40494549e0cbc00de5b7fe64e776d06ed5","c3e788ae463682ef3ad198620d5f8459cade17d8bd6d86a26c645dc48982e689","c69aca9d3976bc8e1273e2240baca1a2c15c662e7a7837bc508de8610058c444","e86271e9a04d7cb11e87bf63bbf78b8542a0d2f4f066f9a27ceab8816a431235"],"ar":"كم ثانية تفصل بين اتصالات الحاسوب الدورية بخادم التحكم؟","command":"qassas pcap evidence/Network/capture.pcap","en":"How many seconds apart are the laptop's check ins with its command server?","id":"q06","module":"network"},{"answer_sha256":["3492cf4862d82e48337f6c6a9e53624405e4079a75511e6df03824a0363da2b0","98fa80f2ba9c28d1b3cf7ed6a03527b09be57a6ae18dbfb12de9aa8644893f1e","c544d79840b805ee43696b84f34a7c28a665859180dab5798ca15fdbe05b6055","f69e2c9c451e4cbee52fbda6d1a79ccc4ee715bbbe4486925135a3fb63138d8e"],"ar":"ما رقم القيد المعدّل في النسخة المؤرشفة من سجل الحيازة؟","command":"qassas custody verify custody/custody_archive_copy.jsonl","en":"Which entry number in the archived custody copy was altered?","id":"q07","module":"custody"},{"answer_sha256":["835ce2662c6401f750688f53f558a02aa1f5b89ce44894215ee928f5f329ac70","f6689dbe5df114ef084422767eb0a500006d03f4276f5c680e5762b96b88bdd7"],"ar":"كم صورة JPEG يمكن استخراجها بالنحت من laptop.img؟","command":"qassas carve evidence/laptop.img out","en":"How many JPEG images can be carved from laptop.img?","id":"q08","module":"filesystems"},{"answer_sha256":["d79097f1ad8cdaeb7d1cecafc9133ffef5fbc261d1770c2927c4b564b8b3dc8f"],"ar":"ما المسار الكامل الذي يشير إليه الاختصار في مجلد العناصر الأخيرة؟","command":"qassas lnk evidence/Recent/Tender_Update.lnk","en":"What full path does the shortcut in the Recent folder point to?","id":"q09","module":"windows"},{"answer_sha256":["0f5cfaf5901f0a97c9ba5bee4b0bc4910b50704b09aecf7eaca4aa0f4348421f","24fb01d8f77b5bf8ddb6459b9ec73155a0bd4d76b91c53d30c9c8e0295a194e5"],"ar":"كم نسخة محفوظة يحتوي ملف المناقصة بصيغة PDF؟","command":"qassas meta evidence/Documents/Tender_2026_Final.pdf","en":"How many saved revisions does the tender PDF contain?","id":"q10","module":"metadata"},{"answer_sha256":["e547efb6120359332e1331c828b80578e585d0252acca742e622ef01b1aee594"],"ar":"ما اسم الخدمة التي ثُبّتت على الحاسوب؟","command":"qassas logs evidence/Logs/LAPTOP-FHD01_security.jsonl","en":"What is the name of the service installed on the laptop?","id":"q11","module":"logs"},{"answer_sha256":["3627e1d6817f85f13bb1fc3ed874556710b77f496e18d3793015a6e7efa8382b"],"ar":"كم مرة اتصل الحاسوب بخادم التحكم في الالتقاط؟","command":"qassas pcap evidence/Network/capture.pcap","en":"How many times did the laptop check in with the command server in the capture?","id":"q12","module":"network"}],"ref":"QS-2026-001","synthetic":{"ar":"كل ما في هذه القضية مختلق لأغراض التعليم فالشركة والأشخاص والنطاقات والعناوين خيالية وتنتهي النطاقات بـ .example وتأتي عناوين IP من النطاقات المخصصة للتوثيق.","en":"Everything in this case is invented for teaching. The company, people, domains and addresses are fictional, domains end in .example and IP addresses come from the documentation ranges."},"title":{"ar":"تسريب مناقصة السنبوك","en":"The Sanbouk tender leak"},"zipMB":"1.9","zipSha256":"96d0bcc58ea1dd104e583c2918e9e3c9fd37980599e220a5e50b4713b3bdc31f"},"custodyText":{"bad_time":{"ar":"الوقت مفقود أو مكتوب بغير صيغة ISO 8601","en":"the time is missing or not ISO 8601"},"broken_link":{"ar":"لا يشير هذا القيد إلى بصمة القيد الذي يسبقه","en":"this entry does not point to the hash of the entry before it"},"entry_altered":{"ar":"عُدّل هذا القيد بعد كتابته","en":"this entry was changed after it was written"},"item_hash_changed":{"ar":"تختلف بصمة SHA-256 للدليل عن أول قيمة سُجّلت له","en":"the item's SHA-256 differs from the first value recorded for it"},"sequence":{"ar":"يوجد قيد مفقود أو قيد في غير موضعه","en":"an entry is missing or out of order"},"time_reversed":{"ar":"تاريخ هذا القيد أسبق من تاريخ القيد الذي قبله","en":"this entry is dated before the entry above it"}},"glossary":[{"def":{"ar":"هو العملية العلمية لتحديد الأدلة الرقمية وحفظها وتحليلها وعرضها بطريقة تصمد أمام المحكمة أو لجنة التأديب.","en":"The scientific process of identifying, preserving, analysing and presenting digital evidence so that it stands up in court or in a disciplinary hearing."},"id":"digital-forensics","module":"foundations","term":{"ar":"التحليل الجنائي الرقمي","en":"Digital forensics"}},{"def":{"ar":"هو الجمع بين التحليل الجنائي الرقمي والاستجابة للحوادث إذ يحتوي المستجيبون الهجوم بينما يحفظ الفاحصون ما حدث ويشرحونه.","en":"Digital forensics and incident response together: responders contain an attack while examiners preserve and explain what happened."},"id":"dfir","module":"foundations","term":{"ar":"التحليل الجنائي الرقمي والاستجابة للحوادث","en":"DFIR"}},{"def":{"ar":"هو كل معلومة مخزنة أو منقولة بصيغة رقمية يمكن أن تثبت واقعة في التحقيق أو تنفيها.","en":"Any information stored or transmitted in digital form that can prove or disprove a fact in an investigation."},"id":"digital-evidence","module":"foundations","term":{"ar":"الدليل الرقمي","en":"Digital evidence"}},{"def":{"ar":"ينص على أن كل تماس يترك أثراً وفي الحوسبة يكتب كل فعل شيئاً في مكان ما لذا يستطيع الفاحص إعادة بناء الأحداث.","en":"Every contact leaves a trace. In computing, every action writes something somewhere, which is why examiners can reconstruct events."},"id":"locard","module":"foundations","term":{"ar":"مبدأ لوكار للتبادل","en":"Locard's exchange principle"}},{"def":{"ar":"هو متتبع الأثر في صحراء الكويت والجزيرة العربية الذي يقرأ آثار الأقدام فيعرف من مرّ ومتى وبأي سرعة ومن هذه الحرفة أخذ المشروع اسمه ومنهجه.","en":"The desert tracker of Kuwait and Arabia who reads footprints to tell who passed, when and how fast. This project takes its name and its method from that craft."},"id":"qassas-al-athar","module":"foundations","term":{"ar":"قصّاص الأثر","en":"Qassas al-athar"}},{"def":{"ar":"هو أن تُجمع البيانات الأقصر عمراً أولاً فالذاكرة والمسجلات ثم حالة الشبكة والعمليات الجارية ثم الأقراص ثم النسخ الاحتياطية كما يبين RFC 3227.","en":"Collect the most short lived data first: registers and memory, then network state and running processes, then disks, then backups. RFC 3227 sets out the order."},"id":"order-of-volatility","module":"seizure","term":{"ar":"ترتيب التطاير","en":"Order of volatility"}},{"def":{"ar":"هي البيانات التي تختفي حين ينقطع التيار عن الجهاز مثل محتوى الذاكرة واتصالات الشبكة المفتوحة والمستخدمين المسجلين.","en":"Data that disappears when a device loses power, such as memory contents, open network connections and logged in users."},"id":"volatile-data","module":"memory","term":{"ar":"البيانات المتطايرة","en":"Volatile data"}},{"def":{"ar":"هو الشخص المدرَّب الذي يؤمّن موقع الحادثة ويوثّقه ويجمع الأدلة أو يحفظها قبل أن يلمسها أحد.","en":"The trained person who secures the scene, documents it and collects or preserves evidence before anyone else touches it."},"id":"first-responder","module":"seizure","term":{"ar":"المستجيب الأول","en":"First responder"}},{"def":{"ar":"هو وضع اليد على الجهاز أو الوسيط بسند قانوني لكي يُحفظ محتواه ويُفحص.","en":"Taking lawful control of a device or medium so that its contents can be preserved and examined."},"id":"seizure","module":"seizure","term":{"ar":"الضبط","en":"Seizure"}},{"def":{"ar":"هي حقيبة معزولة تحجب الإشارات اللاسلكية فلا يستقبل الهاتف المضبوط أمر مسح عن بُعد ولا رسائل جديدة.","en":"A shielded bag that blocks radio signals so a seized phone cannot receive a remote wipe or new messages."},"id":"faraday-bag","module":"mobile","term":{"ar":"حقيبة فاراداي","en":"Faraday bag"}},{"def":{"ar":"هو جهاز أو برنامج يتيح للفاحص قراءة القرص ويمنع أي كتابة عليه.","en":"Hardware or software that lets an examiner read a drive while preventing any write to it."},"id":"write-blocker","module":"acquisition","term":{"ar":"مانع الكتابة","en":"Write blocker"}},{"def":{"ar":"هي نسخة مطابقة للوسيط التخزيني بتّاً ببتّ تشمل المناطق المحذوفة وغير المخصصة وتُحفظ بصيغة خام أو بصيغة ملف أدلة.","en":"A bit for bit copy of a storage device, including deleted and unallocated areas, kept in a raw or evidence file format."},"id":"forensic-image","module":"acquisition","term":{"ar":"الصورة الجنائية","en":"Forensic image"}},{"def":{"ar":"هي صورة بلا حاوية تحمل بايتات المصدر بترتيبها فقط فتقرؤها كل الأدوات لكنها لا تحمل بصمات ولا ملاحظات مدمجة.","en":"An image with no container, just the bytes of the source in order. Any tool can read it, but it carries no built in hashes or notes."},"id":"raw-image","module":"acquisition","term":{"ar":"الصورة الخام (DD)","en":"Raw image (dd)"}},{"def":{"ar":"هي صيغة الشاهد الخبير وتحفظ الصورة مضغوطة ومقسمة إلى أجزاء مع ملاحظات القضية وقيم التحقق داخلها.","en":"The Expert Witness format: a compressed image split into segments, with case notes and checksums stored inside."},"id":"e01","module":"acquisition","term":{"ar":"ملف الأدلة E01","en":"E01 evidence file"}},{"def":{"ar":"هي بصمة ثابتة الطول تُحسب من البيانات فإن تغيّر بتّ واحد تغيّرت البصمة كلياً لذا يدل تطابق البصمتين على تطابق النسختين.","en":"A fixed length fingerprint computed from data. Changing a single bit changes the hash completely, so matching hashes show two copies are identical."},"id":"hash","module":"acquisition","term":{"ar":"قيمة التجزئة (البصمة)","en":"Hash value"}},{"def":{"ar":"هي خوارزمية التجزئة التي يعتمدها الفاحصون اليوم أما MD5 وSHA-1 فما زالتا تظهران للتوافق رغم إمكان توليد تصادمات لكليهما.","en":"The hash algorithm examiners use today. MD5 and SHA-1 still appear for compatibility, but collisions have been made for both."},"id":"sha256","module":"acquisition","term":{"ar":"خوارزمية SHA-256","en":"SHA-256"}},{"def":{"ar":"هو حساب بصمة المصدر وبصمة الصورة وإثبات تطابقهما عند الحصول على الأدلة ثم قبل كل تحليل.","en":"Hashing the source and the image and showing the values match, at acquisition and again before every analysis."},"id":"verification","module":"acquisition","term":{"ar":"التحقق","en":"Verification"}},{"def":{"ar":"هو قائمة بكل ملفات الأدلة مع أحجامها وبصماتها تُكتب لحظة الحصول عليها ليتحقق أي شخص لاحقاً من أن شيئاً لم يتغير.","en":"A list of every evidence file with its size and hashes, written at acquisition so anyone can check later that nothing changed."},"id":"manifest","module":"acquisition","term":{"ar":"سجل بصمات الأدلة","en":"Evidence manifest"}},{"def":{"ar":"هي السجل المكتوب المتصل لمن حاز الدليل ومتى وأين ولماذا من لحظة الضبط حتى المحكمة وتسميها بعض النصوص الخليجية سلسلة حفظ الأدلة.","en":"The unbroken written record of who held an item of evidence, when, where and why, from seizure to court. Some Gulf texts call it the chain of evidence preservation."},"id":"chain-of-custody","module":"custody","term":{"ar":"سلسلة الحيازة","en":"Chain of custody"}},{"def":{"ar":"هو ختم مرقّم يُظهر بوضوح إن فُتحت الحقيبة ويُسجَّل رقمه في سجل الحيازة.","en":"A numbered seal that shows clearly if a bag was opened. Its number goes into the custody log."},"id":"evidence-bag","module":"custody","term":{"ar":"الختم الكاشف للعبث","en":"Tamper evident seal"}},{"def":{"ar":"هي بايتات ثابتة في بداية الملف تحدد صيغته مثل FF D8 FF لصور JPEG و25 50 44 46 لملفات PDF.","en":"Fixed bytes at the start of a file that identify its format, such as FF D8 FF for JPEG or 25 50 44 46 for PDF."},"id":"file-signature","module":"filesystems","term":{"ar":"توقيع الملف (الرقم السحري)","en":"File signature (magic number)"}},{"def":{"ar":"هو البنية التي تربط أسماء الملفات بمواضع بياناتها على القرص مثل NTFS وext4 وAPFS وFAT32.","en":"The structure that maps file names to the places their data lives on disk, such as NTFS, ext4, APFS or FAT32."},"id":"file-system","module":"filesystems","term":{"ar":"نظام الملفات","en":"File system"}},{"def":{"ar":"هي مناطق القرص التي يعدّها نظام الملفات فارغة وكثيراً ما تبقى الملفات المحذوفة فيها حتى يكتب فوقها شيء آخر.","en":"Disk areas the file system marks as free. Deleted files often survive there until something overwrites them."},"id":"unallocated","module":"filesystems","term":{"ar":"المساحة غير المخصصة","en":"Unallocated space"}},{"def":{"ar":"هي البايتات غير المستخدمة بين نهاية الملف ونهاية آخر كتلة له وقد تحوي بقايا بيانات أقدم.","en":"The unused bytes between the end of a file and the end of its last cluster, which can hold remnants of older data."},"id":"slack-space","module":"filesystems","term":{"ar":"المساحة المتبقية في الكتلة","en":"File slack"}},{"def":{"ar":"هو استرجاع الملفات من البيانات الخام بالاعتماد على بداياتها ونهاياتها دون الاستعانة بنظام الملفات.","en":"Recovering files from raw data by their headers and footers, without help from the file system."},"id":"carving","module":"filesystems","term":{"ar":"نحت الملفات","en":"File carving"}},{"def":{"ar":"هي بيانات عن البيانات مثل المؤلف والبرنامج والطوابع الزمنية والموقع المخزنة داخل الملف أو بجانبه.","en":"Data about data: author, software, timestamps and location stored inside or alongside a file."},"id":"metadata","module":"metadata","term":{"ar":"البيانات الوصفية","en":"Metadata"}},{"def":{"ar":"هي كتلة البيانات الوصفية التي تكتبها الكاميرات والهواتف في الصور وكثيراً ما تحمل طراز الجهاز والوقت وإحداثيات GPS.","en":"The metadata block cameras and phones write into photos, often with the device model, the time and GPS coordinates."},"id":"exif","module":"metadata","term":{"ar":"بيانات EXIF","en":"EXIF"}},{"def":{"ar":"هو تاريخ ووقت مسجلان ويخزنه كل نظام بصيغته ومنطقته الزمنية لذا يوحّد الفاحص كل الطوابع إلى UTC أولاً.","en":"A recorded date and time. Each system stores it in its own format and zone, so an examiner always normalises to UTC first."},"id":"timestamp","module":"timeline","term":{"ar":"الطابع الزمني","en":"Timestamp"}},{"def":{"ar":"هي أوقات التعديل والوصول وتغيير السجل والإنشاء التي يحفظها نظام الملفات وتبين متى كُتب الملف وقُرئ وتغيّر سجله وأُنشئ.","en":"Modified, Accessed, Changed and Born: the four file system times that show when a file was written, read, had its record changed and was created."},"id":"macb","module":"timeline","term":{"ar":"أوقات MACB","en":"MACB times"}},{"def":{"ar":"هو خط زمني واحد يُبنى من كل المصادر معاً كنظام الملفات والسجلات والمتصفح والسجل والشبكة ويُرتّب حسب الوقت.","en":"One timeline built from every source at once: file system, logs, browser, registry and network, sorted by time."},"id":"super-timeline","module":"timeline","term":{"ar":"الخط الزمني الشامل","en":"Super timeline"}},{"def":{"ar":"تعمل الكويت بتوقيت الجزيرة العربية UTC+03:00 طوال العام دون توقيت صيفي فالساعة 09:00 في الكويت هي 06:00 بالتوقيت العالمي.","en":"Kuwait runs on Arabia Standard Time, UTC+03:00, all year with no daylight saving, so 09:00 in Kuwait is 06:00 UTC."},"id":"utc","module":"timeline","term":{"ar":"التوقيت العالمي وتوقيت الكويت","en":"UTC and Kuwait time"}},{"def":{"ar":"هو قاعدة البيانات التي يحفظ فيها Windows إعداداته ويجد فيها الفاحص أجهزة USB والملفات المفتوحة مؤخراً والبرامج التي تعمل عند التشغيل.","en":"The database where Windows keeps settings, and where examiners find USB devices, recently opened files and programs that run at startup."},"id":"registry","module":"windows","term":{"ar":"سجل Windows","en":"Windows registry"}},{"def":{"ar":"هو اختصار في Windows يُنشأ كلما فتح المستخدم ملفاً ويحتفظ بمسار الهدف وأوقاته حتى بعد زواله.","en":"A Windows shortcut. Windows makes one each time a user opens a file, and it keeps the target's path and times even after the target is gone."},"id":"lnk-file","module":"windows","term":{"ar":"ملف الاختصار LNK","en":"LNK file"}},{"def":{"ar":"هي ملفات يكتبها Windows لتسريع تشغيل البرامج وتبين أن البرنامج عمل وعدد مرات تشغيله وآخر مرة عمل فيها.","en":"Files Windows writes to start programs faster. They show that a program ran, how many times and when it last ran."},"id":"prefetch","module":"windows","term":{"ar":"ملفات Prefetch","en":"Prefetch"}},{"def":{"ar":"هو ما يحفظه نظام التشغيل من تسجيلات الدخول والأخطاء والخدمات والأحداث الأمنية وفي Windows يعني الحدث 4624 دخولاً ناجحاً ويعني 4625 دخولاً فاشلاً.","en":"The record an operating system keeps of logons, errors, services and security events. In Windows, event 4624 is a logon and 4625 a failed logon."},"id":"event-log","module":"logs","term":{"ar":"سجل الأحداث","en":"Event log"}},{"def":{"ar":"هو محاولات دخول كثيرة بكلمات مرور مختلفة في وقت قصير والدخول الناجح بعد سلسلة فشل من العنوان نفسه يستدعي اهتماماً عاجلاً.","en":"Many login attempts with different passwords in a short time. A success right after a burst of failures from the same address needs urgent attention."},"id":"brute-force","module":"logs","term":{"ar":"تخمين كلمات المرور","en":"Password guessing (brute force)"}},{"def":{"ar":"هو تحليل نسخة من ذاكرة الحاسوب للعثور على العمليات الجارية واتصالات الشبكة والشيفرة المحقونة والمفاتيح التي لا تُكتب على القرص أبداً.","en":"Analysing a capture of a computer's RAM to find running processes, network connections, injected code and keys that never touch the disk."},"id":"memory-forensics","module":"memory","term":{"ar":"التحليل الجنائي للذاكرة","en":"Memory forensics"}},{"def":{"ar":"هو ملف يحفظ نسخاً من حزم الشبكة مع أوقاتها وهو المادة الخام للتحليل الجنائي للشبكات.","en":"A file holding copies of network packets with their times, the raw material of network forensics."},"id":"pcap","module":"network","term":{"ar":"التقاط الحزم (PCAP)","en":"Packet capture (pcap)"}},{"def":{"ar":"هو اتصال البرمجية الخبيثة بخادم التحكم على فترات منتظمة وانتظام الفواصل بين الاتصالات هو ما يكشفها.","en":"Malware calling its command server at regular intervals. Very regular gaps between connections are the giveaway."},"id":"beaconing","module":"network","term":{"ar":"الاتصال الدوري (Beaconing)","en":"Beaconing"}},{"def":{"ar":"هو خادم المهاجم الذي تتصل به الأجهزة المخترقة لتلقي الأوامر وإرسال البيانات المسروقة.","en":"The attacker's server that compromised machines check in with to receive orders and send stolen data."},"id":"c2","module":"network","term":{"ar":"خادم القيادة والتحكم (C2)","en":"Command and control (C2)"}},{"def":{"ar":"هو اسم الموقع الذي يرسله العميل نصاً واضحاً حين يبدأ اتصالاً مشفراً فيكشف وجهة الحركة حتى لو كان المحتوى مشفراً.","en":"The site name a client sends in clear text when it starts an encrypted connection, so it shows where traffic went even when content is encrypted."},"id":"sni","module":"network","term":{"ar":"اسم الخادم في TLS (SNI)","en":"TLS server name (SNI)"}},{"def":{"ar":"هو علامة ملموسة على الهجوم مثل نطاق خبيث أو عنوان IP أو بصمة ملف أو اسم ملف يمكن للآخرين البحث عنه.","en":"An observable sign of an attack, such as a malicious domain, IP address, file hash or file name, that others can search for."},"id":"ioc","module":"network","term":{"ar":"مؤشر الاختراق","en":"Indicator of compromise (IOC)"}},{"def":{"ar":"هو رسالة تخدع الشخص ليكشف بيانات دخوله أو يفتح برمجية خبيثة وكثيراً ما تستخدم نطاقاً يشبه نطاقاً حقيقياً.","en":"A message that tricks someone into giving away credentials or opening malware, often using a domain that looks like a real one."},"id":"phishing","module":"browser","term":{"ar":"التصيد الاحتيالي","en":"Phishing"}},{"def":{"ar":"هو نطاق يُسجَّل ليشبه نطاقاً موثوقاً مثل company-login.example بدلاً من company.example.","en":"A domain registered to resemble a trusted one, such as company-login.example instead of company.example."},"id":"typosquatting","module":"browser","term":{"ar":"النطاق المشابه","en":"Lookalike domain"}},{"def":{"ar":"هو قاعدة البيانات التي يحفظ فيها المتصفح الصفحات المزارة والتنزيلات وعمليات البحث مع وقت كل منها.","en":"The database a browser keeps of pages visited, downloads and searches, with the time of each."},"id":"browser-history","module":"browser","term":{"ar":"سجل التصفح","en":"Browser history"}},{"def":{"ar":"ينسخ الاستخراج المنطقي ما تتيحه النسخة الاحتياطية للهاتف بينما يصل الاستخراج الكامل لنظام الملفات إلى قواعد بيانات التطبيقات وملفات النظام.","en":"A logical extraction copies what the phone's own backup offers, while a full file system extraction reaches app databases and system files."},"id":"mobile-extraction","module":"mobile","term":{"ar":"الاستخراج المنطقي والاستخراج الكامل لنظام الملفات","en":"Logical and full file system extraction"}},{"def":{"ar":"هي صيغة قواعد البيانات الصغيرة التي تستخدمها معظم التطبيقات ومنها المتصفحات وتطبيقات المحادثة وكثيراً ما تُسترجع الصفوف المحذوفة من صفحاتها الحرة.","en":"The small database format most apps use, including browsers and chat apps. Deleted rows can often be recovered from its free pages."},"id":"sqlite","module":"mobile","term":{"ar":"قواعد بيانات SQLite","en":"SQLite"}},{"def":{"ar":"هي أفعال تهدف إلى إخفاء الآثار أو إتلافها مثل مسح السجلات أو محو الملفات أو تغيير الطوابع الزمنية والمحاولة نفسها كثيراً ما تكون دليلاً.","en":"Actions taken to hide or destroy traces, such as clearing logs, wiping files or changing timestamps. The attempt itself is often evidence."},"id":"anti-forensics","module":"reporting","term":{"ar":"مكافحة التحليل الجنائي","en":"Anti forensics"}},{"def":{"ar":"هو ما يكتبه الفاحص الجنائي من نتائج يبين فيها ما فُحص وكيف وما وُجد وما معناه بلغة يفهمها القاضي.","en":"The written findings of a forensic examiner: what was examined, how, what was found and what it means, in language a judge can follow."},"id":"expert-report","module":"reporting","term":{"ar":"تقرير الخبير","en":"Expert report"}},{"def":{"ar":"هي أن يصل فاحص آخر إلى النتيجة نفسها إذا استخدم الأدلة والمنهج نفسيهما لذا تُدوَّن كل خطوة وكل إصدار أداة في الملاحظات.","en":"Another examiner using the same evidence and method must reach the same result. Every step and tool version goes in the notes for that reason."},"id":"repeatability","module":"reporting","term":{"ar":"قابلية التكرار","en":"Repeatability"}},{"def":{"ar":"هي الجهة التي تختص وحدها في الكويت بالتحقيق في جرائم تقنية المعلومات والادعاء فيها بموجب القانون رقم 63 لسنة 2015.","en":"In Kuwait, the body with sole power to investigate and prosecute information technology crimes under Law No. 63 of 2015."},"id":"public-prosecution","module":"law","term":{"ar":"النيابة العامة","en":"Public Prosecution"}},{"def":{"ar":"هو الواجب القانوني بإبلاغ الجهة الرقابية وأحياناً المتأثرين بالاختراق خلال مهلة محددة تكون في الخليج غالباً 24 أو 72 ساعة.","en":"The legal duty to tell a regulator, and sometimes the people affected, about a data breach within a deadline, often 24 or 72 hours in the Gulf."},"id":"breach-notification","module":"law","term":{"ar":"الإبلاغ عن اختراق البيانات","en":"Breach notification"}}],"install":"# Python 3.9 or newer, no other dependencies\npipx install git+https://github.com/SiteQ8/Qassas\n\nqassas lab make --out qassas-case-01\nqassas manifest verify qassas-case-01/manifest.json \\\n    --root qassas-case-01/evidence\nqassas identify qassas-case-01/evidence\nqassas pcap qassas-case-01/evidence/Network/capture.pcap\nqassas report qassas-case-01 --lang ar --out report.md\n\n# MCP server for AI assistants, read only\nqassas mcp --root qassas-case-01","labs":[{"does":{"ar":"احسب بصمة نص أو ملف واقلب بتّاً واحداً لترى بصمة SHA-256 تتغير كلياً","en":"Hash text or a file and flip one bit to watch SHA-256 change completely"},"id":"hash","intro":{"ar":"اكتب أي شيء أدناه أو اختر ملفاً ثم اقلب بتّاً واحداً وانظر كم يتغير من قيمة SHA-256 ولهذا يثبت تطابق البصمات أن النسختين متطابقتان.","en":"Type anything below or choose a file. Then flip a single bit and see how much of the SHA-256 value changes. That is why matching hashes prove two copies are identical."},"module":"acquisition","title":{"ar":"البصمات","en":"Fingerprints"}},{"does":{"ar":"اقرأ البايتات الأولى من الملف واكشف الاسم الذي يكذب بشأن نوعه","en":"Read a file's first bytes and catch a name that lies about its type"},"id":"signature","intro":{"ar":"افتح إحدى عينات القضية أو أي ملف لديك فيقرأ المختبر التوقيع في البايتات الأولى ويقارنه بالامتداد.","en":"Open one of the case samples or any file of your own. The lab reads the signature in the first bytes and compares it with the extension."},"module":"filesystems","title":{"ar":"ما هذا الملف","en":"What is this file"}},{"does":{"ar":"اقرأ كاميرا الصورة ووقتها وموقعها وحدد أقرب منطقة كويتية","en":"Read a photo's camera, time and GPS and name the nearest Kuwaiti area"},"id":"exif","intro":{"ar":"جرّب الصورة المنحوتة من صورة الحاسوب ثم صورة من عندك فيحوّل المختبر الوقت إلى UTC ويضع إحداثيات GPS بين مناطق الكويت.","en":"Try the photo carved from the laptop image, then a photo of your own. The lab converts the time to UTC and places the GPS fix among Kuwaiti areas."},"module":"metadata","title":{"ar":"أين ومتى","en":"Where and when"}},{"does":{"ar":"عدّل سجل الحيازة وراقب سلسلة البصمات وهي تشير إلى القيد بالضبط","en":"Edit a custody log and watch the hash chain point to the exact entry"},"id":"custody","intro":{"ar":"هذا سجل الحيازة الحقيقي للقضية التدريبية فتحقق منه ثم غيّر حقلاً واحداً وتحقق مرة أخرى ثم حمّل النسخة المؤرشفة واكتشف ما غيّره أحدهم.","en":"This is the real custody log of the practice case. Verify it, change one field, verify again, then load the archived copy and find what someone changed."},"module":"custody","title":{"ar":"اكسر السلسلة","en":"Break the chain"}},{"does":{"ar":"استكشف كل أحداث القضية على خط زمني واحد بتوقيت الكويت أو بالتوقيت العالمي","en":"Explore every event of the case on one timeline in Kuwait time or UTC"},"id":"timeline","intro":{"ar":"كل مصادر القضية مدمجة بواسطة الأدوات فبدّل المنطقة الزمنية وأخفِ المصادر واقرأ اللحظات المفصلية بترتيبها.","en":"Every source in the case, merged by the toolkit. Switch zones, hide sources and read the key moments in order."},"module":"timeline","title":{"ar":"صباح التسريب","en":"The morning of the leak"}},{"does":{"ar":"أجب عن اثني عشر سؤالاً عن تسريب السنبوك وتحقق منها في المتصفح","en":"Answer twelve questions about the Sanbouk leak and check them in the browser"},"id":"case","intro":{"ar":"نزّل الأدلة واعمل عليها بالأدوات ثم تحقق من إجاباتك هنا وتُقارن الإجابات بالبصمات فلا يظهر مفتاح الحل أبداً.","en":"Download the evidence, work through it with the toolkit, and check your answers here. Answers are compared by hash, so the key is never shown."},"module":"reporting","title":{"ar":"حل القضية","en":"Solve the case"}}],"legal":[{"caveat_en":"Issued 7 July 2015. Article 21 brought it into force six months after publication in the Official Gazette. The law has 21 articles and no procedural chapter on preserving, producing or searching data, so see the Code of Criminal Procedures and Trials entry for search and seizure. Articles 6 and 7 set penalties by reference to the Press and Publications Law No. 3 of 2006; Kuwait Times reports that Decree-Law No. 102 of 2026 replaces that law and Electronic Media Law No. 8 of 2016 from April 2027, so check those cross references. Law No. 8 of 2016 has no separate entry because no evidence specific provisions were found.","country":"KW","id":"kw-law-63-2015","notes_en":["Article 2 punishes illegal access to a computer, system or network, with higher penalties if data is deleted, altered or disclosed, higher again if the data is personal, and highest if the offender committed or facilitated it during or because of their job.","Article 3 covers access to confidential government data and to bank customer account data, forgery or destruction of electronic documents and signatures, tampering with electronic medical records, threats, blackmail and online fraud.","Article 13 lets the court confiscate the devices, software and tools used and the proceeds, and close the shop or website involved.","Article 15 lets employees named by the competent minister detect offences, write them up and refer them to the Public Prosecution, and Article 17 gives the Public Prosecution sole power to investigate and prosecute these crimes.","Article 18 sets a limitation period of two years where the penalty is up to three years and five years where it is longer, counted from the day of the offence.","Its explanatory memorandum ties the law to the Arab Convention on Combating Information Technology Offences, which Kuwait ratified by Law No. 60 of 2013."],"source":{"name":"Ministry of Justice, Kuwait (official Arabic text with explanatory memorandum)","url":"https://www.moj.gov.kw/AR/Documents/MojDocs/%D9%82%D8%A7%D9%86%D9%88%D9%86%20%D8%B1%D9%82%D9%85%2063%20%D9%84%D8%B3%D9%86%D8%A9%202015%20%D8%A8%D8%A5%D8%B5%D8%AF%D8%A7%D8%B1%20%D9%82%D8%A7%D9%86%D9%88%D9%86%20%D9%85%D9%83%D8%A7%D9%81%D8%AD%D8%A9%20%D8%AC%D8%B1%D8%A7%D8%A6%D9%85%20%D8%AA%D9%82%D9%86%D9%8A%D8%A9%20%D8%A7%D9%84%D9%85%D8%B9%D9%84%D9%88%D9%85%D8%A7%D8%AA.pdf"},"summary":{"ar":"هو قانون الجرائم الإلكترونية الأساسي في الكويت إذ يعرّف البيانات والمستند الإلكتروني والدخول غير المشروع ويجرّم الدخول دون إذن وإتلاف البيانات والتزوير الإلكتروني والتنصت والاحتيال والتهديد والابتزاز وإساءة استخدام بيانات البطاقات لذلك يحدد التهمة وظروفها المشددة ما يجب أن يثبته الدليل الرقمي.","en":"Kuwait's main cybercrime law. It defines terms such as electronic data, electronic document or record and illegal access, and criminalises unauthorised access, data damage, electronic forgery, interception, online fraud, threats, blackmail and misuse of card data. Examiners need it because the offence charged and its aggravating factors decide what the digital evidence has to prove."},"title":{"ar":"القانون رقم 63 لسنة 2015 في شأن مكافحة جرائم تقنية المعلومات","en":"Law No. 63 of 2015 on Combating Information Technology Crimes"},"type":"law","verified":true,"year":2015},{"caveat_en":"Issued 11 February 2014 and effective on publication in the Official Gazette (Article 46). Article 2 limits it to civil, commercial and administrative transactions. Decree-Law No. 148 of 2025, published in the Official Gazette on 23 October 2025 and effective that day, amended the law and, according to a GLA & Company briefing on Legal 500, widened recognition to personal status matters. This translation predates that amendment, so check the current Arabic text.","country":"KW","id":"kw-law-20-2014","notes_en":["Article 3 gives electronic records, documents, messages, transactions and signatures the same legal effect and force as proof as written ones in civil, commercial and administrative transactions.","Article 9 requires an effective electronic record to be kept as it was created, sent or received, or in a way that proves its data was accurate, to be retrievable at any time, to identify the creator or sender and the date and time, and to follow the format rules of the competent authority.","Article 6 makes a hard copy of an official electronic record evidence against everyone, and of an unofficial one evidence against its signer, to the extent it matches the original. Article 7 applies the civil and commercial Evidence Law where this law is silent.","Article 17 makes a time stamp added by an authentication service provider to a signed electronic record evidence of the date and time it was created, sent and received.","Article 32 bars government bodies, companies and their staff from unlawfully accessing or disclosing personal data in their electronic records without the person's consent or a reasoned judicial order."],"source":{"name":"Kuwait Direct Investment Promotion Authority (English translation)","url":"https://kdipa.gov.kw/wp-content/uploads/2022/08/%D9%82%D8%A7%D9%86%D9%88%D9%86-%D8%A7%D9%84%D9%85%D8%B9%D8%A7%D9%85%D9%84%D8%A7%D8%AA-%D8%A7%D9%84%D8%A7%D9%84%D9%83%D8%AA%D8%B1%D9%88%D9%86%D9%8A%D8%A9-20-%D9%84%D8%B3%D9%86%D8%A9-2014-%D9%85%D8%AA%D8%B1%D8%AC%D9%85-%D8%A8%D8%A7%D9%84%D9%84%D8%BA%D8%A9-%D8%A7%D9%84%D8%A7%D9%86%D8%AC%D9%84%D9%8A%D8%B2%D9%8A%D8%A9.pdf"},"summary":{"ar":"يمنح السجلات والمستندات والرسائل والتوقيعات الإلكترونية الأثر القانوني وحجية الإثبات ذاتها للورق في المعاملات المدنية والتجارية والإدارية ويضع شروطاً للسجل الإلكتروني تتطابق مع طريقة الفاحص في حفظ السجل وحساب بصمته وتوثيقه.","en":"Gives electronic records, documents, messages and signatures the same legal effect and force as proof as paper in civil, commercial and administrative transactions. It lists the conditions an electronic record must meet to count, which maps directly onto how an examiner preserves, hashes and documents a record."},"title":{"ar":"القانون رقم 20 لسنة 2014 في شأن المعاملات الإلكترونية","en":"Law No. 20 of 2014 on Electronic Transactions"},"type":"law","verified":true,"year":2014},{"caveat_en":"Issued 8 May 2014. Amended by Law No. 98 of 2015, and its executive regulations were issued by Cabinet Resolution No. 993 of 2015. The Council of Europe lists this law as Kuwait's legal basis for real time collection of traffic data and interception of content data.","country":"KW","id":"kw-law-37-2014","notes_en":["Article 51 makes phone calls and private telecommunications confidential and holds violators legally accountable.","Article 46 limits possession of bugging devices to official entities named by decree, and they may only use them with prior permission from the Public Prosecution under the criminal procedure code.","Article 59 lets designated CITRA employees enter and inspect telecom sites, examine licences, books, registers and documents, and seize unlicensed or misused equipment, without prejudice to the criminal procedure law.","Article 61 requires CITRA to inform the Public Prosecution when an inspection reveals a suspected crime.","Article 72 punishes hiding, copying or disclosing messages and manipulating subscriber data, including unlisted numbers and sent or received messages."],"source":{"name":"CITRA (English translation of the law)","url":"https://citra.gov.kw/sites/en/LawofCITRA/Law%20No.%2037-%202014.pdf"},"summary":{"ar":"ينشئ هيئة الاتصالات وتقنية المعلومات جهةً منظمة للقطاع ويضع قواعد سرية الاتصالات وأجهزة التنصت وصلاحيات التفتيش وجرائم الاتصالات لذا يرجع إليه الفاحص حين يأتي الدليل من المشغلين أو سجلات المشتركين أو الاتصالات المعترضة.","en":"Creates CITRA as the telecom and ICT regulator and sets rules on the confidentiality of communications, bugging devices, inspection powers and telecom offences. Examiners meet it when evidence comes from operators, subscriber records or intercepted communications."},"title":{"ar":"القانون رقم 37 لسنة 2014 بإنشاء هيئة تنظيم الاتصالات وتقنية المعلومات","en":"Law No. 37 of 2014 on the Establishment of the Communication and Information Technology Regulatory Authority (CITRA)"},"type":"law","verified":true,"year":2014},{"caveat_en":"Issued 2 June 1960 and in force from 1 November 1960. Often cited as a decree law, but the Ministry of Justice text titles it Law No. 17 of 1960. Lexis Middle East reports that Decree-Law No. 62 of 2025 added electronic notification of judgments in absentia and amended Article 230 on fines. Check the latest consolidated text before citing.","country":"KW","id":"kw-law-17-1960","notes_en":["Article 9 gives the Public Prosecution investigation and prosecution powers for felonies, and police investigators those powers for misdemeanours.","Article 80 allows the investigator, or someone acting on the investigator's order, to search a person, home or letters to seize items used in, produced by or related to the crime, when the investigation requires it and no other means exists.","Article 91 requires seized items to be recorded in a report describing them, their condition and how and where they were found, and to be sealed in containers labelled with the date, place, reason, case and the signature of the person who seized them.","Article 87 bars the investigator from delegating the reading of seized letters, and allows phone calls to be monitored and recorded only under an order that clearly identifies the calls and for no longer than the investigation needs.","Articles 100 and 101 let the investigator ask anyone with technical expertise for a sworn opinion, require that opinion in writing, and let each party file a consultative report from another expert.","Article 151 has the court base its conviction on evidence from its own investigation or the pre-trial investigations, lets it weigh one piece of evidence against another freely, and bars the judge from relying on personal knowledge."],"source":{"name":"Ministry of Justice, Kuwait (annotated Arabic edition)","url":"https://moj.gov.kw/AR/Documents/MojDocs2/law102.pdf"},"summary":{"ar":"هو قانون الإجراءات الجزائية في الكويت إذ يحدد من يحقق وكيف يُؤمر بالتفتيش والضبط ويُوثّقان وكيف يُستعان بالخبراء وكيف تزن المحاكم الأدلة غير أن مواد التفتيش والضبط لا تذكر الحاسوب ولا البيانات الإلكترونية فيخضع التفتيش الرقمي لهذه القواعد العامة.","en":"Kuwait's criminal procedure code. It sets who investigates, how searches and seizures are ordered and recorded, how experts are used and how courts weigh evidence. Its search and seizure articles say nothing specific about computers or electronic data, so digital search and seizure follow these general rules."},"title":{"ar":"القانون رقم 17 لسنة 1960 بإصدار قانون الإجراءات والمحاكمات الجزائية","en":"Law No. 17 of 1960 issuing the Code of Criminal Procedures and Trials"},"type":"law","verified":true,"year":1960},{"caveat_en":"The portal says its text is not official, so confirm against the Official Gazette. The 1980 text itself has no provisions on electronic documents. Expert work is governed by Decree-Law No. 40 of 1980 on expertise (see the Cassation 536/2003 entry).","country":"KW","id":"kw-dl-39-1980","notes_en":["Article 9 makes an official document binding on everyone as to what its author recorded within their duties, unless it is proven forged by the legal procedure.","Article 7 lets the court change evidentiary steps it ordered and decline to rely on the result of an evidentiary procedure if it gives reasons in its judgment.","Article 71 lets the court inspect the disputed matter on request or on its own motion and appoint an expert to assist.","Article 7 of Law No. 20 of 2014 applies this law to authenticating electronic documents, their hard copies and electronic signatures where the electronic transactions law is silent.","Article 73 brought the law into force on 1 November 1980."],"source":{"name":"Mohamah.net legal portal (unofficial Arabic text)","url":"https://www.mohamah.net/law/?p=41697"},"summary":{"ar":"هو قانون الإثبات العام في القضايا المدنية والتجارية ويحيل إليه قانون المعاملات الإلكترونية مسائل التحقق من صحة السجلات الإلكترونية لذا يحدد كيف تتعامل المحكمة مع المطبوعات والسجلات الرسمية والمعاينة بمساعدة الخبراء في النزاعات المدنية.","en":"Kuwait's general evidence law for civil and commercial cases. The Electronic Transactions Law refers questions about authenticating electronic records back to it, so it shapes how a court treats printouts, official records and expert assisted inspections in civil disputes."},"title":{"ar":"المرسوم بالقانون رقم 39 لسنة 1980 بشأن الإثبات في المواد المدنية والتجارية","en":"Decree-Law No. 39 of 1980 on Evidence in Civil and Commercial Matters"},"type":"law","verified":true,"year":1980},{"caveat_en":"Included as background. Article numbers come from the Council of Europe profile and the text of Law No. 63 of 2015, not from a full reading of the Penal Code.","country":"KW","id":"kw-law-16-1960","notes_en":["Article 16 of Law No. 63 of 2015 keeps any harsher penalty set by the Penal Code or another law.","Article 19 of Law No. 63 of 2015 applies Penal Code Articles 46 and 79 to IT crimes.","A Council of Europe legal profile points to Articles 238 and 257 to 260 for computer related forgery, calling them specialised and limited in scope, and to Articles 231, 260 and 261 for computer related fraud.","The same profile cites Articles 200, 201, 202 and 204 for child related offences and notes that only Articles 200 and 201 define a minor as a person under 18."],"source":{"name":"Council of Europe, Octopus legal profile of Kuwait (16 April 2020)","url":"https://rm.coe.int/octocom-legal-profile-kuwait/16809e5372"},"summary":{"ar":"يُذكر للخلفية فقط لأن قانون الجرائم الإلكترونية يحتفظ بعقوباته الأشد ويطبق بعض قواعده العامة ولأن الجرائم التقليدية كالتزوير والاحتيال قد يُتهم بها الشخص إلى جانب جرائم تقنية المعلومات.","en":"Background only. The general Penal Code still matters because the cybercrime law keeps its harsher penalties and applies some of its general rules, and traditional offences such as forgery and fraud can be charged alongside IT crimes."},"title":{"ar":"القانون رقم 16 لسنة 1960 بإصدار قانون الجزاء","en":"Law No. 16 of 1960 issuing the Penal Code"},"type":"law","verified":true,"year":1960},{"caveat_en":"Article content was reviewed through the Council of Europe profile, not the official gazette text.","country":"KW","id":"kw-law-9-2001","notes_en":["Article 1 bis punishes photographing or recording people without consent through telecom devices and spreading such material, with harsher penalties where violence or blackmail is involved.","Article 2 bans dealing in wiretapping devices, limits possession and use to designated authorities, and requires prior permission from the Public Prosecution before authorities use them.","Law No. 37 of 2014 requires CITRA to respect this law when tracing the source of radio signals.","The Council of Europe lists it among Kuwait's laws on illegal access, interception, data interference and misuse of devices."],"source":{"name":"Council of Europe, Octopus legal profile of Kuwait (16 April 2020)","url":"https://rm.coe.int/octocom-legal-profile-kuwait/16809e5372"},"summary":{"ar":"يجرّم إساءة استخدام الهاتف ومنها التصوير والتسجيل خلسة وينظم أجهزة التنصت لذا يهم الفاحص حين يكون الدليل تسجيلاً أو صورة التُقطت بالهاتف أو حين يوجد اعتراض للاتصالات.","en":"Criminalises abusive use of phones, including secret photos and recordings, and controls wiretapping equipment. It matters when the evidence is a recording or image made with a phone, or when interception is involved."},"title":{"ar":"القانون رقم 9 لسنة 2001 بشأن إساءة استعمال أجهزة الاتصالات الهاتفية وأجهزة التنصت","en":"Law No. 9 of 2001 on the Misuse of Telephone Communication Devices and Wiretapping Devices"},"type":"law","verified":true,"year":2001},{"caveat_en":"DLA Piper words the deadline as 24 hours from becoming aware; the Chambers guide says 24 hours from the breach. The Decision No. 42 of 2021 text is on citra.gov.kw; the 2024 text was confirmed through Al Tamimi and DLA Piper summaries. Kuwait has no single general data protection statute.","country":"KW","id":"kw-citra-dppr-26-2024","notes_en":["Decision No. 42 of 2021 was approved by the CITRA Board on 28 March 2021 and took effect on publication on 4 April 2021.","Decision No. 26 of 2024 replaced it, was published in the Official Gazette on 18 February 2024, and gave service providers a one year grace period.","Service providers must report personal data breaches to CITRA and affected users within 24 hours. Notice to users is not needed if effective technical and organisational protection was applied to the data.","It covers processing inside or outside Kuwait and excludes security authorities handling data for crime control and public security.","A 2026 Chambers guide by GLA & Company says the regulation now applies only to CITRA licensed telecom and internet providers and that the Data Classification Policy was repealed in February 2024."],"source":{"name":"DLA Piper, Data Protection Laws of the World (Kuwait)","url":"https://www.dlapiperdataprotection.com/index.html?c=KW&t=law"},"summary":{"ar":"هي قواعد حماية البيانات لمقدمي خدمات الاتصالات وتقنية المعلومات المرخصين وتفرض واجبات الموافقة وتحديد الغرض والأمان وواجب الإبلاغ عن الاختراق خلال 24 ساعة فيصبح الخط الزمني للحادثة لدى مقدم الخدمة وإشعاراته جزءاً من الأدلة في التحقيق.","en":"CITRA's data protection rules for licensed communications and IT service providers. They set consent, purpose and security duties and a 24 hour breach notification duty, so a provider's incident timeline and notices become part of the evidence in a breach investigation."},"title":{"ar":"لائحة حماية خصوصية البيانات الصادرة عن هيئة الاتصالات وتقنية المعلومات بالقرار رقم 26 لسنة 2024 بدلاً من القرار رقم 42 لسنة 2021","en":"CITRA Data Privacy Protection Regulation (Decision No. 26 of 2024, replacing Decision No. 42 of 2021)"},"type":"regulation","verified":true,"year":2024},{"caveat_en":"The decree number is confirmed by Kuwait Times (July 2023), the NCSI index and a 2026 Chambers guide. ncsc.gov.kw could not be reached during research. CITRA announced a national cyber security center in 2018, but this decree is the current legal basis. The NCSI index (April 2023) found no evidence of a legal incident reporting obligation.","country":"KW","id":"kw-ncsc-decree-37-2022","notes_en":["Article 2 creates the center as a body supervised by the minister designated by the Council of Ministers.","Article 3 sets objectives that include building a national cybersecurity system, protecting vital interests in cyberspace and protecting critical infrastructure.","Article 4 gives it powers to set strategies, policies and standards, classify cybersecurity incidents, assess and instruct incident response teams, intervene technically, monitor threats and conduct investigations, and license cybersecurity companies and experts.","The decree text published by Al Anba sets no explicit duty for organisations to report incidents to the center, though the head of the center may issue decisions on how to respond to incidents that could threaten state security."],"source":{"name":"Al Anba newspaper (decree text as reported, 6 February 2022)","url":"https://www.alanba.com.kw/1100125"},"summary":{"ar":"ينشئ المركز الوطني للأمن السيبراني جهةً وطنية للأمن السيبراني في الكويت وتحدد صلاحياته في تصنيف الحوادث وتوجيه فرق الاستجابة والتحقيق في التهديدات طريقة التعامل مع حوادث الجهات الحكومية والقطاعات الحيوية وتوثيقها.","en":"Creates Kuwait's National Cyber Security Center as the national cybersecurity body. Its powers to classify incidents, direct response teams and investigate threats shape how government and critical sector incidents are handled and documented."},"title":{"ar":"المرسوم رقم 37 لسنة 2022 بإنشاء المركز الوطني للأمن السيبراني","en":"Decree No. 37 of 2022 establishing the National Cyber Security Center (NCSC)"},"type":"decision","verified":true,"year":2022},{"caveat_en":"Based on RSM and 6clicks summaries and a Kuwait Times report of 6 April 2026; the official text could not be fetched. No specific deadline for reporting incidents to the NCSC was found.","country":"KW","id":"kw-ncsc-nbcc-2026","notes_en":["Issued by the NCSC as Decision No. 2 of 2026 on 5 April 2026 and published in Kuwait Al Youm under Decree No. 37 of 2022.","Applies to civil government agencies, military authorities, security agencies and critical private sector institutions.","Covered entities have 18 months from publication to comply fully.","Built on six control domains aligned with NIST CSF 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).","RSM highlights annual self assessments and evidence retention among its requirements."],"source":{"name":"RSM Kuwait","url":"https://www.rsm.global/kuwait/node/282"},"summary":{"ar":"هي حد أدنى إلزامي للأمن السيبراني يصدره المركز الوطني للأمن السيبراني ويرفع جاهزية الجهات الحكومية والحيوية لاكتشاف الحوادث والاستجابة لها والتعافي منها وهذا يحدد ما يوجد من سجلات وقيود حين يُحقَّق في حادثة.","en":"A mandatory minimum cybersecurity baseline issued by the National Cyber Security Center. It aims to raise readiness to detect, respond to and recover from incidents across government and critical sectors, which shapes what logs and records exist when an incident is investigated."},"title":{"ar":"الضوابط الوطنية الأساسية للأمن السيبراني بقرار المركز الوطني للأمن السيبراني رقم 2 لسنة 2026","en":"National Basic Cybersecurity Controls (NCSC Decision No. 2 of 2026)"},"type":"framework","verified":true,"year":2026},{"caveat_en":"Controls 5.x sit in Chapter 4 (Cyber Resilience Baselines) and 8.2.2 in Chapter 5 (Operational Resilience Baselines) of Version 1.0. Control 5.12.4.4 also requires procedures on when management, law enforcement or regulator approval is needed before forensic work starts. The 2020 framework was announced on 18 February 2020.","country":"KW","id":"kw-cbk-corf-2025","notes_en":["Version 1.0 was first released on 3 December 2025 and builds on the central bank's 2020 Cybersecurity Framework.","Controls 8.2.2.1 to 8.2.2.3 require initial reports to the central bank within 1 hour of discovery for high severity incidents and 4 hours for medium, updates every 4 hours (high) or daily (medium), closure reports, and monthly consolidated reports for low severity incidents.","Control 5.12.4.7 requires chain of custody for all evidence, with documented transfers, dates and people involved.","Control 5.12.4.8 requires evidence to be protected with cryptographic hashes such as SHA-256 or SHA-512, with integrity verified before and after every forensic task.","Control 5.12.4.9 requires every forensic task to be logged with tools, versions and configurations, time stamped activities and observations.","Control 5.12.4.10 requires a DFIR capability through internal 24/7 responders or external retainers, and control 5.11.2.4 requires prompt notice to the central bank of personal data breaches."],"source":{"name":"Central Bank of Kuwait","url":"https://www.cbk.gov.kw/en/images/corf-170113_v10_tcm10-170113.pdf"},"summary":{"ar":"هو قواعد بنك الكويت المركزي للمرونة السيبرانية والتشغيلية للمؤسسات الخاضعة لرقابته ويتميز بالتفصيل في التحليل الجنائي الرقمي إذ يتناول سلسلة الحيازة وحساب البصمات وتسجيل أعمال الفحص ومهلاً قصيرة جداً لإبلاغ الجهة الرقابية بالحوادث.","en":"The Central Bank of Kuwait's cyber and operational resilience rules for the institutions it regulates. It is unusually specific on digital forensics, with chain of custody, hashing and logging of forensic work, and very short deadlines for reporting incidents to the regulator."},"title":{"ar":"إطار المرونة السيبرانية والتشغيلية الصادر عن بنك الكويت المركزي لجميع البنوك والمؤسسات المالية المحلية","en":"Central Bank of Kuwait Cyber and Operational Resilience Framework (CORF) for All Local Banks and Financial Institutions"},"type":"framework","verified":true,"year":2025},{"caveat_en":"Issued 8 May 2013. Central Bank of Kuwait AML/CFT instructions repeat the five year retention for the entities they regulate. Al Jarida reports that Decree-Law No. 76 of 2025 amended Article 25 and added Article 33 bis on UN Security Council measures, not the record keeping rule.","country":"KW","id":"kw-law-106-2013","notes_en":["Article 11 requires financial institutions and designated non-financial businesses and professions to keep records and make them available to competent authorities.","Due diligence records must be kept for at least five years after the business relationship ends, and transaction records for at least five years after the transaction or attempt.","A competent authority may require longer retention in specific cases.","Article 9 of Law No. 63 of 2015 separately punishes money laundering through networks or IT means with up to ten years in prison."],"source":{"name":"English translation of Law No. 106 of 2013 (hosted by Alkarama)","url":"https://www.alkarama.org/sites/default/files/2016-11/KWT_Anti-MoneyLaunderingAndCombatingTheFinancingOfTerrorismLawNo.%28106%29of2013.pdf"},"summary":{"ar":"هو قانون مكافحة غسل الأموال وتمويل الإرهاب في الكويت ويوجب الاحتفاظ بسجلات العناية الواجبة والمعاملات خمس سنوات على الأقل فيجد المحققون أثراً موثوقاً يمكن طلبه.","en":"Kuwait's AML and CFT law. Its record keeping rule means due diligence and transaction records must exist for at least five years, which gives investigators a dependable trail to request."},"title":{"ar":"القانون رقم 106 لسنة 2013 في شأن مكافحة غسل الأموال وتمويل الإرهاب","en":"Law No. 106 of 2013 on Anti-Money Laundering and Combating the Financing of Terrorism"},"type":"law","verified":true,"year":2013},{"caveat_en":"Summary taken from the Ministry of Justice annotation, not the full judgment.","country":"KW","id":"kw-cassation-24-2008","notes_en":["The court upheld the seizure of computers, CDs and floppy disks found with the appellants and the examination of the files on them.","It noted the media held general material and speeches from the internet and no postal or telegraphic letters, the category that only the investigator may read under the code.","The annotated code files the ruling under a heading on searching computers, next to the rule that the investigator, or someone acting on the investigator's order, may search a person, home or letters.","Reported in the Justice and Law Journal, year 36, part 3, page 523."],"source":{"name":"Ministry of Justice, Kuwait (annotated Code of Criminal Procedures and Trials)","url":"https://moj.gov.kw/AR/Documents/MojDocs2/law102.pdf"},"summary":{"ar":"هو مبدأ لمحكمة التمييز منشور في قانون الإجراءات الجزائية المشروح الصادر عن وزارة العدل يطبق قواعد التفتيش والضبط العادية على الحواسيب والأقراص لذا يفيد مرجعاً لأن قانون الإجراءات يخلو من نصوص خاصة بتفتيش الحاسوب.","en":"A Court of Cassation principle, published in the Ministry of Justice's annotated criminal procedure code, applying ordinary search and seizure rules to computers and discs. It is a useful reference because the procedure code has no computer specific search provisions."},"title":{"ar":"حكم محكمة التمييز في الطعن الجزائي رقم 24 لسنة 2008 بجلسة 7 يوليو 2008 بشأن الحواسيب المضبوطة","en":"Kuwait Court of Cassation, Criminal Appeal No. 24 of 2008 (session of 7 July 2008) on seized computers"},"type":"court","verified":true,"year":2008},{"caveat_en":"This is a civil ruling, so treat it as persuasive on expert evidence generally. In criminal investigations, Articles 100 and 101 of the criminal procedure code also apply.","country":"KW","id":"kw-cassation-536-2003","notes_en":["Article 4 (second paragraph) of Decree-Law No. 40 of 1980 on expertise requires an expert appointed from outside the Experts Department or the experts roster to take an oath before the court or the urgent matters judge before starting.","The Court of Cassation held that a missing oath does not void the report, because the law sets no nullity for it and the rule is not one of public order.","The trial court is the highest expert in the case and may adopt or reject an expert report, even on a technical question.","The research gives a forensic doctor of the Ministry of Interior's Criminal Evidence Department as an example of an expert outside the Experts Department."],"source":{"name":"Kuwait Institute for Judicial and Legal Studies (Ministry of Justice), bulletin no. 12, January 2019","url":"https://www.kijls.moj.gov.kw/ar/sections/section4/sub4_section4/Research&Translation/Researchs/%D8%AD%D9%82%20%D8%A7%D9%84%D9%85%D8%AD%D9%83%D9%85%D8%A9%20%D9%81%D9%8A%20%D8%A7%D9%84%D8%A3%D8%AE%D8%B0%20%D8%A8%D8%AA%D9%82%D8%B1%D9%8A%D8%B1%20%D8%A7%D9%84%D8%AE%D8%A8%D9%8A%D8%B1.pdf"},"summary":{"ar":"يبين كيف تتعامل المحاكم الكويتية مع تقارير الخبراء ومنها تقارير الخبراء الفنيين من خارج إدارة الخبراء بوزارة العدل ولأن للمحكمة الكلمة الأخيرة في ما ينتهي إليه الخبير يجب أن يكون التقرير الجنائي واضحاً بما يكفي لإقناعها.","en":"Shows how Kuwaiti courts treat expert reports, including those by technical experts from outside the Ministry of Justice Experts Department. The court has the final word on an expert's findings, so a forensic report must be clear enough to persuade it."},"title":{"ar":"حكم محكمة التمييز في الطعن المدني رقم 536 لسنة 2003 بجلسة 21 نوفمبر 2005 بشأن تقارير الخبراء","en":"Kuwait Court of Cassation, Civil Appeal No. 536 of 2003 (session of 21 November 2005) on expert reports"},"type":"court","verified":true,"year":2005},{"caveat_en":"Dated 26 March 2007. The 2009 translation uses the institution names of that time, so check the current names of the investigating and technical bodies. The Arabic text governs.","country":"SA","id":"sa-acl-m17-2007","notes_en":["Article 3 punishes interception of data sent over a network or computer without legitimate authorisation, among other offences, with up to one year in prison and a fine up to SAR 500,000.","Article 5 punishes unlawful access to delete, destroy, leak or alter private data, and disrupting networks or services, with up to four years and SAR 3 million.","Article 13 allows confiscation of equipment, software and proceeds and closure of the website or venue used.","Article 14 requires the Communications and Information Technology Commission to give technical support to security agencies during investigation and trial.","Article 15 assigns investigation and prosecution to the Bureau of Investigation and Public Prosecution, and Article 16 brought the law into force 120 days after publication."],"source":{"name":"Bureau of Experts at the Council of Ministers, official translation (hosted by MCIT)","url":"https://www.mcit.gov.sa/sites/default/files/anti_cyber_crime_law_en_0.pdf"},"summary":{"ar":"هو النظام الأساسي للجرائم المعلوماتية في المملكة العربية السعودية ويعدد الجرائم من التنصت والدخول غير المشروع إلى الاحتيال وإتلاف البيانات ويوزع أدوار التحقيق والادعاء والدعم الفني.","en":"Saudi Arabia's core cybercrime law. It lists offences from interception and unlawful access to fraud and data destruction, and assigns investigation, prosecution and technical support roles."},"title":{"ar":"نظام مكافحة جرائم المعلوماتية الصادر بالمرسوم الملكي رقم م/17 بتاريخ 8/3/1428هـ","en":"Anti-Cyber Crime Law (Royal Decree No. M/17 of 8/3/1428H)"},"type":"law","verified":true,"year":2007},{"caveat_en":"Dated 30 December 2021 in the translation, last updated 18 September 2022. Article 1 limits the law to civil and commercial transactions, so criminal cases follow separate procedure rules. Article 127 allows private sector help in evidentiary procedures under rules from the Minister of Justice.","country":"SA","id":"sa-evidence-m43-2021","notes_en":["Article 53 defines digital evidence as evidence derived from data generated, issued, delivered, stored or communicated by digital means and retrievable in a comprehensible form.","Article 54 lists digital registers, documents, signatures, correspondence including email, means of communication and digital media, and Article 55 gives digital evidence the same effect as writing.","Article 56 gives official digital evidence the value of an official document, including records generated automatically by public agencies' systems, and Article 58 puts the burden on the party who disputes it.","Article 60 requires digital evidence to be submitted in its original or another digital form, and Article 63 gives extracts the same value as long as they match the digital register.","Article 62 lets the court assess probative value itself when the evidence cannot be verified for reasons outside the parties' control, and Article 129 brought the law into force 180 days after publication."],"source":{"name":"Bureau of Experts at the Council of Ministers, official translation (hosted by MISA)","url":"https://misa.gov.sa/app/uploads/2025/07/Law-of-Evidence.pdf"},"summary":{"ar":"هو نظام الإثبات في القضايا المدنية والتجارية في المملكة العربية السعودية وفيه باب كامل للدليل الرقمي يعامله معاملة الكتابة ويضع قواعد للأصل والمستخرجات والتحقق تتطابق مع طريقة كتابة التقرير الجنائي.","en":"Saudi Arabia's evidence law for civil and commercial cases, with a full part on digital evidence. It treats digital evidence like writing and sets rules on originals, extracts and verification that map directly onto forensic reporting."},"title":{"ar":"نظام الإثبات الصادر بالمرسوم الملكي رقم م/43","en":"Law of Evidence (Royal Decree No. M/43)"},"type":"law","verified":true,"year":2021},{"caveat_en":"Control texts were checked through the NCA implementation guide, which uses ECC-2:2024 numbering and scope. The guide's text for control 2-13-3-3 sets no reporting deadline. ECC-2:2024 is the second edition after ECC-1:2018.","country":"SA","id":"sa-nca-ecc-2-2024","notes_en":["Applies to government agencies and their affiliated companies and entities inside and outside the Kingdom, and to private entities that own, operate or host Critical National Infrastructure.","Subdomain 2-13 covers cybersecurity incident and threat management, and control 2-13-3-3 requires reporting cybersecurity incidents to the NCA.","Control 2-13-3-4 requires sharing incident notifications, threat intelligence, indicators and incident reports with the NCA.","The NCA guide names approved reporting channels such as the Haseen portal and the is@nca.gov.sa mailbox.","Control 2-12-3-5 requires cybersecurity event logs to be kept for at least 12 months."],"source":{"name":"National Cybersecurity Authority, Guide to ECC Implementation (GECC-2:2026)","url":"https://cdn.nca.gov.sa/api/files/public/upload/11bb8f2d-706a-4f18-80f1-40d620ebd845_GECC-.pdf"},"summary":{"ar":"هي الضوابط الأساسية التي تصدرها الهيئة للجهات الحكومية ومشغلي البنية التحتية الحيوية وتوجب إبلاغ الهيئة بالحوادث والاحتفاظ بالسجلات حداً أدنى وكلاهما يحدد ما يبقى من أدلة بعد الحادثة.","en":"The NCA's baseline controls for government bodies and critical infrastructure operators. They require incident reporting to the NCA and minimum log retention, both of which decide what evidence exists after an incident."},"title":{"ar":"الضوابط الأساسية للأمن السيبراني ECC-2:2024 الصادرة عن الهيئة الوطنية للأمن السيبراني","en":"Essential Cybersecurity Controls (ECC-2:2024), National Cybersecurity Authority"},"type":"framework","verified":true,"year":2024},{"caveat_en":"Article 24 and the 2026 draft come from Clyde & Co (8 October 2026) and PwC; the portal from DLA Piper; the processing record rule from Clyde & Co (September 2023). The breach article number in the Law itself was not confirmed, so it is omitted.","country":"SA","id":"sa-pdpl-m19-2021","notes_en":["Issued 16 September 2021, amended 27 March 2023, in force from 14 September 2023, with enforcement from 14 September 2024 after a one year transition.","Under Article 24 of the Implementing Regulations, controllers must notify SDAIA within 72 hours of becoming aware of a breach that may harm personal data or data subjects or conflict with their rights, through the National Data Governance Portal.","Data subjects must be notified without undue delay where the breach may harm them or their rights.","Draft amendments to Article 24, under public consultation from 6 October to 5 November 2026, would require notice to SDAIA within 72 hours whether or not harm is likely.","Controllers must keep a record of processing activities for as long as the processing lasts plus five years."],"source":{"name":"Latham & Watkins client alert (December 2023)","url":"https://www.lw.com/en/insights/2023/12/Saudi-Arabias-data-protection-law-enters-into-force"},"summary":{"ar":"هو النظام العام لحماية البيانات في المملكة العربية السعودية تحت إشراف الهيئة السعودية للبيانات والذكاء الاصطناعي ويبدأ واجب الإبلاغ عن الاختراق فيه مهلة 72 ساعة تشكّل الاستجابة للحادثة وجمع الأدلة المبكر.","en":"Saudi Arabia's general data protection law, supervised by SDAIA. Its breach notification duty starts a 72 hour clock that shapes incident response and early evidence collection."},"title":{"ar":"نظام حماية البيانات الشخصية الصادر بالمرسوم الملكي رقم م/19 بتاريخ 9/2/1443هـ والمعدل بالمرسوم الملكي رقم م/148 بتاريخ 5/9/1444هـ","en":"Personal Data Protection Law (Royal Decree No. M/19 of 9/2/1443H, amended by Royal Decree No. M/148 of 5/9/1444H)"},"type":"law","verified":true,"year":2021},{"caveat_en":"Article texts were read from the English translation hosted by ADGM. The portal lists one amendment (record updated 4 April 2024), which was not reviewed.","country":"AE","id":"ae-fdl-34-2021","notes_en":["Article 1 defines digital evidence as electronic information with probative value that is stored, transmitted, extracted or derived from computers or networks and can be gathered and analysed with special tools.","Article 65 gives evidence extracted from electronic devices, media, information systems and software the same probative force as physical forensic evidence.","Article 18 punishes anyone managing a website, account, email or information system who hides or tampers with digital evidence to obstruct investigators, with at least six months in prison and/or a fine of at least AED 200,000.","Article 16 punishes using tools, passcodes or encryption to commit these crimes or to hide their evidence or traces.","Issued 20 September 2021, published in Official Gazette No. 712 (supplement) on 26 September 2021, and in force from 2 January 2022. Article 73 repealed Decree-Law No. 5 of 2012."],"source":{"name":"UAE Legislation portal","url":"https://uaelegislation.gov.ae/en/legislations/1526"},"summary":{"ar":"هو قانون الجرائم الإلكترونية في الإمارات العربية المتحدة ويعرّف الدليل الرقمي ويجرّم العبث به ويمنح الدليل المستخرج من الأجهزة الإلكترونية حجية الدليل الجنائي المادي في القضايا الجزائية.","en":"The UAE's cybercrime law. It defines digital evidence, criminalises tampering with it, and gives evidence extracted from electronic devices the same force as physical forensic evidence in criminal cases."},"title":{"ar":"مرسوم بقانون اتحادي رقم 34 لسنة 2021 في شأن مكافحة الشائعات والجرائم الإلكترونية","en":"Federal Decree-Law No. 34 of 2021 on Countering Rumors and Cybercrimes"},"type":"law","verified":true,"year":2021},{"caveat_en":"The replacement of Law No. 10 of 1992 comes from a Taylor Wessing briefing, which also notes the court is not bound by an expert's opinion but must give reasons for rejecting it.","country":"AE","id":"ae-fdl-35-2022","notes_en":["Article 53 defines electronic evidence as evidence derived from data or information generated, stored, extracted or copied electronically.","Article 54 lists electronic records, instruments, signatures, seals, correspondence including email, modern means of communication and electronic media.","Article 55 applies the documentary evidence rules to electronic evidence, and Article 56 gives formal electronic evidence the value of formal instruments when its conditions are met.","Article 63(1) gives extracts of electronic evidence the same probative value as the evidence itself.","Issued 3 October 2022 and in force from 2 January 2023, replacing Federal Law No. 10 of 1992."],"source":{"name":"UAE Legislation portal","url":"https://uaelegislation.gov.ae/en/legislations/1612"},"summary":{"ar":"هو قانون الإثبات المدني والتجاري في الإمارات وفيه باب مخصص للدليل الإلكتروني يحدد ما يُعد دليلاً وكيف يُوزن الدليل الإلكتروني الرسمي وغير الرسمي وما قيمة المستخرجات.","en":"The UAE civil and commercial evidence law. A dedicated part on electronic evidence sets what counts, how formal and informal electronic evidence are weighed, and the value of extracts."},"title":{"ar":"مرسوم بقانون اتحادي رقم 35 لسنة 2022 بإصدار قانون الإثبات في المعاملات المدنية والتجارية","en":"Federal Decree-Law No. 35 of 2022 Promulgating the Law of Evidence in Civil and Commercial Transactions"},"type":"law","verified":true,"year":2022},{"caveat_en":"The official translation calls the regulator the Data Bureau; it is commonly called the UAE Data Office, created by Federal Decree-Law No. 44 of 2021. BSA Law reported in July 2024 that the Executive Regulations were not yet issued, and their later issue could not be confirmed.","country":"AE","id":"ae-fdl-45-2021","notes_en":["Article 9 requires the controller, on becoming aware of a breach that may harm privacy, confidentiality or security, to notify the regulator with the nature, causes and approximate number of records, expected effects, corrective measures and documents of the breach.","Article 9 also requires notice to data subjects where the breach would prejudice their privacy, and requires processors to tell the controller as soon as they learn of a breach.","Deadlines for both notices are left to the Executive Regulations.","Article 2 excludes government data, data held by security and judicial authorities, health and banking data covered by their own laws, and free zones with their own data protection laws.","Issued 20 September 2021 and in force from 2 January 2022."],"source":{"name":"UAE Legislation portal","url":"https://uaelegislation.gov.ae/en/legislations/1972"},"summary":{"ar":"هو قانون حماية البيانات الاتحادي في الإمارات وتوجب مادة الإبلاغ عن الاختراق فيه أن يرسل المتحكم تفاصيل الاختراق ومستنداته وهي تتداخل مع سجلات الحادثة والفحص الجنائي.","en":"The UAE federal data protection law. Its breach reporting article requires the controller to send details and documents of the breach, which overlap with incident and forensic records."},"title":{"ar":"مرسوم بقانون اتحادي رقم 45 لسنة 2021 بشأن حماية البيانات الشخصية","en":"Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data"},"type":"law","verified":true,"year":2021},{"caveat_en":"The translation dates the law 15 September 2014, while an Al Tamimi briefing says 16 September 2014. Law No. 11 of 2025 added Article 8 bis on publishing images of people without consent (Pinsent Masons). The Arabic text in the Official Gazette governs.","country":"QA","id":"qa-law-14-2014","notes_en":["Article 14 lets the Public Prosecution, or an officer it authorises, search people, places and information systems under a reasoned and specific warrant that can be renewed.","Article 15 says evidence collected through IT techniques, systems, networks or electronic data may not be excluded because of its nature, and Article 16 accepts evidence gathered abroad through lawful international cooperation.","Articles 17 and 18 let the Public Prosecution order prompt collection of electronic, traffic or content data and order anyone to hand over relevant devices or data, and Article 19 requires seized devices and data to be protected until a judicial decision.","Article 21 requires service providers to keep user information for one year and to keep IT, traffic and content data on an urgent basis for 90 days, renewable at the request of the competent body or investigating authorities.","Article 22 requires state bodies to report crimes under the law, and unlawful attempts at capture, interception or spying, promptly to the competent authority at the Ministry of Interior, and to keep IT and user data for at least 120 days."],"source":{"name":"UNODC SHERLOC (unofficial translation by Squire Patton Boggs)","url":"https://sherloc.unodc.org/cld/uploads/res/document/the-cybercrime-prevention-law_html/Qatar_Cybercrime_Law_unofficial_translation.pdf"},"summary":{"ar":"هو قانون الجرائم الإلكترونية في دولة قطر وفيه فصل إجرائي كامل للدليل الإلكتروني وحفظه وواجبات مقدمي الخدمة لذا يُعد من أكثر النصوص الخليجية عوناً للفاحص.","en":"Qatar's cybercrime law, with a full procedural chapter on electronic evidence, preservation and service provider duties. It is one of the most examiner friendly texts in the GCC."},"title":{"ar":"القانون رقم 14 لسنة 2014 بإصدار قانون مكافحة الجرائم الإلكترونية","en":"Law No. 14 of 2014 Promulgating the Cybercrime Prevention Law"},"type":"law","verified":true,"year":2014},{"caveat_en":"The 72 hour deadline comes from Clyde & Co (March 2021) and DLA Piper (January 2024), and the current regulator from DLA Piper. Confirm the text against the Official Gazette.","country":"QA","id":"qa-law-13-2016","notes_en":["Issued 3 November 2016, with Article 30 giving those it covers six months from entry into force to comply.","Article 14 requires the controller to inform the individual and the competent department of any breach of the required safeguards that may cause serious harm to personal data or privacy.","Regulatory guidelines issued in November 2020 set the notification deadline at 72 hours.","The regulator is now the National Cyber Governance and Assurance Affairs within the National Cyber Security Agency."],"source":{"name":"Al Sharq newspaper (published law text, 3 November 2016)","url":"https://al-sharq.com/article/03/11/2016/%D8%A8%D9%88%D8%A7%D8%A8%D8%A9-%D8%A7%D9%84%D8%B4%D8%B1%D9%82-%D8%AA%D9%86%D8%B4%D8%B1-%D9%86%D8%B5-%D9%82%D8%A7%D9%86%D9%88%D9%86-%D8%AD%D9%85%D8%A7%D9%8A%D8%A9-%D8%AE%D8%B5%D9%88%D8%B5%D9%8A%D8%A9-%D8%A7%D9%84%D8%A8%D9%8A%D8%A7%D9%86%D8%A7%D8%AA-%D8%A7%D9%84%D8%B4%D8%AE%D8%B5%D9%8A%D8%A9"},"summary":{"ar":"هو قانون البيانات الشخصية في دولة قطر ويوجب على المتحكم إبلاغ الجهة المختصة والفرد معاً بالاختراقات الجسيمة وهذا يدفع إلى الفرز المبكر للحادثة وحفظ الأدلة.","en":"Qatar's personal data law. It requires controllers to notify both the regulator and the individual of serious breaches, which drives early incident triage and evidence capture."},"title":{"ar":"القانون رقم 13 لسنة 2016 بشأن حماية خصوصية البيانات الشخصية","en":"Law No. 13 of 2016 on the Protection of Personal Data Privacy"},"type":"law","verified":true,"year":2016},{"caveat_en":"The Amiri Decision number comes from a Gulf Times report (3 April 2021); the standard and breach role from Cisco and DLA Piper summaries. Who must report incidents to the NCSA, and by when, could not be verified, and ncsa.gov.qa returned no readable content.","country":"QA","id":"qa-ncsa-incident-2025","notes_en":["The agency was created by Amiri Decision No. 1 of 2021 to unify efforts to secure Qatar's cyberspace.","The National Incident Management Framework was launched in February 2025 for cyber incidents with national implications.","It has five stages: notification and categorisation, incident initiation, response and investigation, remediation and recovery, and closure and review.","Its components include command and control, detection and monitoring, investigation, national strategic response, system recovery and national incident review.","The agency also oversees the National Information Assurance Standard and, through its National Cyber Governance and Assurance Affairs, receives personal data breach notifications."],"source":{"name":"Qatar Tribune (19 February 2025)","url":"https://www.qatar-tribune.com/article/163854/nation/ncsa-launches-national-incident-management-framework"},"summary":{"ar":"تنسق الوكالة الوطنية للأمن السيبراني في قطر التعامل مع الحوادث وتصدر المعايير الوطنية ويحدد إطارها لعام 2025 مراحل التعامل مع الحوادث ذات الأهمية الوطنية ومنها التحقيق.","en":"Qatar's national cybersecurity agency coordinates incident handling and issues national standards. Its 2025 framework sets the stages for handling incidents of national significance, including investigation."},"title":{"ar":"الوكالة الوطنية للأمن السيبراني وإطار إدارة الحوادث الوطني","en":"National Cyber Security Agency (NCSA) and the National Incident Management Framework"},"type":"framework","verified":true,"year":2025},{"caveat_en":"Issued 30 September 2014 and in force one month after publication in the Official Gazette (Article 24). Article 14 separately lets a lower court judge order fast preservation and partial disclosure of traffic data. The Council of Europe lists Bahrain's Budapest Convention status as NA.","country":"BH","id":"bh-law-60-2014","notes_en":["Article 12 lets the Public Prosecution order urgent preservation of specific data, including traffic data, for up to 90 days, extendable by the High Criminal Court in chambers by up to another 90 days in total, and lets it order the recipient to keep the order confidential.","Article 13 allows production orders for stored data, and orders to service providers for subscriber information, excluding traffic and content data.","Article 15 allows entry and search of an information system and storage media, extended to a connected system where the data is reachable from the first.","Article 16 allows seizing systems or media, copying and keeping data, preserving its integrity and making it inaccessible, but not information the accused gave to their lawyer or adviser for the case or their correspondence.","Article 18 allows real time collection of traffic and content data with a lower court judge's authorisation for up to 30 days at a time, renewable.","Article 22 applies the criminal procedure law and treats IT data and systems as things, papers and documents under it."],"source":{"name":"Legislation and Legal Opinion Commission, Bahrain (English translation)","url":"https://www.lloc.gov.bh/FullEn/K6014.docx"},"summary":{"ar":"هو قانون الجرائم الإلكترونية في مملكة البحرين وفي فصله الإجرائي أدوات على نهج اتفاقية بودابست منها الحفظ العاجل وأوامر التقديم وتفتيش الحاسوب والضبط والجمع الآني.","en":"Bahrain's cybercrime law. Its procedural chapter provides Budapest style tools: expedited preservation, production orders, computer search, seizure and real time collection."},"title":{"ar":"القانون رقم 60 لسنة 2014 بشأن جرائم تقنية المعلومات","en":"Law No. 60 of 2014 on Information Technology Crimes"},"type":"law","verified":true,"year":2014},{"caveat_en":"The issue date and Arabic title were checked on the LLOC Arabic text (lloc.gov.bh/FullAr/K3018.docx), which brings the law into force on the first day of the month after one year from Gazette publication.","country":"BH","id":"bh-law-30-2018","notes_en":["Issued 12 July 2018 and in force from 1 August 2019.","Resolution No. 43 of 2022 requires controllers to notify the authority no later than 72 hours after becoming aware of a breach, unless it is unlikely to risk data subjects' rights.","Controllers must also inform data subjects of breaches in certain circumstances.","Ten ministerial resolutions issued on 17 March 2022 added rules on transfers, security measures, sensitive data, data protection officers, data subject rights and complaints."],"source":{"name":"Clyde & Co briefing (April 2022)","url":"https://www.clydeco.com/en/insights/2022/04/bahrain-issues-new-privacy-guidelines"},"summary":{"ar":"هو قانون حماية البيانات في البحرين تحت إشراف هيئة حماية البيانات الشخصية وأضاف قرار صدر في 2022 واجب الإبلاغ عن الاختراق خلال 72 ساعة.","en":"Bahrain's data protection law, supervised by the Personal Data Protection Authority. A 2022 resolution added a 72 hour breach notification duty."},"title":{"ar":"القانون رقم 30 لسنة 2018 بإصدار قانون حماية البيانات الشخصية","en":"Law No. 30 of 2018 issuing the Personal Data Protection Law"},"type":"law","verified":true,"year":2018},{"caveat_en":"Issued 1 June 2026, published in Official Gazette No. 1651 on 7 June 2026, and in force the next day. It repealed Royal Decree 12/2011. Qanoon.om says it is not an official source, so check the Gazette.","country":"OM","id":"om-rd-61-2026","notes_en":["Article 1 defines digital evidence as any electronic data or information with probative value that is stored, transmitted or extracted from an information system or IT means.","Article 3 gives judicial officer status to employees named by the competent authority in agreement with the Minister of Transport, Communications and Information Technology.","Article 4 lets the ministry, where there are sufficient reasons to believe an IT crime occurred, obtain electronic data from bodies inside and outside Oman on a judicial order from the Public Prosecution or the competent court, without prejudice to the Cyber Defense Center's powers.","Article 14 punishes hiding or refusing to give judicial officers the passwords of IT means used in a crime.","Article 15 punishes anyone responsible for digital evidence who hides it, refuses to hand it over or tampers with it, with 6 months to 3 years in prison and a fine of OMR 1,000 to 3,000.","Article 60 lets the court confiscate the devices, tools and software used and close the system, website or premises."],"source":{"name":"Qanoon.om (reproduction of the Official Gazette text)","url":"https://qanoon.om/p/2026/rd2026061/"},"summary":{"ar":"هو قانون الجرائم الإلكترونية الجديد في سلطنة عُمان النافذ منذ يونيو 2026 ويعرّف الدليل الرقمي ويمنح الوزارة طريقاً للحصول على البيانات بأمر قضائي ويجرّم إخفاء الدليل الرقمي أو العبث به.","en":"Oman's new cybercrime law, in force since June 2026. It defines digital evidence, gives the ministry a route to obtain data under judicial order, and makes hiding or tampering with digital evidence a crime."},"title":{"ar":"المرسوم السلطاني رقم 61/2026 بإصدار قانون مكافحة جرائم تقنية المعلومات","en":"Royal Decree No. 61/2026 issuing the Law on Combating Information Technology Crimes"},"type":"law","verified":true,"year":2026},{"caveat_en":"The text of the attached law sat behind a members only notice and was not reviewed. Whether it still governs acts committed before June 2026 depends on transitional rules that were not checked.","country":"OM","id":"om-rd-12-2011","notes_en":["Issued 6 February 2011, published in Official Gazette No. 929 on 15 February 2011, and in force the day after publication.","It repealed the cybercrime chapter (chapter two bis of book seven) of the earlier Omani Penal Law.","Royal Decree No. 61/2026 repealed it."],"source":{"name":"Decree.om","url":"https://decree.om/2011/rd20110012/"},"summary":{"ar":"هو قانون الجرائم الإلكترونية السابق في عُمان وقد أُلغي في يونيو 2026 لكنه يبقى مهماً للقضايا الأقدم وللبحوث المكتوبة قبل التغيير.","en":"Oman's earlier cybercrime law. It was repealed in June 2026 but remains relevant to older cases and to research written before the change."},"title":{"ar":"المرسوم السلطاني رقم 12/2011 بإصدار قانون مكافحة جرائم تقنية المعلومات وهو ملغى","en":"Royal Decree No. 12/2011 issuing the Cyber Crime Law (repealed)"},"type":"law","verified":true,"year":2011},{"caveat_en":"Article 19 and the decree details were checked on decree.om and qanoon.om. The article number of the 72 hour rule in the regulation was not confirmed.","country":"OM","id":"om-rd-6-2022","notes_en":["Issued 9 February 2022, published in Official Gazette No. 1429 on 13 February 2022, and set to take effect one year after issuance.","Article 19 requires the controller, when a breach leads to destruction, alteration, disclosure, access or unlawful processing of personal data, to notify the ministry and the data subject under the regulation's procedures.","The Executive Regulation (Ministerial Decision No. 34/2024) requires notice to the regulator within 72 hours, and to data subjects within 72 hours where serious harm or high risk is likely.","The transition period was extended by Ministerial Decision No. 6/2025 and ended on 5 February 2026."],"source":{"name":"CMS legal update","url":"https://cms.law/en/omn/legal-updates/oman-personal-data-protection-law-entering-the-enforcement-phase"},"summary":{"ar":"هو قانون حماية البيانات في عُمان تحت إشراف وزارة النقل والاتصالات وتقنية المعلومات ويشكّل واجب الإبلاغ عن الاختراق فيه وقاعدة 72 ساعة في لائحته التنفيذية طريقة الاستجابة للحوادث.","en":"Oman's data protection law, supervised by the Ministry of Transport, Communications and Information Technology. Its breach duty and the 72 hour rule in its executive regulation shape incident response."},"title":{"ar":"المرسوم السلطاني رقم 6/2022 بإصدار قانون حماية البيانات الشخصية","en":"Royal Decree No. 6/2022 issuing the Personal Data Protection Law"},"type":"law","verified":true,"year":2022},{"caveat_en":"Pairs with ISO/IEC 27041, 27042 and 27043 for the later stages of an investigation.","country":"INTL","id":"intl-iso-27037-2012","notes_en":["Covers identification, collection, acquisition and preservation of potential digital evidence.","Addresses storage media, mobile phones and other personal devices, navigation systems, digital cameras including CCTV, networked computers and TCP/IP networks, as an indicative list.","Meant to support organisational disciplinary procedures and the exchange of potential evidence between jurisdictions.","Published October 2012, and ISO lists it as current after review."],"source":{"name":"ISO","url":"https://www.iso.org/standard/44381.html"},"summary":{"ar":"هو الإرشاد الدولي الأساسي للمستجيبين الأوائل الذين يتعاملون مع أدلة رقمية محتملة ويستشهد به الفاحص ليبين أن الضبط والتصوير الجنائي والحفظ اتبعت منهجاً معترفاً به.","en":"The core international guideline for first responders handling potential digital evidence. Examiners cite it to show that seizure, imaging and preservation followed a recognised method."},"title":{"ar":"المعيار ISO/IEC 27037:2012 لإرشادات تحديد الأدلة الرقمية وجمعها والحصول عليها وحفظها","en":"ISO/IEC 27037:2012 Guidelines for identification, collection, acquisition and preservation of digital evidence"},"type":"framework","verified":true,"year":2012},{"caveat_en":"Source URL is the 27042 page; 27041 is at iso.org/standard/44405.html and 27043 at iso.org/standard/44407.html.","country":"INTL","id":"intl-iso-27041-27043-2015","notes_en":["ISO/IEC 27041:2015 guides assuring that investigative methods are fit for purpose, including validation and the use of vendor and third party testing.","ISO/IEC 27042:2015 covers analysis and interpretation of digital evidence so the work is continuous, valid, reproducible and repeatable, with enough records for independent review.","ISO/IEC 27043:2015 sets idealised models for incident investigation from pre-incident preparation to case closure.","ISO pages show systematic reviews in 2025 and 2026, so check for revisions before citing."],"source":{"name":"ISO","url":"https://www.iso.org/standard/44406.html"},"summary":{"ar":"هي ثلاثة معايير مرافقة للمعيار ISO/IEC 27037 تغطي التحقق من صحة أساليب التحقيق وتحليل الأدلة الرقمية وتفسيرها وعملية التحقيق في الحوادث كاملة.","en":"Three companion standards to ISO/IEC 27037. They cover validating investigative methods, analysing and interpreting digital evidence, and the overall incident investigation process."},"title":{"ar":"المعايير ISO/IEC 27041 و27042 و27043 لسنة 2015 بشأن أساليب التحقيق وتحليل الأدلة الرقمية وعمليات التحقيق","en":"ISO/IEC 27041, 27042 and 27043:2015 on investigative methods, analysis of digital evidence and investigation processes"},"type":"framework","verified":true,"year":2015},{"caveat_en":"SP 800-101 Rev. 1 page: csrc.nist.gov/pubs/sp/800/101/r1/final. Both are listed as final with no withdrawal notice.","country":"INTL","id":"intl-nist-sp800-86-101r1","notes_en":["SP 800-86, published August 2006, describes a four phase process of collection, examination, analysis and reporting.","SP 800-86 takes an IT rather than a law enforcement view and advises consulting legal counsel before applying its practices.","SP 800-101 Rev. 1, published May 2014, defines mobile device forensics as recovering digital evidence from a mobile device under forensically sound conditions.","SP 800-101 Rev. 1 outlines how to validate, preserve, collect, examine, analyse and report mobile device data, and replaced the 2007 edition."],"source":{"name":"NIST Computer Security Resource Center","url":"https://csrc.nist.gov/pubs/sp/800/86/final"},"summary":{"ar":"هما دليلان واسعا الاستشهاد إذ يضع SP 800-86 التحليل الجنائي داخل الاستجابة للحوادث ويغطي SP 800-101 Rev 1 استرجاع الأدلة من الأجهزة المحمولة في ظروف سليمة جنائياً.","en":"Two widely cited NIST guides. SP 800-86 places forensics inside incident response, and SP 800-101 Rev. 1 covers recovering evidence from mobile devices under forensically sound conditions."},"title":{"ar":"دليلا NIST SP 800-86 لدمج تقنيات التحليل الجنائي في الاستجابة للحوادث وSP 800-101 Rev 1 لإرشادات التحليل الجنائي للأجهزة المحمولة","en":"NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response) and SP 800-101 Rev. 1 (Guidelines on Mobile Device Forensics)"},"type":"framework","verified":true,"year":2006},{"caveat_en":"18-F-002 page: swgde.org/documents/published-complete-listing/18-f-002-swgde-best-practices-for-digital-evidence-collection/. The SWGDE listing shows a newer 18-F-002 version than that 2018 page, so cite the current version.","country":"INTL","id":"intl-swgde-best-practices","notes_en":["17-F-002 version 2.1 (5 August 2025) covers preparation, triage, physical, logical and live acquisition, forensic boot media, targeted collection, verification, documentation and preservation.","It is aimed at qualified personnel, is not a training manual and does not replace organisational policy.","It does not cover incident response, complex live acquisitions, complex disk arrays or hybrid storage devices.","18-F-002 covers collecting computers and other storage media, including preparation, scene search, documentation and storage, and leaves mobile devices to a separate SWGDE document."],"source":{"name":"SWGDE","url":"https://www.swgde.org/documents/published-complete-listing/17-f-002-2-1/"},"summary":{"ar":"هي وثائق أفضل الممارسات العملية الصادرة عن مجموعة العمل العلمية للأدلة الرقمية ويُستشهد بها كثيراً في خطوات الحصول على الأدلة وجمعها.","en":"Practitioner best practice documents from the Scientific Working Group on Digital Evidence. They are often cited for acquisition and collection steps."},"title":{"ar":"أفضل ممارسات SWGDE للحصول الجنائي على بيانات الحاسوب (17-F-002) ولجمع الأدلة الرقمية (18-F-002)","en":"SWGDE Best Practices for Computer Forensic Acquisition (17-F-002) and for Digital Evidence Collection (18-F-002)"},"type":"framework","verified":true,"year":2025},{"caveat_en":"Dates come from the Council of Europe milestones page (coe.int/en/web/cybercrime/milestones1). Morocco and Tunisia are the only Arab League states in the Parties list.","country":"INTL","id":"intl-budapest-2001","notes_en":["Opened for signature in Budapest on 23 November 2001 and in force since 1 July 2004.","The Council of Europe lists 83 Parties and 14 states that have signed or been invited to accede.","Kuwait, Saudi Arabia, the UAE, Qatar, Bahrain and Oman do not appear in any of these categories.","The Council of Europe Octopus pages list Kuwait's and Bahrain's status as NA.","The Second Additional Protocol on enhanced cooperation (CETS No. 224) opened for signature on 12 May 2022."],"source":{"name":"Council of Europe","url":"https://www.coe.int/web/cybercrime/the-budapest-convention"},"summary":{"ar":"هي المعاهدة الدولية الرئيسية للجريمة الإلكترونية والدليل الإلكتروني وليست أي دولة خليجية طرفاً فيها ولا موقعة عليها ولا مدعوة إليها وهذا يؤثر في طلبات الأدلة العابرة للحدود من الخليج وإليه.","en":"The main international treaty on cybercrime and electronic evidence. No GCC state is a party, signatory or invitee, which affects cross border evidence requests to and from the Gulf."},"title":{"ar":"اتفاقية مجلس أوروبا بشأن الجريمة الإلكترونية المعروفة باتفاقية بودابست رقم 185 في سلسلة المعاهدات الأوروبية","en":"Council of Europe Convention on Cybercrime (Budapest Convention, ETS No. 185)"},"type":"law","verified":true,"year":2001},{"caveat_en":"The ratification status of the other GCC states was not verified.","country":"INTL","id":"intl-arab-convention-2010","notes_en":["Signed in Cairo on 21 December 2010, with ratifications deposited with the General Secretariat of the League of Arab States.","Chapter III covers expedited preservation of stored data (Article 23), expedited preservation and partial disclosure of traffic data (Article 24) and orders to submit information (Article 25).","It also covers search of stored information (Article 26), seizure of stored information (Article 27), expedited gathering of traffic data (Article 28) and interception of content (Article 29).","Kuwait ratified it by Law No. 60 of 2013, according to the explanatory memorandum of Law No. 63 of 2015."],"source":{"name":"National Security Archive (English translation of the Convention)","url":"https://nsarchive.gwu.edu/sites/default/files/documents/5975835/National-Security-Archive-Arab-Convention-on.pdf"},"summary":{"ar":"هي معاهدة جامعة الدول العربية للجرائم الإلكترونية ونظيرة اتفاقية بودابست في المنطقة وقد صادقت عليها الكويت وتفسر موادها الإجرائية أدوات الحفظ والتفتيش الموجودة في عدد من القوانين الخليجية.","en":"The Arab League's cybercrime treaty and the regional counterpart to the Budapest Convention. Kuwait ratified it, and its procedural articles explain the preservation and search tools found in several Gulf laws."},"title":{"ar":"الاتفاقية العربية لمكافحة جرائم تقنية المعلومات لسنة 2010","en":"Arab Convention on Combating Information Technology Offences (2010)"},"type":"law","verified":true,"year":2010}],"media":[{"caption":{"ar":"القصّاص يقرأ الأثر عند الفجر","en":"The tracker reads the trail at dawn"},"id":"01-hero-tracker"},{"caption":{"ar":"أثر القدم يصبح بيانات","en":"A footprint becomes data"},"id":"02-footprint-hex"},{"caption":{"ar":"التصوير الجنائي عبر مانع الكتابة","en":"Imaging through a write blocker"},"id":"03-write-blocker"},{"caption":{"ar":"هاتف مختوم في حقيبة أدلة","en":"A sealed phone in an evidence bag"},"id":"04-evidence-bag"},{"caption":{"ar":"كل تسليم يُسجَّل في السجل","en":"Every handover goes in the log"},"id":"05-custody-handover"},{"caption":{"ar":"الذاكرة تتلاشى عند الإطفاء","en":"Memory vanishes at power off"},"id":"06-memory-motes"},{"caption":{"ar":"قطع على القرص غمر الرمل بعضها","en":"Plots on the disk, some swept by sand"},"id":"07-filesystem-aerial"},{"caption":{"ar":"أحداث مرتبة كأوتاد المساحة","en":"Events in order, like survey stakes"},"id":"08-timeline-stakes"},{"caption":{"ar":"السجلات تتذكر","en":"Logs and the registry remember"},"id":"09-archive-ledgers"},{"caption":{"ar":"إشارة بإيقاع ثابت","en":"A signal at a steady beat"},"id":"10-network-beacon"},{"caption":{"ar":"هاتف على طاولة الفاحص","en":"A phone on the examiner's bench"},"id":"11-mobile-bench"},{"caption":{"ar":"آثار صغيرة يمكن قراءتها","en":"Small tracks that can still be read"},"id":"12-malware-tracks"},{"caption":{"ar":"كل فعل يترك أثراً","en":"Every action leaves a trace"},"id":"poster-01-traces"},{"caption":{"ar":"منهج القصّاص","en":"The tracker's method"},"id":"poster-02-tracker"},{"caption":{"ar":"الحفظ والتصوير الجنائي","en":"Preservation and imaging"},"id":"poster-03-imaging"},{"caption":{"ar":"بتّ واحد يغيّر البصمة","en":"One bit changes the fingerprint"},"id":"poster-04-hash"},{"caption":{"ar":"سلسلة الحيازة","en":"The chain of custody"},"id":"poster-05-custody"},{"caption":{"ar":"خط زمني واحد لكل المصادر","en":"One timeline for every source"},"id":"poster-06-timeline"},{"caption":{"ar":"تقرير تتابعه المحكمة","en":"A report a court can follow"},"id":"poster-07-report"}],"modules":[{"commands":["qassas glossary locard","qassas lab make --out qassas-case-01"],"hours":2,"id":"foundations","image":"02-footprint-hex","kuwait":{"ar":"في الكويت يمنح القانون رقم 63 لسنة 2015 النيابة العامة وحدها سلطة التحقيق في جرائم تقنية المعلومات لذا يجب أن يجري الفحص الداخلي في الشركة بطريقة تسمح بتسليمه سليماً.","en":"In Kuwait, Law No. 63 of 2015 gives the Public Prosecution sole power to investigate IT crimes, so a company's internal examination should be done in a way that can be handed over intact."},"lab":null,"law_refs":["kw-law-63-2015","intl-iso-27037-2012"],"lesson":[{"ar":"كان قصّاص الأثر الكويتي يقرأ أثر قدم واحد فيعرف من مرّ وكم كان حمله ومنذ متى عبر والتحليل الجنائي الرقمي يطرح الأسئلة نفسها على الحاسوب.","en":"A Kuwaiti tracker could read a single footprint and say who passed, how heavy their load was and how long ago they walked by. Digital forensics asks the same questions of a computer."},{"ar":"ينص مبدأ لوكار للتبادل على أن كل تماس يترك أثراً فعلى الجهاز يكتب فتح ملف أو توصيل ذاكرة USB أو زيارة موقع سجلات في أماكن عدة في وقت واحد.","en":"Locard's exchange principle says every contact leaves a trace. On a device, opening a file, plugging in a USB stick or visiting a site writes records in several places at once."},{"ar":"وتمر العملية بخمس مراحل هي تحديد الأدلة ثم حفظها دون تغيير ثم الحصول على نسخة موثقة منها ثم تحليل النسخة ثم عرض النتائج بطريقة يستطيع غيرك تكرارها.","en":"The process has five stages: identify the evidence, preserve it unchanged, acquire a verified copy, analyse the copy, and present findings others can repeat."},{"ar":"تريد الاستجابة للحوادث إيقاف الهجوم بسرعة بينما يريد التحليل الجنائي حفظ كل أثر لذا يخطط الفريق الجيد للأمرين معاً كي لا يتلف الاحتواء الأدلة.","en":"Incident response wants the attack stopped fast, while forensics wants every trace kept. A good team plans both so that containment does not destroy the evidence."}],"n":1,"objectives":[{"ar":"شرح العملية الجنائية من التحديد حتى العرض","en":"Explain the forensic process from identification to presentation"},{"ar":"تطبيق مبدأ لوكار على الحواسيب والهواتف","en":"Apply Locard's principle to computers and phones"},{"ar":"التمييز بين الفحص الجنائي والاستجابة للحادثة","en":"Tell a forensic examination apart from an incident response"}],"pitfalls":[{"ar":"البدء بالتحليل قبل حفظ الأدلة وهذا قد يغيّر الطوابع الزمنية ويتلف البيانات المحذوفة.","en":"Starting analysis before the evidence is preserved, which can change timestamps and destroy deleted data."},{"ar":"تقرير الجواب مسبقاً ثم البحث عن الأدلة التي توافقه وحدها.","en":"Deciding on the answer first and then looking only for evidence that fits it."}],"quiz":[{"answer":1,"options":[{"ar":"لأن قراءة النسخ أسرع","en":"Copies are faster to read"},{"ar":"ليبقى الأصل دون تغيير ويمكن فحصه مرة أخرى","en":"So the original stays unchanged and can be checked again"},{"ar":"لأن القانون يمنع فتح الأجهزة","en":"Because the law forbids opening devices"},{"ar":"لتوفير مساحة التخزين","en":"To save storage space"}],"q":{"ar":"لماذا يعمل الفاحص على نسخة بدلاً من الأصل","en":"Why does an examiner work on a copy rather than the original"},"why":{"ar":"قد تغيّر أي أداة البيانات التي تفتحها والإبقاء على الأصل سليماً يتيح لأي شخص التحقق من النسخة بمقارنتها به لاحقاً.","en":"Any tool can change data it opens. Keeping the original untouched lets anyone verify the copy against it later."}},{"answer":2,"options":[{"ar":"أن الملفات المحذوفة لا تُسترجع","en":"Deleted files cannot be recovered"},{"ar":"أن المسؤولين وحدهم يتركون آثاراً","en":"Only administrators leave traces"},{"ar":"أن كل فعل يكتب أثراً في مكان ما","en":"Every action writes a trace somewhere"},{"ar":"أن السجلات كاملة دائماً","en":"Logs are always complete"}],"q":{"ar":"ماذا يعني مبدأ لوكار على الحاسوب","en":"What does Locard's principle mean on a computer"},"why":{"ar":"يحدّث الفتح والنسخ والتصفح السجلات والذاكرة المؤقتة وقواعد البيانات والطوابع الزمنية وهذا ما يقرؤه الفاحص.","en":"Opening, copying or browsing updates logs, caches, databases and timestamps, which is what examiners read."}}],"steps":[{"ar":"اعمل على النسخ ولا تعمل على الأصل أبداً","en":"Work on copies, never on the original"},{"ar":"احسب بصمة كل شيء قبل أن تلمسه وبعده","en":"Hash everything before and after you touch it"},{"ar":"دوّن كل إجراء مع وقته","en":"Write down every action with its time"},{"ar":"لا تذكر في التقرير إلا ما تدعمه الأدلة","en":"Report only what the evidence supports"}],"summary":{"ar":"ما التحليل الجنائي الرقمي وكيف يخدم الاستجابة للحوادث والقانون وما القواعد الأربع التي يعمل بها كل فاحص.","en":"What digital forensics is, how it serves incident response and the law, and the four rules every examiner works by."},"terms":["digital-forensics","dfir","digital-evidence","locard","qassas-al-athar"],"title":{"ar":"قراءة الأثر","en":"Reading the trace"},"tools":["autopsy","cyberchef"]},{"commands":["qassas law --country KW","qassas law --country SA"],"hours":2,"id":"law","image":"09-archive-ledgers","kuwait":{"ar":"صادقت الكويت على الاتفاقية العربية لمكافحة جرائم تقنية المعلومات وليست طرفاً في اتفاقية بودابست وهذا يحدد طريقة انتقال الأدلة عبر الحدود.","en":"Kuwait ratified the Arab Convention on Combating Information Technology Offences but is not a party to the Budapest Convention, which shapes how evidence moves across borders."},"lab":null,"law_refs":["kw-law-63-2015","kw-law-20-2014","kw-law-17-1960","kw-cassation-536-2003","kw-citra-dppr-26-2024","intl-arab-convention-2010"],"lesson":[{"ar":"يعرّف القانون رقم 63 لسنة 2015 جرائم تقنية المعلومات في الكويت ويمنح القانون رقم 20 لسنة 2014 السجلات الإلكترونية حجية الورق في الإثبات متى استوفت شروطه.","en":"Law No. 63 of 2015 defines Kuwait's IT crimes, and Law No. 20 of 2014 gives electronic records the same evidential force as paper when they meet its conditions."},{"ar":"ولا يتضمن قانون الإجراءات الجزائية وهو القانون رقم 17 لسنة 1960 مواد مكتوبة للحاسوب فيخضع تفتيش الأجهزة لقواعده العامة في التفتيش والضبط والخبرة.","en":"The criminal procedure code, Law No. 17 of 1960, has no articles written for computers, so searches of devices follow its general rules on search, seizure and experts."},{"ar":"وللمحكمة الكلمة الأخيرة في ما ينتهي إليه الخبير لذا يجب أن يشرح التقرير منهجه بوضوح يتيح للقاضي متابعته واختباره.","en":"Courts have the final word on an expert's findings, so a report must explain its method plainly enough that a judge can follow and test it."},{"ar":"وتضيف قوانين حماية البيانات في الخليج مهلاً قصيرة للإبلاغ تكون غالباً 24 أو 72 ساعة لذا يجب أن تنتج الساعات الأولى من الحادثة سجلات موثقة أيضاً.","en":"Across the Gulf, data protection laws add short reporting clocks, often 24 or 72 hours, so the first hours of an incident must also produce records."}],"n":2,"objectives":[{"ar":"تسمية القوانين الكويتية التي تحكم جرائم تقنية المعلومات والدليل الإلكتروني","en":"Name the Kuwaiti laws that govern IT crimes and electronic evidence"},{"ar":"شرح طريقة وزن المحكمة لتقرير الخبير","en":"Explain how a court weighs an expert report"},{"ar":"ذكر مهل الإبلاغ عن الاختراق في دول الخليج","en":"List breach reporting deadlines across the GCC"}],"pitfalls":[{"ar":"فحص الهاتف الشخصي للموظف دون موافقته أو دون أمر وهذا قد يجعل الدليل غير صالح ويعرّض الشركة للمساءلة.","en":"Examining an employee's personal phone without consent or an order, which can make the evidence unusable and expose the company."},{"ar":"افتراض أن مهلة الجهة الرقابية تبدأ عند انتهاء التحقيق لا عند اكتشاف الاختراق.","en":"Assuming a regulator's deadline starts when the investigation ends rather than when the breach was found."}],"quiz":[{"answer":0,"options":[{"ar":"القانون رقم 20 لسنة 2014","en":"Law No. 20 of 2014"},{"ar":"القانون رقم 16 لسنة 1960","en":"Law No. 16 of 1960"},{"ar":"القانون رقم 106 لسنة 2013","en":"Law No. 106 of 2013"},{"ar":"القانون رقم 9 لسنة 2001","en":"Law No. 9 of 2001"}],"q":{"ar":"أي قانون كويتي يمنح السجلات الإلكترونية حجية في الإثبات","en":"Which Kuwaiti law gives electronic records evidential force"},"why":{"ar":"يعامل قانون المعاملات الإلكترونية وهو القانون رقم 20 لسنة 2014 السجلات الإلكترونية معاملة الورق متى استوفت شروطه.","en":"The Electronic Transactions Law, Law No. 20 of 2014, treats electronic records like paper when they meet its conditions."}},{"answer":2,"options":[{"ar":"الخبير","en":"The expert"},{"ar":"الشركة التي استعانت بالخبير","en":"The company that hired the expert"},{"ar":"المحكمة","en":"The court"},{"ar":"الجهة الرقابية","en":"The regulator"}],"q":{"ar":"من يقرر في النهاية إن كانت نتائج الخبير معتبرة","en":"Who decides in the end whether an expert's findings hold"},"why":{"ar":"تعدّ المحاكم الكويتية رأي الخبير عنصراً من عناصر الإثبات وتحتفظ لنفسها بالتقدير النهائي.","en":"Kuwaiti courts treat expert opinion as one element of proof and keep the final assessment for themselves."}}],"steps":[{"ar":"تأكد ممن يملك صلاحية جمع الأدلة","en":"Confirm who has authority to collect the evidence"},{"ar":"سجّل السند القانوني لكل تفتيش","en":"Record the legal basis for every search"},{"ar":"ابدأ حساب مهلة الإبلاغ لحظة الاكتشاف","en":"Start the notification clock at discovery"},{"ar":"اقتصر من البيانات الشخصية على ما تحتاجه القضية","en":"Keep personal data you find to the minimum the case needs"}],"summary":{"ar":"ما القوانين التي تجعل الدليل الرقمي مقبولاً ومن يحق له التحقيق وما المهل التي يبدأ حسابها حين تُكتشف الحادثة.","en":"Which laws make digital evidence admissible, who may investigate, and which deadlines start the clock when an incident is found."},"terms":["public-prosecution","breach-notification","expert-report"],"title":{"ar":"القانون في الكويت والخليج","en":"The law in Kuwait and the Gulf"},"tools":[]},{"commands":["qassas glossary volatility"],"hours":2,"id":"seizure","image":"04-evidence-bag","kuwait":{"ar":"يوجب قانون الإجراءات الكويتي توثيق التفتيش والضبط وتطبق محكمة التمييز هذه القواعد العادية على الحواسيب والأقراص.","en":"Kuwait's procedure code requires searches and seizures to be recorded, and the Court of Cassation applies those ordinary rules to computers and discs."},"lab":null,"law_refs":["kw-law-17-1960","kw-cassation-24-2008","intl-iso-27037-2012","intl-swgde-best-practices"],"lesson":[{"ar":"مهمة المستجيب الأول أن يمنع الموقع من التغير فيبعد الناس عن الأجهزة ويصوّر الشاشات والكابلات ويدوّن ما يعمل وما هو مطفأ.","en":"The first responder's job is to stop the scene from changing: keep people away from the devices, photograph screens and cables, and note what is on and what is off."},{"ar":"واجمع الأدلة حسب ترتيب التطاير لأن الذاكرة واتصالات الشبكة الحية تختفي عند الإطفاء فإن كان الجهاز يعمل واحتاجتها القضية فالتقطها قبل أي شيء آخر.","en":"Collect in order of volatility. Memory and live network connections vanish at power off, so if a machine is running and the case needs them, capture them before anything else."},{"ar":"وقد يصبح الجهاز المشفر بالكامل غير قابل للقراءة بعد إطفائه لذا تحقق من التشفير قبل فصل التيار.","en":"A running machine with full disk encryption may be unreadable once powered off, so check for encryption before you pull the plug."},{"ar":"ويوضع الهاتف في حقيبة فاراداي فوراً كي لا يُمسح عن بُعد ثم يُعبأ كل دليل ويُختم بختم مرقّم ويُسجَّل.","en":"Phones go into a Faraday bag at once so they cannot be wiped remotely, and every item is bagged, sealed with a numbered seal and logged."}],"n":3,"objectives":[{"ar":"تطبيق ترتيب التطاير","en":"Apply the order of volatility"},{"ar":"تقرير إطفاء الجهاز أو إبقائه يعمل","en":"Decide whether to power a device off or keep it running"},{"ar":"ختم الأدلة وتوسيمها بالشكل الصحيح","en":"Seal and label evidence correctly"}],"pitfalls":[{"ar":"السماح لفريق تقنية المعلومات بالدخول والتجول قبل جمع الأدلة وهذا يكتب فوق السجلات والطوابع الزمنية.","en":"Letting the IT team log in to look around before evidence is collected, which overwrites logs and timestamps."},{"ar":"إطفاء الخادم إطفاءً عادياً لأن ذلك يشغّل مهام تنظيف تتلف الآثار التي تحتاجها.","en":"Shutting down a server normally, which runs cleanup tasks that destroy the very traces you need."}],"quiz":[{"answer":1,"options":[{"ar":"سطوع الشاشة","en":"The screen brightness"},{"ar":"حاجتك إلى الذاكرة أو البيانات المفتوحة أولاً","en":"Whether you need memory or unlocked data first"},{"ar":"مستوى البطارية فقط","en":"The battery level only"},{"ar":"لا شيء بل أطفئه فوراً دائماً","en":"Nothing, always switch off at once"}],"q":{"ar":"حاسوب يعمل وقرصه مشفر بالكامل فما الذي تتحقق منه قبل إطفائه","en":"A running laptop has full disk encryption. What should you check before switching it off"},"why":{"ar":"بعد الإطفاء قد يبقى القرص المشفر مقفلاً وتضيع الذاكرة لذا التقط ما تحتاجه وهو مفتوح.","en":"Once powered off, the encrypted disk may stay locked and the memory is lost, so capture what you need while it is unlocked."}},{"answer":1,"options":[{"ar":"لإبقائه دافئاً","en":"To keep it warm"},{"ar":"لحجب المسح عن بُعد والرسائل الجديدة","en":"To block remote wipes and new messages"},{"ar":"لشحنه","en":"To charge it"},{"ar":"لفك قفله","en":"To unlock it"}],"q":{"ar":"لماذا يوضع الهاتف المضبوط في حقيبة فاراداي","en":"Why does a seized phone go into a Faraday bag"},"why":{"ar":"تحجب الحقيبة الإشارات اللاسلكية فلا يستطيع أحد مسح الهاتف عن بُعد ولا تكتب البيانات الجديدة فوق القديمة.","en":"The bag blocks radio signals, so nobody can wipe the phone remotely and new data cannot overwrite old data."}}],"steps":[{"ar":"أمّن المكان وسجّل الحاضرين","en":"Secure the area and record who is present"},{"ar":"صوّر الموقع قبل أن تلمس شيئاً","en":"Photograph the scene before touching anything"},{"ar":"التقط البيانات المتطايرة إن احتاجتها القضية","en":"Capture volatile data if the case needs it"},{"ar":"اعزل الهواتف في حقيبة فاراداي","en":"Isolate phones in a Faraday bag"},{"ar":"اختم كل دليل وابدأ سجل حيازته","en":"Seal each item and start its custody log"}],"summary":{"ar":"كيف تؤمّن الموقع وتصوّره وتقرر ما تجمعه أولاً وتختم كل دليل بحيث لا يشكك فيه أحد لاحقاً.","en":"How to secure a scene, photograph it, decide what to collect first and seal each item so nobody can doubt it later."},"terms":["first-responder","order-of-volatility","seizure","faraday-bag","evidence-bag","volatile-data"],"title":{"ar":"في موقع الحادثة","en":"At the scene"},"tools":["velociraptor","avml","winpmem"]},{"commands":["qassas hash qassas-case-01/evidence/laptop.img","qassas manifest verify qassas-case-01/manifest.json --root qassas-case-01/evidence"],"hours":3,"id":"acquisition","image":"03-write-blocker","kuwait":{"ar":"يطلب إطار المرونة الصادر عن بنك الكويت المركزي من المؤسسات الخاضعة لرقابته حساب البصمات وتسجيل أعمال الفحص لذا تُعد هذه الخطوات متطلباً في القطاع المالي.","en":"The Central Bank of Kuwait's resilience framework asks regulated institutions for hashing and logging of forensic work, so these steps are an expectation in the financial sector."},"lab":"hash","law_refs":["kw-cbk-corf-2025","intl-iso-27037-2012","intl-swgde-best-practices"],"lesson":[{"ar":"يقع مانع الكتابة بين القرص وحاسوب الفاحص فيمرر القراءة ويوقف كل كتابة فلا تستطيع حتى نقرة خاطئة أن تغيّر الدليل.","en":"A write blocker sits between the drive and the examiner's computer and lets reads through but stops every write, so even a careless click cannot change the evidence."},{"ar":"وتنسخ الصورة الجنائية كل قطاع بما فيها الملفات المحذوفة والمساحة غير المخصصة التي يفوّتها النسخ العادي.","en":"The image copies every sector, including deleted files and unallocated space, which a normal file copy would miss."},{"ar":"والبصمة تشبه بصمة الإصبع للبيانات فإن تغيّر بتّ واحد تغيّرت بصمة SHA-256 كلياً لذا يثبت تساوي بصمتي المصدر والصورة أنهما متطابقتان.","en":"A hash is a fingerprint of the data. If one bit changes, SHA-256 changes completely, so equal hashes of source and image prove they are identical."},{"ar":"واحسب البصمة عند الحصول على الصورة واكتبها في سجل الحيازة وسجل البصمات ثم احسبها مرة أخرى قبل كل تحليل ليرى الجميع أن شيئاً لم يتغير بينهما.","en":"Hash at acquisition, write the values in the custody log and the manifest, and hash again before each analysis so anyone can see nothing changed in between."}],"n":4,"objectives":[{"ar":"تصوير القرص عبر مانع الكتابة","en":"Image a drive through a write blocker"},{"ar":"حساب بصمات MD5 وSHA-1 وSHA-256 ومقارنتها","en":"Compute and compare MD5, SHA-1 and SHA-256"},{"ar":"كتابة سجل بصمات الأدلة والتحقق منه","en":"Write and verify an evidence manifest"}],"pitfalls":[{"ar":"الاعتماد على MD5 وحدها مع إمكان تزويرها بالتصادمات بدلاً من تسجيل SHA-256 معها.","en":"Relying on MD5 alone, which can be forged with collisions, instead of recording SHA-256 as well."},{"ar":"حساب بصمة الصورة وحدها دون المصدر وهذا لا يثبت شيئاً عن صحة النسخة.","en":"Hashing only the image and not the source, which proves nothing about the copy."}],"quiz":[{"answer":2,"options":[{"ar":"تبقى كما هي","en":"It stays the same"},{"ar":"يتغير آخر حرف فيها","en":"Its last character changes"},{"ar":"تتغير كلياً","en":"It changes completely"},{"ar":"تصبح أقصر","en":"It becomes shorter"}],"q":{"ar":"تغيّر بتّ واحد في صورة حجمها 2 GB فماذا يحدث لبصمة SHA-256","en":"One bit of a 2 GB image changes. What happens to its SHA-256"},"why":{"ar":"توزّع دوال التجزئة الجيدة أي تغيير على القيمة كلها لذا يظهر البتّ الواحد المعدّل بوضوح.","en":"Good hash functions spread any change across the whole value, which is why a single altered bit is obvious."}},{"answer":1,"options":[{"ar":"يشفر القرص","en":"Encrypts the drive"},{"ar":"يسمح بالقراءة ويوقف كل كتابة","en":"Allows reads and stops every write"},{"ar":"يسرّع النسخ","en":"Speeds up copying"},{"ar":"يحذف الملفات المخفية","en":"Deletes hidden files"}],"q":{"ar":"ما وظيفة مانع الكتابة","en":"What does a write blocker do"},"why":{"ar":"يحمي الأصل من أي تغيير بما فيه الكتابات الصغيرة التي تجريها أنظمة التشغيل من تلقاء نفسها.","en":"It protects the original from any change, including the small writes operating systems make on their own."}}],"steps":[{"ar":"صِل المصدر عبر مانع الكتابة","en":"Connect the source through a write blocker"},{"ar":"احسب بصمة المصدر","en":"Hash the source"},{"ar":"اكتب الصورة على وسيط تخزين نظيف","en":"Write the image to clean storage"},{"ar":"احسب بصمة الصورة وقارنها","en":"Hash the image and compare"},{"ar":"سجّل القيمتين في سجل الحيازة وسجل البصمات","en":"Record both values in the custody log and the manifest"}],"summary":{"ar":"كيف تأخذ نسخة مطابقة بتّاً ببتّ عبر مانع الكتابة وتثبت بالبصمات أن النسخة تساوي المصدر.","en":"How to make a bit for bit copy through a write blocker and prove with hashes that the copy equals the source."},"terms":["write-blocker","forensic-image","raw-image","e01","hash","sha256","verification","manifest"],"title":{"ar":"التصوير الجنائي والبصمات","en":"Imaging and hashing"},"tools":["guymager","libewf","sleuthkit"]},{"commands":["qassas custody verify qassas-case-01/custody/custody.jsonl","qassas custody verify qassas-case-01/custody/custody_archive_copy.jsonl"],"hours":2,"id":"custody","image":"05-custody-handover","kuwait":{"ar":"يذكر إطار بنك الكويت المركزي سلسلة الحيازة ضمن متطلباته الجنائية للمؤسسات الخاضعة لرقابته.","en":"The Central Bank of Kuwait's framework names chain of custody among its forensic requirements for regulated institutions."},"lab":"custody","law_refs":["kw-cbk-corf-2025","kw-law-17-1960","intl-iso-27037-2012"],"lesson":[{"ar":"يجيب سجل الحيازة عن أربعة أسئلة في كل لحظة من حياة الدليل هي من حازه ومتى وأين وماذا فعل به.","en":"A custody record answers four questions for every moment of an item's life: who had it, when, where and what they did with it."},{"ar":"والفجوة أو الوقت الخاطئ يمنحان الدفاع سبباً للقول إن الدليل ربما تغيّر حتى لو لم يتغير.","en":"A gap or a wrong time gives the defence a reason to argue the evidence could have been changed, even when it was not."},{"ar":"ويكتب قصّاص السجل سلسلةً من البصمات فيحفظ كل قيد بصمة SHA-256 للقيد الذي قبله وتغطي بصمته الخاصة كل حقوله.","en":"Qassas writes the log as a hash chain: each entry stores the SHA-256 of the previous entry, and its own hash covers all its fields."},{"ar":"فإن تغيّر أي حقل لاحقاً انكسرت بصمة ذلك القيد وإن حُذف قيد انكسر ارتباط القيد الذي يليه فيحدد المدقق الموضع بالضبط.","en":"Changing any field later breaks that entry's hash, and deleting an entry breaks the link of the next one, so the verifier names the exact place."}],"n":5,"objectives":[{"ar":"كتابة قيد حيازة كامل","en":"Write a complete custody entry"},{"ar":"شرح سبب حمل كل قيد بصمة القيد الذي قبله","en":"Explain why each entry carries the hash of the one before"},{"ar":"تحديد القيد المعدّل بالضبط","en":"Find the exact entry that was altered"}],"pitfalls":[{"ar":"تصحيح خطأ إملائي في قيد قديم بدلاً من إضافة قيد تصحيحي جديد وهذا يجعل السجل يبدو معبوثاً به.","en":"Fixing a typo in an old entry instead of adding a new correcting entry, which makes the log look tampered with."},{"ar":"حفظ السجل في جدول بيانات يستطيع أي شخص تعديله دون أن يترك أثراً.","en":"Keeping the log in a spreadsheet anyone can edit without a trace."}],"quiz":[{"answer":1,"options":[{"ar":"القيد 1","en":"Entry 1"},{"ar":"القيد 5","en":"Entry 5"},{"ar":"كل القيود","en":"Every entry"},{"ar":"لا شيء","en":"None"}],"q":{"ar":"عدّل شخص الوقت في القيد 5 من سجل مسلسل بالبصمات فأي قيد يفشل","en":"Someone edits the time in entry 5 of a hash chained log. Which entry fails"},"why":{"ar":"لم تعد البصمة المخزنة في القيد 5 تطابق محتواه أما القيد التالي فما زال يشير إلى البصمة القديمة المخزنة فيتحدد الكسر في القيد 5.","en":"Entry 5's stored hash no longer matches its content. The next entry still points to the old stored hash, so the break is located at entry 5."}},{"answer":2,"options":[{"ar":"عدّل القيد القديم","en":"Edit the old entry"},{"ar":"احذف السجل وابدأ من جديد","en":"Delete the log and start again"},{"ar":"أضف قيداً جديداً يشرح التصحيح","en":"Add a new entry that explains the correction"},{"ar":"تجاهله","en":"Ignore it"}],"q":{"ar":"ما الطريقة الصحيحة لتصحيح خطأ في سجل الحيازة","en":"What is the right way to correct a mistake in a custody log"},"why":{"ar":"السجلات تُضاف إليها القيود ولا تُعدّل والقيد الجديد يحفظ صدق التاريخ وسلامة السلسلة.","en":"Logs are append only. A new entry keeps the history honest and the chain intact."}}],"steps":[{"ar":"افتح السجل لحظة ضبط الدليل","en":"Open a log the moment the item is seized"},{"ar":"سجّل كل تسليم باسمي الطرفين","en":"Record every handover with both names"},{"ar":"اكتب أرقام الأختام عند الختم والفتح","en":"Write seal numbers when sealing and opening"},{"ar":"أضف بصمة الصورة عند الحصول عليها","en":"Add the image hash at acquisition"},{"ar":"تحقق من السلسلة قبل أن تشهد","en":"Verify the chain before you testify"}],"summary":{"ar":"كيف تسجّل كل عملية تسليم بحيث يُتتبع الدليل من الضبط حتى المحكمة وكيف تكشف سلسلة البصمات أي تعديل خفي في السجل.","en":"How to record every handover so the evidence can be traced from seizure to court, and how a hash chain exposes a quietly edited log."},"terms":["chain-of-custody","evidence-bag","hash"],"title":{"ar":"سلسلة الحيازة","en":"Chain of custody"},"tools":["cyberchef"]},{"commands":["qassas identify qassas-case-01/evidence","qassas carve qassas-case-01/evidence/laptop.img carved"],"hours":3,"id":"filesystems","image":"07-filesystem-aerial","kuwait":{"ar":"إخفاء المستند بتغيير اسمه شائع في قضايا التسريب ويشدد القانون رقم 63 لسنة 2015 العقوبة على إفشاء البيانات التي تم الحصول عليها بالدخول غير المشروع.","en":"Hiding a document by renaming it is common in leak cases, and Law No. 63 of 2015 treats disclosure of data obtained through illegal access more severely."},"lab":"signature","law_refs":["kw-law-63-2015"],"lesson":[{"ar":"يحتفظ نظام الملفات بفهرس للأسماء ولمواضع بياناتها كأنها قطع أرض مخططة في الرمل وأسماء ملاكها في دفتر.","en":"A file system keeps an index of names and the places their data lives, much like plots marked out in the sand with the owners' names in a ledger."},{"ar":"ويزيل حذف الملف غالباً قيده في الفهرس فقط ويعلّم مساحته بأنها فارغة فتبقى البايتات حتى يُكتب فوقها ملف جديد.","en":"Deleting a file usually removes only its entry in the index and marks the space as free. The bytes stay until a new file is written over them."},{"ar":"وتبدأ كل صيغة ببايتات ثابتة تسمى التوقيع فالملف المسمى invoice.jpg الذي يبدأ بالحرفين PK هو أرشيف ZIP لا صورة.","en":"Every format starts with fixed bytes called a signature. A file named invoice.jpg that starts with PK is a ZIP archive, not a photo."},{"ar":"ويبحث النحت في البيانات الخام عن هذه التواقيع وعن النهايات المقابلة لها فيسترجع الملفات حتى إن ضاع الفهرس.","en":"Carving searches raw data for those signatures and the matching ends, and recovers files even when the index is gone."}],"n":6,"objectives":[{"ar":"تحديد نوع الملف من توقيعه","en":"Identify a file by its signature"},{"ar":"شرح ما يزيله الحذف فعلاً","en":"Explain what deletion really removes"},{"ar":"نحت الملفات من المساحة غير المخصصة","en":"Carve files from unallocated space"}],"pitfalls":[{"ar":"الثقة بامتداد الملف الذي يستطيع أي شخص تغييره في ثانية.","en":"Trusting the extension, which anyone can change in a second."},{"ar":"إيقاف نحت صورة JPEG عند أول علامة نهاية وهذا يقطع الصورة عند الصورة المصغرة المضمنة فيها.","en":"Stopping a JPEG carve at the first end marker, which cuts the photo at its embedded thumbnail."}],"quiz":[{"answer":1,"options":[{"ar":"مستند PDF","en":"A PDF document"},{"ar":"صورة JPEG","en":"A JPEG image"},{"ar":"أرشيف ZIP","en":"A ZIP archive"},{"ar":"برنامج Windows","en":"A Windows program"}],"q":{"ar":"ملف اسمه report.pdf يبدأ بالبايتات FF D8 FF فما هو","en":"A file called report.pdf begins with the bytes FF D8 FF. What is it"},"why":{"ar":"البايتات FF D8 FF هي توقيع صور JPEG أما ملف PDF الحقيقي فيبدأ بـ %PDF.","en":"FF D8 FF is the JPEG signature. A real PDF starts with %PDF."}},{"answer":1,"options":[{"ar":"لأن الحذف ينقلها إلى مجلد مخفي","en":"Deletion moves them to a hidden folder"},{"ar":"لأن قيد الفهرس يزول وتبقى البايتات حتى يُكتب فوقها","en":"The index entry goes but the bytes stay until overwritten"},{"ar":"لأن Windows يحفظ نسختين من كل ملف","en":"Windows keeps two copies of every file"},{"ar":"لا يمكن استرجاعها","en":"They cannot be recovered"}],"q":{"ar":"لماذا يمكن غالباً استرجاع الملفات المحذوفة","en":"Why can deleted files often be recovered"},"why":{"ar":"تُعلَّم المساحة بأنها فارغة فقط ويبقى المحتوى القديم حتى يُكتب فيها شيء جديد.","en":"The space is only marked free. Until something new is written there, the old content survives."}}],"steps":[{"ar":"حدد نوع كل ملف من محتواه لا من اسمه","en":"Identify every file by content, not name"},{"ar":"اجمع الملفات التي يختلف اسمها عن محتواها","en":"List the files whose name and content disagree"},{"ar":"انحت المساحة غير المخصصة بحثاً عن الصيغ المعروفة","en":"Carve unallocated space for known formats"},{"ar":"احسب بصمة كل ملف منحوت ودوّن موضعه","en":"Hash every carved file and note its offset"}],"summary":{"ar":"كيف تخزّن أنظمة الملفات الملفات وتنساها وكيف تكشف ملفاً يكذب اسمه بشأن نوعه وكيف تستعيد الملفات المحذوفة بالنحت من البايتات الخام.","en":"How file systems store and forget files, how to spot a file whose name lies about its type, and how to carve deleted files back from raw bytes."},"terms":["file-system","file-signature","unallocated","slack-space","carving"],"title":{"ar":"الملفات والتواقيع والنحت","en":"Files, signatures and carving"},"tools":["sleuthkit","autopsy","photorec","bulk-extractor","scalpel"]},{"commands":["qassas meta qassas-case-01/evidence/Pictures/IMG_2038.jpg","qassas meta qassas-case-01/evidence/Documents/Tender_2026_Final.pdf"],"hours":2,"id":"metadata","image":"poster-02-tracker","kuwait":{"ar":"يجرّم القانون رقم 9 لسنة 2001 والقانون رقم 63 لسنة 2015 التصوير خلسة وإساءة استخدامه لذا كثيراً ما تكون البيانات الوصفية للصور في قلب القضايا الكويتية.","en":"Law No. 9 of 2001 and Law No. 63 of 2015 make secret photography and its misuse a crime, so photo metadata often sits at the centre of Kuwaiti cases."},"lab":"exif","law_refs":["kw-law-9-2001","kw-law-63-2015"],"lesson":[{"ar":"تحمل صورة الهاتف عادةً طراز الجهاز ووقت الالتقاط مع فرق المنطقة الزمنية وإحداثيات GPS دقيقة إلى بضعة أمتار.","en":"A phone photo usually carries the device model, the time it was taken with its zone offset, and GPS coordinates accurate to a few metres."},{"ar":"ويحوّل قصّاص الإحداثيات إلى أقرب منطقة كويتية مثل السالمية أو الجهراء ليرى الطالب فوراً إن كان المكان يوافق الرواية.","en":"Qassas turns coordinates into the nearest Kuwaiti area, such as Salmiya or Jahra, so a student can see at once whether the place fits the story."},{"ar":"وتسجّل ملفات PDF المؤلف والبرنامج المستخدم وتاريخي الإنشاء والتعديل ويضيف كل حفظ تراكمي علامة نهاية ملف جديدة تكشف التعديلات اللاحقة.","en":"PDFs record an author, the software used and creation and modification dates. Each incremental save adds another end of file marker, which reveals later edits."},{"ar":"والبيانات الوصفية سهلة التعديل فهي خيط يقود إلى الدليل لا دليل قاطع لذا أكدها بمصدر مستقل كقيد في سجل أو أثر في الشبكة.","en":"Metadata is easy to edit, so it is a lead, not proof. Confirm it with something independent, such as a log entry or a network record."}],"n":7,"objectives":[{"ar":"قراءة وقت الصورة وإحداثياتها من بيانات EXIF","en":"Read EXIF time and GPS from a photo"},{"ar":"اكتشاف النسخ المحفوظة داخل ملف PDF","en":"Find revisions inside a PDF"},{"ar":"تعزيز البيانات الوصفية بمصدر ثانٍ","en":"Corroborate metadata with a second source"}],"pitfalls":[{"ar":"قراءة وقت EXIF دون فرقه الزمني وافتراض أنه UTC وهذا يزيح وقت صورة كويتية ثلاث ساعات.","en":"Reading an EXIF time without its offset and assuming UTC, which shifts a Kuwaiti photo by three hours."},{"ar":"عدّ حقل المؤلف في ملف PDF دليلاً على كاتب المستند.","en":"Treating the PDF author field as proof of who wrote the document."}],"quiz":[{"answer":1,"options":[{"ar":"22:12","en":"22:12"},{"ar":"16:12","en":"16:12"},{"ar":"19:12","en":"19:12"},{"ar":"13:12","en":"13:12"}],"q":{"ar":"تقول صورة إن وقتها 19:12 بفرق +03:00 فما الوقت بالتوقيت العالمي","en":"A photo says 19:12 with offset +03:00. What is the time in UTC"},"why":{"ar":"تسبق الكويت التوقيت العالمي بثلاث ساعات لذا اطرح 3 ساعات من 19:12.","en":"Kuwait is three hours ahead of UTC, so subtract 3 hours from 19:12."}},{"answer":1,"options":[{"ar":"على أن الملف تالف","en":"The file is corrupt"},{"ar":"على أن الملف حُفظ مرة أخرى بعد كتابته أول مرة","en":"The file was saved again after it was first written"},{"ar":"على أن الملف مشفر","en":"The file is encrypted"},{"ar":"على أن للملف مؤلفين","en":"The file has two authors"}],"q":{"ar":"علامَ تدل علامة نهاية ملف ثانية في ملف PDF","en":"What does a second end of file marker in a PDF suggest"},"why":{"ar":"يضيف الحفظ التراكمي التغييرات وعلامة نهاية جديدة لذا يمكن أحياناً استرجاع النسخ الأقدم أيضاً.","en":"An incremental save appends changes and a new end marker, so earlier versions can sometimes be recovered too."}}],"steps":[{"ar":"استخرج البيانات الوصفية من كل صورة ومستند","en":"Extract metadata from every photo and document"},{"ar":"حوّل كل وقت إلى UTC مع فرقه الزمني","en":"Convert every time to UTC with its offset"},{"ar":"ضع إحداثيات GPS على الخريطة","en":"Place GPS fixes on a map"},{"ar":"ابحث عن مصدر ثانٍ لكل واقعة رئيسية","en":"Look for a second source for each key fact"}],"summary":{"ar":"كيف تسجّل الصور وملفات PDF وملفات Office مؤلفها وبرنامجها ووقتها ومكانها وكيف تقرأ ذلك دون أن تثق به ثقة عمياء.","en":"How photos, PDFs and Office files record their author, software, time and place, and how to read that without trusting it blindly."},"terms":["metadata","exif","timestamp"],"title":{"ar":"البيانات الوصفية أين ومتى","en":"Metadata: where and when"},"tools":["exiftool","cyberchef"]},{"commands":["qassas lnk qassas-case-01/evidence/Recent/Tender_Update.lnk","qassas logs qassas-case-01/evidence/Logs/LAPTOP-FHD01_security.jsonl"],"hours":3,"id":"windows","image":"12-malware-tracks","kuwait":{"ar":"ترفع الضوابط الوطنية الأساسية للأمن السيبراني في الكويت مستوى التسجيل المتوقع من الجهات الحكومية والحيوية وهذا يحدد ما سيوجد من أدلة Windows بعد الحادثة.","en":"Kuwait's national cybersecurity baseline raises the logging expected from government and critical bodies, which decides what Windows evidence will exist after an incident."},"lab":null,"law_refs":["kw-ncsc-nbcc-2026","sa-nca-ecc-2-2024"],"lesson":[{"ar":"حين يفتح المستخدم ملفاً يكتب Windows اختصاراً في مجلد العناصر الأخيرة يحمل مسار الهدف وحجمه ووحدة التخزين وأوقاته ويحتفظ به بعد حذف الملف.","en":"When a user opens a file, Windows writes a shortcut in the Recent folder with the target's path, size, volume and times, and keeps it after the file is deleted."},{"ar":"وتبين ملفات Prefetch أن برنامجاً عمل وعدد مرات تشغيله وآخر أوقات تشغيله وهذا يساعد على تأريخ تشغيل البرمجية الخبيثة.","en":"Prefetch files show that a program ran, how many times and its last run times, which helps date malware execution."},{"ar":"ويسرد السجل أجهزة USB التي وُصّلت يوماً والمستندات المفتوحة مؤخراً والبرامج المضبوطة للعمل مع بدء Windows وهي مخبأ مفضل للبرمجيات الخبيثة.","en":"The registry lists USB devices ever connected, recently opened documents and the programs set to start with Windows, a favourite hiding place for malware."},{"ar":"ويسجّل الحدث الأمني 4688 العمليات الجديدة ويسجّل الحدث 7045 الخدمات الجديدة ويسجّل الحدث 1102 أن أحداً مسح السجل.","en":"Security event 4688 records new processes, 7045 records a new service, and 1102 records that someone cleared the log."}],"n":8,"objectives":[{"ar":"إثبات فتح المستخدم ملفاً باختصار LNK","en":"Prove a user opened a file with an LNK shortcut"},{"ar":"إثبات تشغيل برنامج ووقته","en":"Show that a program ran and when"},{"ar":"العثور على أجهزة USB وآليات البقاء في السجل","en":"Find USB devices and persistence in the registry"}],"pitfalls":[{"ar":"فتح ملف سجل المشتبه به بمحرر سجل حي وهذا قد يغيّره.","en":"Opening a suspect's registry hive with a live registry editor, which can change it."},{"ar":"استنتاج أن شيئاً لم يحدث لأن السجل الأمني فارغ بينما الفراغ نفسه علامة على المسح.","en":"Concluding nothing happened because the security log is empty, when the empty log is itself a sign of clearing."}],"quiz":[{"answer":2,"options":[{"ar":"4624","en":"4624"},{"ar":"4688","en":"4688"},{"ar":"1102","en":"1102"},{"ar":"7045","en":"7045"}],"q":{"ar":"أي حدث أمني في Windows يدل على مسح السجل","en":"Which Windows security event shows the log was cleared"},"why":{"ar":"يُكتب الحدث 1102 حين يُمسح السجل الأمني ويذكر الحساب الذي مسحه.","en":"Event 1102 is written when the security log is cleared, and it names the account that did it."}},{"answer":1,"options":[{"ar":"لا لأنه يُحذف معه","en":"No, it is deleted too"},{"ar":"نعم لأنه يحتفظ بالمسار والحجم والأوقات","en":"Yes, it keeps the path, size and times"},{"ar":"فقط في Windows 7","en":"Only on Windows 7"},{"ar":"فقط إن كان الملف على USB","en":"Only if the file was on USB"}],"q":{"ar":"حُذف الملف الهدف فهل يبقى اختصاره LNK مفيداً","en":"The target file is deleted. Can its LNK shortcut still help"},"why":{"ar":"تبقى الاختصارات بعد زوال أهدافها لذا تثبت أن الملف كان موجوداً وأنه فُتح.","en":"Shortcuts outlive their targets, which is why they prove a file existed and was opened."}}],"steps":[{"ar":"حلّل كل اختصار في مجلدات العناصر الأخيرة","en":"Parse every shortcut in the Recent folders"},{"ar":"افحص ملفات Prefetch بحثاً عن برامج غير متوقعة","en":"Check prefetch for unexpected programs"},{"ar":"راجع مفاتيح التشغيل التلقائي والخدمات","en":"Review run keys and services"},{"ar":"ابحث في سجلات الأحداث عن الخدمات الجديدة والسجلات الممسوحة","en":"Search the event logs for new services and cleared logs"}],"summary":{"ar":"الأماكن التي يسجّل فيها Windows ما فتحه المستخدم وما شغّله وما وصّله وهي الاختصارات وملفات Prefetch والسجل وسجلات الأحداث.","en":"The places Windows records what a user opened, ran and plugged in: shortcuts, prefetch, the registry and the event logs."},"terms":["registry","lnk-file","prefetch","event-log"],"title":{"ar":"آثار Windows","en":"Windows artifacts"},"tools":["regripper","chainsaw","hayabusa","eztools","velociraptor","yara","capa"]},{"commands":["qassas logs qassas-case-01/evidence/Logs/srv-files_auth.log --year 2026"],"hours":2,"id":"logs","image":"poster-06-timeline","kuwait":{"ar":"تحدد الضوابط الأساسية في السعودية حداً أدنى لحفظ السجلات وترفع الضوابط الوطنية في الكويت واجبات التسجيل وكلاهما يحدد المدى الذي يبلغه التحقيق في الماضي.","en":"Saudi Arabia's essential controls set minimum log retention and Kuwait's national baseline raises logging duties, and both decide how far back an investigation can see."},"lab":null,"law_refs":["sa-nca-ecc-2-2024","kw-ncsc-nbcc-2026","kw-law-63-2015"],"lesson":[{"ar":"يسجّل Linux تسجيلات دخول SSH في الملف auth.log ويسجّل Windows الدخول في الحدثين 4624 للنجاح و4625 للفشل مع عنوان المصدر في كل منهما.","en":"Linux records SSH logins in auth.log, and Windows records logons as events 4624 for success and 4625 for failure, each with the source address."},{"ar":"والإخفاقات الكثيرة من عنوان واحد في دقائق تعني التخمين أما الدخول الناجح من العنوان نفسه بعدها مباشرة فهو اللحظة الأهم.","en":"Many failures from one address in minutes is guessing. A success from that same address right after is the moment that matters most."},{"ar":"وقد يكون الدخول الناجح بكلمة المرور الصحيحة دون إخفاقات مهاجماً يستخدم بيانات سُرقت بالتصيد لذا قارن عنوان المصدر بالأماكن المعتادة للمستخدم.","en":"A success with the right password and no failures can still be an attacker using credentials stolen by phishing, so compare the source address with the user's usual places."},{"ar":"ولا تحمل أسطر Syslog السنة ولا المنطقة الزمنية لذا تأكد من المنطقة الزمنية للخادم من إعداداته قبل تحويل أي وقت إلى UTC.","en":"Syslog lines carry no year and no zone, so confirm the server's time zone from its configuration before you convert anything to UTC."}],"n":9,"objectives":[{"ar":"تحليل أحداث دخول SSH وWindows","en":"Parse SSH and Windows logon events"},{"ar":"رصد دخول ناجح يتلو سلسلة إخفاقات","en":"Spot a success that follows a burst of failures"},{"ar":"التعامل الصحيح مع المناطق الزمنية في السجلات","en":"Handle log time zones correctly"}],"pitfalls":[{"ar":"افتراض أن كل السجلات بتوقيت UTC وهذا يزيح أحداث الكويت ثلاث ساعات.","en":"Assuming every log is in UTC, which misplaces Kuwaiti events by three hours."},{"ar":"النظر إلى الإخفاقات وحدها وتفويت الدخول الناجح الهادئ الذي جاء بعدها.","en":"Looking only at failures and missing the quiet success that came later."}],"quiz":[{"answer":1,"options":[{"ar":"دخول فاشل واحد ليلاً","en":"One failed login at night"},{"ar":"إخفاقات كثيرة ثم دخول ناجح من العنوان نفسه","en":"Many failures then a success from the same address"},{"ar":"تسجيل خروج","en":"A logoff"},{"ar":"تغيير كلمة مرور من فريق التقنية","en":"A password change by IT"}],"q":{"ar":"أي نمط يستحق الاهتمام الأعجل","en":"Which pattern deserves the most urgent attention"},"why":{"ar":"يدل على أن التخمين نجح أو أن المهاجم انتقل إلى كلمة مرور مسروقة.","en":"It suggests the guessing worked or the attacker switched to a stolen password."}},{"answer":0,"options":[{"ar":"06:27:03","en":"06:27:03"},{"ar":"12:27:03","en":"12:27:03"},{"ar":"09:27:03","en":"09:27:03"},{"ar":"03:27:03","en":"03:27:03"}],"q":{"ar":"سطر في auth.log يقول Oct 4 09:27:03 على خادم مضبوط على توقيت الكويت فكم الوقت بالتوقيت العالمي","en":"An auth.log line reads Oct 4 09:27:03 on a server set to Kuwait time. What is that in UTC"},"why":{"ar":"توقيت الكويت هو UTC+03:00 لذا تقابل الساعة 09:27:03 في الكويت الساعة 06:27:03 بالتوقيت العالمي.","en":"Kuwait is UTC+03:00, so 09:27:03 in Kuwait is 06:27:03 UTC."}}],"steps":[{"ar":"اجمع السجلات من كل نظام له صلة","en":"Collect logs from every system involved"},{"ar":"تأكد من المنطقة الزمنية لكل جهاز ومن انحراف ساعته","en":"Confirm each host's time zone and clock drift"},{"ar":"صنّف الإخفاقات حسب عنوان المصدر","en":"Group failures by source address"},{"ar":"علّم الدخول الناجح من عناوين التخمين","en":"Flag successes from guessing addresses"}],"summary":{"ar":"كيف تقرأ سجلات المصادقة في Linux وWindows لتكشف تخمين كلمات المرور وبيانات الدخول المسروقة ومحاولات إخفاء الأثر.","en":"How to read authentication logs from Linux and Windows to find password guessing, stolen credentials and attempts to cover tracks."},"terms":["event-log","brute-force","utc"],"title":{"ar":"السجلات وتسجيلات الدخول","en":"Logs and logins"},"tools":["chainsaw","hayabusa","sigma","timesketch"]},{"commands":[],"hours":3,"id":"memory","image":"06-memory-motes","kuwait":{"ar":"يستطيع المركز الوطني للأمن السيبراني في الكويت توجيه فرق الاستجابة في الحوادث الكبرى لذا اتفقوا مسبقاً على من يلتقط الذاكرة وكيف تُسلَّم.","en":"Kuwait's national center can direct response teams during major incidents, so agree in advance who captures memory and how it is handed over."},"lab":null,"law_refs":["kw-ncsc-decree-37-2022","intl-nist-sp800-86-101r1"],"lesson":[{"ar":"تعيش بعض البرمجيات الخبيثة في الذاكرة وحدها دون أن تكتب ملفاً وكثيراً ما توجد مفاتيح التشفير ومقاطع المحادثات وأسطر الأوامر هناك فقط.","en":"Some malware lives only in memory and never writes a file, and encryption keys, chat fragments and command lines often exist only there."},{"ar":"وتختفي الذاكرة كسراب الحر حين ينقطع التيار لذا تُلتقط أولاً بأداة صغيرة موثوقة تعمل من وسيط خارجي.","en":"Memory disappears like heat shimmer when the power goes, so it is captured first, with a small trusted tool run from external media."},{"ar":"وتغيّر أي أداة التقاط قليلاً من الذاكرة بنفسها لذا سجّل بدقة الأداة التي شغلتها وإصدارها ووقت تشغيلها.","en":"Any capture tool changes a little memory itself, so record exactly which tool and version you ran and when."},{"ar":"ويقرأ Volatility الالتقاط فيسرد العمليات وآباءها والاتصالات المفتوحة والشيفرة المحمّلة وينبّه إلى مناطق الذاكرة التي تبدو محقونة.","en":"Volatility reads the capture to list processes, their parents, open connections and loaded code, and flags memory that looks injected."}],"n":10,"objectives":[{"ar":"التقاط الذاكرة من Windows وLinux","en":"Capture memory from Windows and Linux"},{"ar":"سرد العمليات واتصالات الشبكة من الالتقاط","en":"List processes and network connections from a capture"},{"ar":"التعرف على شيفرة محقونة في عملية","en":"Recognise code injected into a process"}],"pitfalls":[{"ar":"تشغيل أداة كبيرة من قرص الجهاز المشتبه به نفسه وهذا يكتب فوق الذاكرة الحرة التي تريدها.","en":"Running a large tool from the suspect machine's own disk, which overwrites the free memory you wanted."},{"ar":"الثقة بقائمة العمليات التي يعرضها النظام الحي مع أن أداة التخفي قد تخفي منها عمليات.","en":"Trusting the process list the live system shows, which a rootkit can hide entries from."}],"quiz":[{"answer":1,"options":[{"ar":"لأن ذلك يصغّر صورة القرص","en":"It makes the disk image smaller"},{"ar":"لأن الذاكرة تضيع عند الإطفاء وقد تحوي مفاتيح وبرمجيات بلا ملفات","en":"Memory is lost at power off and may hold keys and fileless malware"},{"ar":"لأن القانون يوجبه في كل قضية","en":"The law requires it in every case"},{"ar":"لأنه أسرع","en":"It is faster"}],"q":{"ar":"لماذا تلتقط الذاكرة قبل فصل التيار","en":"Why capture memory before pulling the plug"},"why":{"ar":"الذاكرة أكثر الأدلة تطايراً وبعض ما فيها لا يوجد في أي مكان آخر.","en":"Memory is the most volatile evidence, and some of it exists nowhere else."}},{"answer":1,"options":[{"ar":"اسم الملف فقط","en":"Only the file name"},{"ar":"الأداة وإصدارها والوقت وبصمة الالتقاط","en":"The tool, its version, the time and the hash of the capture"},{"ar":"لا شيء لأن الذاكرة ليست دليلاً","en":"Nothing, memory is not evidence"},{"ar":"دقة الشاشة","en":"The screen resolution"}],"q":{"ar":"ما الذي يجب تسجيله عند التقاط الذاكرة","en":"What must you record when you capture memory"},"why":{"ar":"تغيّر الأداة قليلاً من الذاكرة لذا تحتاج المحكمة إلى معرفة ما شُغّل بالضبط ومتى.","en":"The tool changes a little memory, so a court needs to know exactly what ran and when."}}],"steps":[{"ar":"التقط الذاكرة قبل أن تطفئ أي شيء","en":"Capture memory before you shut anything down"},{"ar":"احسب بصمة الالتقاط وسجّل الأداة المستخدمة","en":"Hash the capture and log the tool used"},{"ar":"اسرد العمليات وقارن آباءها بالآباء المعتادين","en":"List processes and compare parents with normal ones"},{"ar":"طابق الاتصالات المفتوحة مع أدلة الشبكة","en":"Match open connections to the network evidence"}],"summary":{"ar":"لماذا تحوي الذاكرة أدلة لا يراها القرص أبداً وكيف تلتقطها من جهاز يعمل وعمّ تبحث في الالتقاط.","en":"Why memory holds evidence the disk never sees, how to capture it from a live machine and what to look for in the capture."},"terms":["memory-forensics","volatile-data","order-of-volatility"],"title":{"ar":"التحليل الجنائي للذاكرة","en":"Memory forensics"},"tools":["volatility3","avml","winpmem","lime"]},{"commands":["qassas pcap qassas-case-01/evidence/Network/capture.pcap"],"hours":3,"id":"network","image":"10-network-beacon","kuwait":{"ar":"يخضع اعتراض الاتصالات في الكويت للقانون رقم 37 لسنة 2014 والقانون رقم 9 لسنة 2001 لذا التقط الحركة على الشبكات التي تملكها أو بسند قانوني واضح.","en":"Interception of communications in Kuwait falls under Law No. 37 of 2014 and Law No. 9 of 2001, so capture on networks you own or under a clear legal basis."},"lab":null,"law_refs":["kw-law-37-2014","kw-law-9-2001","bh-law-60-2014"],"lesson":[{"ar":"حتى حين يكون المحتوى مشفراً يُظهر الالتقاط من تحدث مع من ومتى وكم دام الاتصال وكم أُرسل.","en":"Even when content is encrypted, the capture shows who talked to whom, when, for how long and how much they sent."},{"ar":"وتنتقل استعلامات DNS واسم الخادم في كل مصافحة TLS نصاً واضحاً فتكشف المواقع التي زارها الجهاز.","en":"DNS lookups and the server name in each TLS handshake travel in clear text, so they reveal the sites a machine visited."},{"ar":"وتتصل البرمجية الخبيثة بخادم التحكم وفق مؤقت كفانوس يومض في الصحراء بإيقاع ثابت والفواصل التي لا تكاد تتغير هي ما يفضحها.","en":"Malware checks in with its command server on a timer, like a lantern flashing in the desert at a steady beat. Gaps that barely vary give it away."},{"ar":"والطلب الكبير من نوع POST إلى خادم غير مألوف لا سيما بعد فتح ملف حساس مباشرة هو العلامة التقليدية لتسريب البيانات.","en":"A large POST to an unfamiliar host, especially right after a sensitive file was opened, is the classic sign of exfiltration."}],"n":11,"objectives":[{"ar":"استخراج استعلامات DNS وأسماء خوادم TLS","en":"Extract DNS lookups and TLS server names"},{"ar":"كشف الاتصال الدوري من التوقيت وحده","en":"Detect beaconing from timing alone"},{"ar":"استرجاع ملف أُرسل عبر HTTP غير مشفر","en":"Recover a file sent over clear HTTP"}],"pitfalls":[{"ar":"تجاهل الحركة المشفرة لأن محتواها لا يُقرأ مع أن التوقيت والأسماء ما زالت تروي القصة.","en":"Ignoring encrypted traffic because the content cannot be read, when timing and names still tell the story."},{"ar":"الالتقاط من منفذ خاطئ في المحوّل وتفويت حركة الجهاز المشتبه به.","en":"Capturing on the wrong switch port and missing the suspect machine's traffic."}],"quiz":[{"answer":1,"options":[{"ar":"شخص يتصفح","en":"A person browsing"},{"ar":"اتصال دوري آلي بخادم تحكم","en":"Automated beaconing to a command server"},{"ar":"شبكة بطيئة","en":"A slow network"},{"ar":"طابعة","en":"A printer"}],"q":{"ar":"تحدث اتصالات بخادم واحد كل 60 ثانية دون تغيّر يُذكر فعلامَ يدل ذلك","en":"Connections to one host happen every 60 seconds with almost no variation. What does that suggest"},"why":{"ar":"سلوك البشر غير منتظم أما المؤقت الثابت فيشير إلى برنامج والبرنامج المجهول الذي يتصل وفق مؤقت هو قناة تحكم تقليدية.","en":"People are irregular. A steady timer points to software, and unknown software calling out on a timer is a classic command channel."}},{"answer":2,"options":[{"ar":"لا شيء إطلاقاً","en":"Nothing at all"},{"ar":"محتوى الصفحة كاملاً","en":"The full page content"},{"ar":"اسم الخادم والتوقيت وحجم البيانات","en":"The server name, timing and amount of data"},{"ar":"كلمة مرور المستخدم","en":"The user's password"}],"q":{"ar":"ما الذي يمكن معرفته من جلسة TLS مشفرة","en":"What can you still learn from an encrypted TLS session"},"why":{"ar":"تحمل المصافحة اسم الخادم نصاً واضحاً وتبقى أوقات الحزم وأحجامها ظاهرة دائماً.","en":"The handshake carries the server name in clear text, and packet times and sizes are always visible."}}],"steps":[{"ar":"احسب بصمة الالتقاط قبل فتحه","en":"Hash the capture before opening it"},{"ar":"رتّب المحادثات حسب حجم البيانات","en":"List conversations by bytes"},{"ar":"استخرج أسماء DNS وأسماء خوادم TLS","en":"Extract DNS names and TLS server names"},{"ar":"قِس توقيت الاتصالات المتكررة","en":"Measure the timing of repeated connections"},{"ar":"انحت الملفات من الجلسات غير المشفرة","en":"Carve files from clear text sessions"}],"summary":{"ar":"كيف تقرأ التقاط الحزم بحثاً عن استعلامات الأسماء والاتصالات المشفرة وعمليات الرفع والنبض المنتظم للبرمجية الخبيثة وهي تتصل بخادمها.","en":"How to read a packet capture for lookups, encrypted connections, uploads and the regular heartbeat of malware calling home."},"terms":["pcap","beaconing","c2","sni","ioc"],"title":{"ar":"التحليل الجنائي للشبكات","en":"Network forensics"},"tools":["wireshark","zeek","suricata"]},{"commands":["qassas browser qassas-case-01/evidence/Browser/History"],"hours":2,"id":"browser","image":"poster-01-traces","kuwait":{"ar":"كثيراً ما تُستهدف البنوك والوزارات الكويتية بالنطاقات المشابهة والاحتيال الإلكتروني جريمة بموجب القانون رقم 63 لسنة 2015.","en":"Kuwaiti banks and ministries are frequent targets of lookalike domains, and online fraud is an offence under Law No. 63 of 2015."},"lab":null,"law_refs":["kw-law-63-2015","ae-fdl-34-2021"],"lesson":[{"ar":"تحفظ متصفحات Chromium السجل في ملف SQLite اسمه History وفيه كل رابط وكل زيارة ووقتها إضافة إلى التنزيلات وكلمات البحث.","en":"Chromium browsers keep history in an SQLite file called History, with every URL, every visit and its time, plus downloads and search terms."},{"ar":"وانسخ قاعدة البيانات دائماً قبل فتحها لأن SQLite قد يكتب في الملف بمجرد فتحه.","en":"Always copy the database before opening it, because SQLite can write to a file just by opening it."},{"ar":"ويسجّل كل تنزيل الصفحة التي كان المستخدم عليها والصفحة المحيلة فيربط الملف على القرص بالرابط الذي نُقر.","en":"Each download records the page the user was on and the referrer, which links the file on disk back to the link that was clicked."},{"ar":"وتنسخ نطاقات التصيد اسماً موثوقاً مع تغيير صغير ككلمة زائدة أو شرطة لذا اقرأ كل نطاق حرفاً حرفاً.","en":"Phishing domains copy a trusted name with a small change, such as an extra word or a hyphen, so read each domain letter by letter."}],"n":12,"objectives":[{"ar":"قراءة سجل Chromium وFirefox بأمان","en":"Read Chromium and Firefox history safely"},{"ar":"ربط التنزيل بالصفحة التي قادت إليه","en":"Tie a download to the page that led to it"},{"ar":"التعرف على النطاقات المشابهة","en":"Recognise lookalike domains"}],"pitfalls":[{"ar":"فتح ملف History الأصلي في متصفح أو عارض يحدّثه.","en":"Opening the live History file in a browser or viewer that updates it."},{"ar":"قراءة أوقات WebKit على أنها أوقات Unix وهذا يضع الأحداث في قرن آخر.","en":"Reading WebKit times as Unix times, which puts events in the wrong century."}],"quiz":[{"answer":1,"options":[{"ar":"portal.company.example","en":"portal.company.example"},{"ar":"company-login.example","en":"company-login.example"},{"ar":"mail.company.example","en":"mail.company.example"},{"ar":"company.example","en":"company.example"}],"q":{"ar":"أي نطاق هو الأرجح نسخة تصيد من company.example","en":"Which domain is most likely a phishing copy of company.example"},"why":{"ar":"النطاق company-login.example نطاق منفصل يستطيع أي شخص تسجيله أما الأخرى فأسماء تحت النطاق الحقيقي.","en":"company-login.example is a separate domain anyone can register. The others are names under the real domain."}},{"answer":1,"options":[{"ar":"لأنه أكبر من أن يُقرأ مباشرة","en":"It is too large to read directly"},{"ar":"لأن SQLite قد يكتب في الملف عند فتحه","en":"SQLite may write to the file when it opens it"},{"ar":"لأن المتصفح يقفله إلى الأبد","en":"The browser locks it forever"},{"ar":"لأنه مشفر","en":"It is encrypted"}],"q":{"ar":"لماذا تنسخ ملف History قبل قراءته","en":"Why copy the History file before reading it"},"why":{"ar":"قد يعيد الفتح تطبيق ملف اليومية أو يحدّث الملف وهذا يغيّر الدليل.","en":"Opening can replay a journal or update the file, which would change the evidence."}}],"steps":[{"ar":"انسخ قاعدة بيانات السجل وملف اليومية التابع لها","en":"Copy the history database and its journal"},{"ar":"اسرد الزيارات حول وقت الحادثة","en":"List visits around the time of the incident"},{"ar":"طابق التنزيلات مع صفحاتها المحيلة","en":"Match downloads with their referrer pages"},{"ar":"قارن كل نطاق بالنطاق الحقيقي","en":"Compare every domain with the real one"}],"summary":{"ar":"كيف يُظهر سجل التصفح والتنزيلات وعمليات البحث الطريق من رابط التصيد إلى الجهاز المخترق.","en":"How browser history, downloads and searches show the path from a phishing link to a compromised machine."},"terms":["browser-history","phishing","typosquatting","sqlite"],"title":{"ar":"المتصفحات والتصيد","en":"Browsers and phishing"},"tools":["hindsight","unfurl","cyberchef"]},{"commands":[],"hours":3,"id":"mobile","image":"11-mobile-bench","kuwait":{"ar":"تحمل الهواتف بيانات شخصية لأشخاص خارج القضية لذا احتفظ بما يحتاجه التحقيق فقط كما تتوقع قواعد حماية البيانات في الخليج.","en":"Phones carry personal data of people outside the case, so keep only what the investigation needs, as the data protection rules across the Gulf expect."},"lab":null,"law_refs":["kw-citra-dppr-26-2024","intl-nist-sp800-86-101r1","qa-law-14-2014"],"lesson":[{"ar":"يوضع الهاتف المضبوط في حقيبة فاراداي فوراً ويبقى مشحوناً لأن إعادة التشغيل قد تقفل البيانات خلف التشفير.","en":"A seized phone goes into a Faraday bag at once and stays charged, because a reboot can lock data away behind encryption."},{"ar":"ويجمع الاستخراج المنطقي ما تتيحه النسخة الاحتياطية بينما يصل الاستخراج الكامل لنظام الملفات إلى قواعد بيانات التطبيقات والسجلات المحذوفة وسجلات النظام.","en":"A logical extraction collects what a backup offers. A full file system extraction reaches app databases, deleted records and system logs."},{"ar":"وتُحفظ معظم المحادثات وسجلات المكالمات والمواقع في قواعد بيانات SQLite وكثيراً ما تُسترجع الصفوف المحذوفة من صفحاتها الحرة.","en":"Most chats, call logs and locations are stored in SQLite databases, and deleted rows can often be recovered from their free pages."},{"ar":"وتحوّل أدوات التحليل مفتوحة المصدر مثل ALEAPP وiLEAPP الاستخراج إلى تقارير مقروءة للمحادثات والمواقع والحسابات واستخدام التطبيقات.","en":"Open source parsers such as ALEAPP and iLEAPP turn an extraction into readable reports of chats, locations, accounts and app usage."}],"n":13,"objectives":[{"ar":"عزل الهاتف دون فقدان بياناته","en":"Isolate a phone without losing data"},{"ar":"الاختيار بين الاستخراج المنطقي والاستخراج الكامل لنظام الملفات","en":"Choose between logical and full file system extraction"},{"ar":"العثور على قواعد بيانات المحادثات والمواقع","en":"Find chat and location databases"}],"pitfalls":[{"ar":"تصفح الهاتف يدوياً للبحث عن الرسائل وهذا يغيّر حالة القراءة والطوابع الزمنية.","en":"Browsing the phone by hand to look for messages, which changes read status and timestamps."},{"ar":"ترك البطارية تنفد وهذا قد يجعل الهاتف المفتوح غير قابل للاسترجاع.","en":"Letting the battery die, which can make an unlocked phone unrecoverable."}],"quiz":[{"answer":2,"options":[{"ar":"لقطة شاشة","en":"A screenshot"},{"ar":"الاستخراج المنطقي","en":"A logical extraction"},{"ar":"الاستخراج الكامل لنظام الملفات","en":"A full file system extraction"},{"ar":"نسخ بطاقة SIM","en":"A SIM card copy"}],"q":{"ar":"أي نوع استخراج يصل إلى سجلات المحادثات المحذوفة","en":"Which extraction reaches deleted chat records"},"why":{"ar":"الاستخراج الكامل وحده يشمل قواعد بيانات التطبيقات التي قد تحفظ صفحاتها الحرة صفوفاً محذوفة.","en":"Only the full file system includes the app databases, whose free pages may still hold deleted rows."}},{"answer":1,"options":[{"ar":"لاستقبال رسائل جديدة","en":"To receive new messages"},{"ar":"لأن إعادة التشغيل قد تقفل البيانات خلف التشفير","en":"A restart can lock data behind encryption"},{"ar":"لأن الهواتف تفقد كل بياناتها عند نفاد البطارية","en":"Phones lose all data at zero battery"},{"ar":"ليس مهماً","en":"It is not important"}],"q":{"ar":"لماذا تُبقي الهاتف المضبوط مشحوناً","en":"Why keep a seized phone charged"},"why":{"ar":"بعد إعادة التشغيل لا تتاح المفاتيح في كثير من الهواتف إلا بعد إدخال رمز المرور مجدداً فقد تصبح البيانات المتاحة غير متاحة.","en":"After a restart many phones hold keys only after the passcode is entered again, so data that was reachable may no longer be."}}],"steps":[{"ar":"اعزل الهاتف وأبقه مشحوناً","en":"Isolate the phone and keep it powered"},{"ar":"سجّل حالة الشاشة وأي قفل","en":"Record the screen state and any lock"},{"ar":"استخرج البيانات بأداة موثقة ومختبرة","en":"Extract with a documented and tested tool"},{"ar":"احسب بصمة الاستخراج ثم حلّله","en":"Hash the extraction and parse it"}],"summary":{"ar":"كيف تُعزل الهواتف وما أنواع الاستخراج وأين توجد المحادثات والمواقع وبيانات التطبيقات في Android وiOS.","en":"How phones are isolated, which kinds of extraction exist, and where chats, locations and app data live on Android and iOS."},"terms":["faraday-bag","mobile-extraction","sqlite"],"title":{"ar":"الأجهزة المحمولة","en":"Mobile devices"},"tools":["aleapp","ileapp","mvt"]},{"commands":["qassas timeline qassas-case-01 --tz kuwait"],"hours":3,"id":"timeline","image":"08-timeline-stakes","kuwait":{"ar":"لا تعمل الكويت بالتوقيت الصيفي فيبقى UTC+03:00 ثابتاً كل أيام السنة بخلاف الخطوط الزمنية التي تعبر تغيير الساعة في أوروبا أو أمريكا.","en":"Kuwait has no daylight saving time, so UTC+03:00 holds every day of the year, unlike timelines that cross a European or American clock change."},"lab":"timeline","law_refs":["kw-cbk-corf-2025","intl-iso-27041-27043-2015"],"lesson":[{"ar":"لكل مصدر ساعته الخاصة ففي الاختصارات FILETIME وفي Chromium وقت WebKit وفي Syslog الوقت المحلي وفي الالتقاطات ثوانٍ منذ بداية Unix وفي EXIF الوقت المحلي.","en":"Each source speaks its own clock: FILETIME in shortcuts, WebKit time in Chromium, local time in syslog, epoch seconds in captures and local time in EXIF."},{"ar":"حوّل كل شيء إلى UTC أولاً ثم رتّبه ثم اعرضه بعد ذلك بتوقيت الكويت UTC+03:00 لأن خلط المناطق الزمنية هو أشهر أخطاء الخط الزمني.","en":"Convert everything to UTC first, sort, and only then display in Kuwait time, UTC+03:00. Mixing zones is the most common timeline mistake."},{"ar":"وكل حدث يشبه وتداً مغروساً في الرمل يعلّم نقطة واحدة فإن قرأت الأوتاد بترتيبها ظهر مسار الحادثة.","en":"Like survey stakes planted across the sand, each event marks one point. Read them in order and the path of the incident appears."},{"ar":"وابحث عن نقطة التحول وهي اللحظة التي تغيّر فيها كل شيء كالنقرة أو التنزيل أو أول دخول من عنوان جديد ثم انطلق منها إلى ما قبلها وما بعدها.","en":"Look for the pivot, the moment everything changes: the click, the download or the first login from a new address, then work outward from it."}],"n":14,"objectives":[{"ar":"توحيد كل صيغ الطوابع الزمنية إلى UTC","en":"Normalise every timestamp format to UTC"},{"ar":"دمج المصادر في خط زمني واحد مرتب","en":"Merge sources into one sorted timeline"},{"ar":"تحديد نقطة التحول في الحادثة","en":"Find the pivot point of an incident"}],"pitfalls":[{"ar":"خلط الأوقات المحلية والعالمية في خط زمني واحد وهذا يعكس ترتيب الأحداث المتقاربة.","en":"Mixing local and UTC times on one timeline, which reverses the order of close events."},{"ar":"تجاهل انحراف الساعة في خادم كانت ساعته خاطئة.","en":"Ignoring clock drift on a server whose clock was wrong."}],"quiz":[{"answer":1,"options":[{"ar":"عرضها بتوقيت الكويت","en":"Show them in Kuwait time"},{"ar":"تحويلها كلها إلى UTC","en":"Convert them all to UTC"},{"ar":"تقريبها إلى أقرب ساعة","en":"Round them to the nearest hour"},{"ar":"حذف ما لا يحمل ثوانيَ","en":"Remove the ones without seconds"}],"q":{"ar":"ما أول ما تفعله عند دمج أوقات من مصادر كثيرة","en":"What should you do first when merging times from many sources"},"why":{"ar":"توحيد المنطقة المرجعية يجعل الترتيب صحيحاً أما العرض فخطوة منفصلة لاحقة.","en":"A single reference zone makes sorting correct. Display is a separate, later step."}},{"answer":0,"options":[{"ar":"06:15","en":"06:15"},{"ar":"05:15","en":"05:15"},{"ar":"12:15","en":"12:15"},{"ar":"09:15","en":"09:15"}],"q":{"ar":"الوقت في الكويت يوم 4 أكتوبر هو 09:15 فكم يكون بالتوقيت العالمي","en":"Kuwait time on 4 October is 09:15. What is it in UTC"},"why":{"ar":"توقيت الكويت هو UTC+03:00 طوال العام لذا اطرح ثلاث ساعات.","en":"Kuwait is UTC+03:00 all year, so subtract three hours."}}],"steps":[{"ar":"حلّل كل مصدر بصيغة وقته الخاصة","en":"Parse each source with its own time format"},{"ar":"حوّل كل حدث إلى UTC","en":"Convert every event to UTC"},{"ar":"رتّب الأحداث وادمجها","en":"Sort and merge"},{"ar":"اعرضها بتوقيت الكويت وعلّم نقطة التحول","en":"Display in Kuwait time and mark the pivot"}],"summary":{"ar":"كيف تدمج كل المصادر في خط زمني واحد بالتوقيت العالمي ثم تقرؤه بتوقيت الكويت لتروي القصة بترتيبها.","en":"How to merge every source onto one timeline in UTC and read it back in Kuwait time to tell the story in order."},"terms":["timestamp","macb","super-timeline","utc"],"title":{"ar":"بناء الخط الزمني","en":"Building the timeline"},"tools":["plaso","timesketch","sleuthkit"]},{"commands":["qassas report qassas-case-01 --lang ar --out report-ar.md","qassas lab check --questions qassas-case-01/questions.json --answers answers.json"],"hours":3,"id":"reporting","image":"poster-07-report","kuwait":{"ar":"تحتفظ محكمة التمييز بالكلمة الأخيرة في نتائج الخبراء لذا فالتقرير الواضح الموثق الصادق هو ما يقنعها.","en":"The Court of Cassation keeps the final word on expert findings, so a clear, sourced and honest report is what persuades it."},"lab":"case","law_refs":["kw-cassation-536-2003","kw-law-17-1960","intl-iso-27041-27043-2015"],"lesson":[{"ar":"يذكر التقرير ما استُلم وكيف تُحقق من سلامته وما الأدوات وإصداراتها المستخدمة وما وُجد وما معناه بهذا الترتيب.","en":"A report states what was received, how its integrity was checked, which tools and versions were used, what was found, and what it means, in that order."},{"ar":"وتشير كل نتيجة إلى ملفها المصدر وموضعها فيه ليستطيع القارئ أن يذهب ويرى بنفسه.","en":"Every finding points to its source file and location, so a reader can go and look for themselves."},{"ar":"وافصل بين الوقائع والآراء فالسجل يُظهر دخولاً من عنوان ما أما أن العنوان يعود إلى المهاجم فهو تفسيرك.","en":"Keep facts and opinions apart. The log shows a login from an address, and it is your interpretation that the address belongs to the attacker."},{"ar":"واذكر ما لم تستطع تحديده وسبب ذلك لأن الإقرار الصادق بالحدود يزيد بقية التقرير مصداقية.","en":"Say what you could not determine and why. Honest limits make the rest of the report more credible."}],"n":15,"objectives":[{"ar":"بناء تقرير الفحص","en":"Structure an examination report"},{"ar":"الفصل بين الوقائع والتفسير","en":"Separate facts from interpretation"},{"ar":"حل القضية التدريبية من أولها إلى آخرها","en":"Solve the practice case end to end"}],"pitfalls":[{"ar":"الكتابة لفاحصين آخرين بمصطلحات لا يتابعها القاضي.","en":"Writing for other examiners in jargon a judge cannot follow."},{"ar":"صياغة الخلاصة بقوة تفوق ما تدعمه الأدلة.","en":"Stating a conclusion more strongly than the evidence supports."}],"quiz":[{"answer":1,"options":[{"ar":"سرق المهاجم المناقصة","en":"The attacker stole the tender"},{"ar":"في الساعة 09:15 أرسل الحاسوب 1487 بايت إلى updates.sanbouk-cdn.example","en":"At 09:15 the laptop posted 1487 bytes to updates.sanbouk-cdn.example"},{"ar":"ساعد فهد المهاجم","en":"Fahad helped the attacker"},{"ar":"كانت الشركة مهملة","en":"The company was careless"}],"q":{"ar":"أي جملة واقعة لا تفسير","en":"Which sentence is a fact rather than an interpretation"},"why":{"ar":"تذكر ما يُظهره الالتقاط بالوقت والحجم والوجهة وتترك المعنى لقسم التحليل.","en":"It states what the capture shows, with time, size and destination, and leaves the meaning to the analysis section."}},{"answer":1,"options":[{"ar":"للإعلان عن الأدوات","en":"To advertise the tools"},{"ar":"ليتمكن فاحص آخر من تكرار العمل","en":"So another examiner can repeat the work"},{"ar":"إجراء شكلي بلا غرض","en":"It is a formality with no purpose"},{"ar":"لإطالة التقرير","en":"To make the report longer"}],"q":{"ar":"لماذا تُذكر إصدارات الأدوات في التقرير","en":"Why list the tool versions in a report"},"why":{"ar":"قد تحلل الإصدارات المختلفة البيانات بطرق مختلفة لذا يحتاج تكرار العمل إلى الأدوات نفسها.","en":"Different versions can parse differently, so repeating the work needs the same tools."}}],"steps":[{"ar":"صِف الأدلة وفحوص سلامتها","en":"Describe the evidence and its integrity checks"},{"ar":"اذكر الأدوات مع إصداراتها","en":"List tools with their versions"},{"ar":"اعرض النتائج بترتيبها الزمني مع مصادرها","en":"Present findings in time order with sources"},{"ar":"اذكر الخلاصات والحدود بوضوح","en":"State conclusions and limits plainly"}],"summary":{"ar":"كيف تكتب نتائج يتابعها القاضي ويكررها فاحص آخر ثم تحل قضية السنبوك التدريبية كاملة.","en":"How to write findings a judge can follow and another examiner can repeat, then solve the full Sanbouk practice case."},"terms":["expert-report","repeatability","anti-forensics"],"title":{"ar":"التقرير والقضية","en":"The report and the case"},"tools":["autopsy","timesketch"]}],"pivotText":{"beacon":{"ar":"أول اتصال دوري","en":"First check in"},"cleared":{"ar":"مسح السجل","en":"Log cleared"},"download":{"ar":"تنزيل خبيث","en":"Malicious download"},"execution":{"ar":"تشغيل البرمجية الخبيثة","en":"Malware runs"},"exfil":{"ar":"إرسال البيانات إلى الخارج","en":"Data sent out"},"guessing":{"ar":"بدء تخمين كلمات المرور","en":"Password guessing begins"},"login":{"ar":"دخول المهاجم","en":"Attacker logs in"},"persistence":{"ar":"تثبيت خدمة","en":"Service installed"},"phish":{"ar":"فُتحت صفحة التصيد","en":"Phishing page opened"}},"signatures":[{"ext":["jpg","jpeg","jfif"],"hex":"ffd8ff","id":"jpeg","name":"JPEG image","offset":0},{"ext":["png"],"hex":"89504e470d0a1a0a","id":"png","name":"PNG image","offset":0},{"ext":["gif"],"hex":"474946383961","id":"gif","name":"GIF image","offset":0},{"ext":["gif"],"hex":"474946383761","id":"gif87","name":"GIF image (87a)","offset":0},{"also":{"hex":"57454250","offset":8},"ext":["webp"],"hex":"52494646","id":"webp","name":"WebP image","offset":0},{"ext":["bmp"],"hex":"424d","id":"bmp","name":"Bitmap image","offset":0},{"ext":["tif","tiff","dng"],"hex":"49492a00","id":"tiff_le","name":"TIFF image (little endian)","offset":0},{"ext":["tif","tiff"],"hex":"4d4d002a","id":"tiff_be","name":"TIFF image (big endian)","offset":0},{"ext":["heic","heif"],"hex":"6674797068656963","id":"heic","name":"HEIC image","offset":4},{"ext":["pdf"],"hex":"255044462d","id":"pdf","name":"PDF document","offset":0},{"ext":["docx","xlsx","pptx"],"hex":"504b0304","id":"ooxml","name":"Office Open XML document (ZIP container)","offset":0,"zip_member":"[Content_Types].xml"},{"ext":["apk"],"hex":"504b0304","id":"apk","name":"Android package (ZIP container)","offset":0,"zip_member":"AndroidManifest.xml"},{"ext":["zip","jar","kmz"],"hex":"504b0304","id":"zip","name":"ZIP archive","offset":0},{"ext":["zip"],"hex":"504b0506","id":"zip_empty","name":"ZIP archive (empty)","offset":0},{"ext":["rar"],"hex":"526172211a070100","id":"rar5","name":"RAR archive (v5)","offset":0},{"ext":["rar"],"hex":"526172211a0700","id":"rar4","name":"RAR archive (v4)","offset":0},{"ext":["7z"],"hex":"377abcaf271c","id":"7z","name":"7-Zip archive","offset":0},{"ext":["gz","tgz"],"hex":"1f8b08","id":"gzip","name":"GZIP archive","offset":0},{"ext":["bz2"],"hex":"425a68","id":"bzip2","name":"BZIP2 archive","offset":0},{"ext":["xz"],"hex":"fd377a585a00","id":"xz","name":"XZ archive","offset":0},{"ext":["doc","xls","ppt","msi","msg","db"],"hex":"d0cf11e0a1b11ae1","id":"ole","name":"OLE compound file (legacy Office, MSI, thumbs.db)","offset":0},{"ext":["exe","dll","sys","scr","cpl","ocx"],"hex":"4d5a","id":"pe","name":"Windows executable (PE)","offset":0},{"ext":["","so","elf","bin","o"],"hex":"7f454c46","id":"elf","name":"Linux executable (ELF)","offset":0},{"ext":["","dylib"],"hex":"cffaedfe","id":"macho64","name":"macOS executable (Mach-O 64 bit)","offset":0},{"ext":["sqlite","sqlite3","db",""],"hex":"53514c69746520666f726d6174203300","id":"sqlite","name":"SQLite database","offset":0},{"ext":["evtx"],"hex":"456c6646696c6500","id":"evtx","name":"Windows event log (EVTX)","offset":0},{"ext":["","dat","hve"],"hex":"72656766","id":"regf","name":"Windows registry hive","offset":0},{"ext":["lnk"],"hex":"4c0000000114020000000000c000000000000046","id":"lnk","name":"Windows shortcut (LNK)","offset":0},{"ext":["pf"],"hex":"53434341","id":"prefetch","name":"Windows prefetch (uncompressed)","offset":4},{"ext":["pf"],"hex":"4d414d04","id":"prefetch_mam","name":"Windows prefetch (compressed)","offset":0},{"ext":["pcap","cap","dmp"],"hex":"d4c3b2a1","id":"pcap_le","name":"Packet capture (pcap)","offset":0},{"ext":["pcap","cap"],"hex":"a1b2c3d4","id":"pcap_be","name":"Packet capture (pcap, big endian)","offset":0},{"ext":["pcap"],"hex":"4d3cb2a1","id":"pcap_ns","name":"Packet capture (pcap, nanosecond)","offset":0},{"ext":["pcapng"],"hex":"0a0d0d0a","id":"pcapng","name":"Packet capture (pcapng)","offset":0},{"ext":["plist"],"hex":"62706c6973743030","id":"bplist","name":"Apple binary property list","offset":0},{"ext":["mp4","m4v","mov","m4a","3gp"],"hex":"66747970","id":"mp4","name":"MP4 or MOV video","offset":4},{"also":{"hex":"57415645","offset":8},"ext":["wav"],"hex":"52494646","id":"riff_wav","name":"WAV audio","offset":0},{"also":{"hex":"41564920","offset":8},"ext":["avi"],"hex":"52494646","id":"riff_avi","name":"AVI video","offset":0},{"ext":["mp3"],"hex":"494433","id":"mp3_id3","name":"MP3 audio (ID3 tag)","offset":0},{"ext":["ogg","oga","opus"],"hex":"4f676753","id":"ogg","name":"Ogg media","offset":0},{"ext":["e01","ex01"],"hex":"455646090d0aff00","id":"e01","name":"EnCase evidence file (E01)","offset":0},{"ext":["vmdk"],"hex":"4b444d56","id":"vmdk","name":"VMware disk (VMDK)","offset":0},{"ext":["vhdx"],"hex":"7668647866696c65","id":"vhdx","name":"Hyper-V disk (VHDX)","offset":0},{"ext":["iso"],"hex":"4344303031","id":"iso","name":"ISO 9660 disc image","offset":32769},{"ext":["rtf"],"hex":"7b5c72746631","id":"rtf","name":"Rich Text document","offset":0},{"ext":["html","htm"],"hex":"3c21646f6374797065","id":"html","name":"HTML document","offset":0},{"ext":["xml","svg","plist"],"hex":"3c3f786d6c","id":"xml","name":"XML document","offset":0},{"ext":["txt","csv","log","xml","json"],"hex":"efbbbf","id":"utf8bom","name":"Text with UTF-8 byte order mark","offset":0},{"ext":["txt","csv","log","reg"],"hex":"fffe","id":"utf16le","name":"Text in UTF-16 little endian","offset":0}],"timeline":[{"artifact":"Pictures/IMG_2038.jpg","description":"Photo taken with QassasLab QL-1 Phone","source":"exif","time_utc":"2026-09-28T14:40:05+00:00","type":"photo_taken"},{"artifact":"laptop.img @ 700001","description":"Photo taken with QassasLab QL-1 Phone","source":"exif","time_utc":"2026-09-28T14:40:05+00:00","type":"photo_taken"},{"artifact":"Documents/Tender_2026_Final.pdf","description":"document created by Fahad","source":"document","time_utc":"2026-10-02T07:15:00+00:00","type":"document_created"},{"artifact":"laptop.img @ 1049353","description":"document created by Fahad","source":"document","time_utc":"2026-10-02T07:15:00+00:00","type":"document_created"},{"artifact":"laptop.img @ 131072","description":"Photo taken with QassasLab QL-1 Phone at 29.3346, 48.0715","source":"exif","time_utc":"2026-10-03T16:12:40+00:00","type":"photo_taken"},{"artifact":"Logs/LAPTOP-FHD01_security.jsonl","description":"An account logged on: fahad","source":"windows","time_utc":"2026-10-04T04:41:03+00:00","type":"logon_success"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for portal.dar-alsanbouk.example","source":"network","time_utc":"2026-10-04T04:55:10+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to portal.dar-alsanbouk.example (192.0.2.10)","source":"network","time_utc":"2026-10-04T04:55:10+00:00","type":"tls"},{"artifact":"Browser/History","description":"https://portal.dar-alsanbouk.example/ (typed)","source":"browser","time_utc":"2026-10-04T04:55:12+00:00","type":"visit"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login accepted for fahad from 10.10.20.15","source":"auth_log","time_utc":"2026-10-04T04:58:21+00:00","type":"ssh_accepted"},{"artifact":"Logs/srv-files_auth.log","description":"session_opened fahad(uid=1001)","source":"auth_log","time_utc":"2026-10-04T04:58:21+00:00","type":"session_opened"},{"artifact":"Browser/History","description":"https://www.google.example/search?q=%D9%85%D9%86%D8%A7%D9%82%D8%B5%D8%A9 (typed)","source":"browser","time_utc":"2026-10-04T05:02:40+00:00","type":"visit"},{"artifact":"Browser/History","description":"Searched for: مناقصة","source":"browser","time_utc":"2026-10-04T05:02:40+00:00","type":"search"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for portal.dar-alsanbouk.example","source":"network","time_utc":"2026-10-04T05:09:31+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to portal.dar-alsanbouk.example (192.0.2.10)","source":"network","time_utc":"2026-10-04T05:09:31+00:00","type":"tls"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login accepted for itadmin from 10.10.20.30","source":"auth_log","time_utc":"2026-10-04T05:15:02+00:00","type":"ssh_accepted"},{"artifact":"Logs/srv-files_auth.log","description":"sudo /usr/bin/systemctl restart smbd","source":"auth_log","time_utc":"2026-10-04T05:15:40+00:00","type":"sudo"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for portal.dar-alsanbouk.example","source":"network","time_utc":"2026-10-04T05:31:02+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to portal.dar-alsanbouk.example (192.0.2.10)","source":"network","time_utc":"2026-10-04T05:31:02+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for dar-alsanbouk-login.example","source":"network","time_utc":"2026-10-04T05:42:08+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to dar-alsanbouk-login.example (198.51.100.77)","source":"network","time_utc":"2026-10-04T05:42:08+00:00","type":"tls"},{"artifact":"Browser/History","description":"https://dar-alsanbouk-login.example/sso/reset (link)","pivot":"phish","source":"browser","time_utc":"2026-10-04T05:42:09+00:00","type":"visit"},{"artifact":"Browser/History","description":"https://dar-alsanbouk-login.example/sso/done (form_submit)","source":"browser","time_utc":"2026-10-04T05:43:30+00:00","type":"visit"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for files.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:44:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to files.sanbouk-cdn.example (198.51.100.77)","source":"network","time_utc":"2026-10-04T05:44:01+00:00","type":"tls"},{"artifact":"Browser/History","description":"https://files.sanbouk-cdn.example/Tender_Update.zip (link)","source":"browser","time_utc":"2026-10-04T05:44:02+00:00","type":"visit"},{"artifact":"Browser/History","description":"Downloaded C:\\Users\\fahad\\Downloads\\Tender_Update.zip from https://files.sanbouk-cdn.example/Tender_Update.zip","pivot":"download","source":"browser","time_utc":"2026-10-04T05:44:03+00:00","type":"download"},{"artifact":"Recent/Tender_Update.lnk","description":"Shortcut records created of C:\\Users\\fahad\\Downloads\\Tender_Update\\update.exe","source":"lnk","time_utc":"2026-10-04T05:44:07+00:00","type":"target_created"},{"artifact":"Recent/Tender_Update.lnk","description":"Shortcut records modified of C:\\Users\\fahad\\Downloads\\Tender_Update\\update.exe","source":"lnk","time_utc":"2026-10-04T05:44:07+00:00","type":"target_modified"},{"artifact":"Recent/Tender_Update.lnk","description":"Shortcut records accessed of C:\\Users\\fahad\\Downloads\\Tender_Update\\update.exe","source":"lnk","time_utc":"2026-10-04T05:46:09+00:00","type":"target_accessed"},{"artifact":"Logs/LAPTOP-FHD01_security.jsonl","description":"A new process was created: C:\\Users\\fahad\\Downloads\\Tender_Update\\update.exe","pivot":"execution","source":"windows","time_utc":"2026-10-04T05:46:10+00:00","type":"process_created"},{"artifact":"Logs/LAPTOP-FHD01_security.jsonl","description":"A new process was created: C:\\Windows\\System32\\sc.exe","source":"windows","time_utc":"2026-10-04T05:46:31+00:00","type":"process_created"},{"artifact":"Logs/LAPTOP-FHD01_security.jsonl","description":"A service was installed in the system: SanboukUpdater","pivot":"persistence","source":"windows","time_utc":"2026-10-04T05:46:32+00:00","type":"service_installed"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","pivot":"beacon","source":"network","time_utc":"2026-10-04T05:47:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:47:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:48:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:48:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:49:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:49:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:50:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:50:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:51:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:51:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:52:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:52:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:53:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:53:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:54:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:54:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:55:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:55:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:56:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:56:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:57:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:57:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:58:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:58:05+00:00","type":"tls"},{"artifact":"Documents/Tender_2026_Final.pdf","description":"document modified by Fahad","source":"document","time_utc":"2026-10-04T05:59:00+00:00","type":"document_modified"},{"artifact":"laptop.img @ 1049353","description":"document modified by Fahad","source":"document","time_utc":"2026-10-04T05:59:00+00:00","type":"document_modified"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T05:59:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T05:59:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:00:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:00:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:01:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:01:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:02:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:02:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:03:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:03:05+00:00","type":"tls"},{"artifact":"Logs/LAPTOP-FHD01_security.jsonl","description":"An account failed to log on: Administrator","source":"windows","time_utc":"2026-10-04T06:03:15+00:00","type":"logon_failed"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:04:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:04:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:05:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:05:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for portal.dar-alsanbouk.example","source":"network","time_utc":"2026-10-04T06:05:53+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to portal.dar-alsanbouk.example (192.0.2.10)","source":"network","time_utc":"2026-10-04T06:05:53+00:00","type":"tls"},{"artifact":"Browser/History","description":"https://portal.dar-alsanbouk.example/tenders/2026 (typed)","source":"browser","time_utc":"2026-10-04T06:05:55+00:00","type":"visit"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:06:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:06:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:07:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:07:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:08:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:08:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:09:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:09:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:10:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:10:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:11:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:11:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:12:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:12:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:13:05+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:13:05+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:14:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:14:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:15:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:15:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 POST updates.sanbouk-cdn.example/upload?id=FHD01 (1487 bytes)","pivot":"exfil","source":"network","time_utc":"2026-10-04T06:15:10+00:00","type":"http"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:16:04+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:16:04+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:17:03+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:17:03+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:18:03+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:18:03+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:19:02+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:19:02+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:20:02+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:20:02+00:00","type":"tls"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for admin from 203.0.113.45","pivot":"guessing","source":"auth_log","time_utc":"2026-10-04T06:20:11+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for admin from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:20:33+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for root from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:20:54+00:00","type":"ssh_failed"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:21:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:21:01+00:00","type":"tls"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for admin from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:21:15+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH attempt for unknown user administrator from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:21:34+00:00","type":"ssh_invalid_user"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for administrator from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:21:35+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for root from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:21:57+00:00","type":"ssh_failed"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:22:02+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:22:02+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for portal.dar-alsanbouk.example","source":"network","time_utc":"2026-10-04T06:22:18+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to portal.dar-alsanbouk.example (192.0.2.10)","source":"network","time_utc":"2026-10-04T06:22:18+00:00","type":"tls"},{"artifact":"Logs/srv-files_auth.log","description":"SSH attempt for unknown user backup from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:22:19+00:00","type":"ssh_invalid_user"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for backup from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:22:20+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for admin from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:22:40+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for fahad from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:22:59+00:00","type":"ssh_failed"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:23:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:23:01+00:00","type":"tls"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for fahad from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:23:17+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for root from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:23:37+00:00","type":"ssh_failed"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login failed for admin from 203.0.113.45","source":"auth_log","time_utc":"2026-10-04T06:23:54+00:00","type":"ssh_failed"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:24:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:24:01+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:25:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:25:01+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:26:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:26:01+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:27:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:27:01+00:00","type":"tls"},{"artifact":"Logs/srv-files_auth.log","description":"SSH login accepted for fahad from 203.0.113.45","pivot":"login","source":"auth_log","time_utc":"2026-10-04T06:27:03+00:00","type":"ssh_accepted"},{"artifact":"Logs/srv-files_auth.log","description":"session_opened fahad(uid=1001)","source":"auth_log","time_utc":"2026-10-04T06:27:03+00:00","type":"session_opened"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:28:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:28:01+00:00","type":"tls"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 asked for updates.sanbouk-cdn.example","source":"network","time_utc":"2026-10-04T06:29:01+00:00","type":"dns_query"},{"artifact":"Network/capture.pcap","description":"10.10.20.15 opened TLS to updates.sanbouk-cdn.example (198.51.100.23)","source":"network","time_utc":"2026-10-04T06:29:01+00:00","type":"tls"},{"artifact":"Logs/LAPTOP-FHD01_security.jsonl","description":"The audit log was cleared: fahad","pivot":"cleared","source":"windows","time_utc":"2026-10-04T06:41:02+00:00","type":"log_cleared"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 seized by Noura, incident responder","source":"custody","time_utc":"2026-10-04T07:05:00+00:00","type":"seized"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 sealed by Noura, incident responder","source":"custody","time_utc":"2026-10-04T07:12:00+00:00","type":"sealed"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 transferred by Noura, incident responder to Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T08:40:00+00:00","type":"transferred"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 received by Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T08:41:00+00:00","type":"received"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 opened by Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T10:00:00+00:00","type":"opened"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 imaged by Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T11:25:00+00:00","type":"imaged"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 verified by Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T11:31:00+00:00","type":"verified"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 resealed by Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T11:50:00+00:00","type":"resealed"},{"artifact":"custody/custody.jsonl","description":"ITEM-01 laptop LAPTOP-FHD01 stored by Yousef, forensic examiner","source":"custody","time_utc":"2026-10-04T12:05:00+00:00","type":"stored"}],"tools":{"categories":[{"id":"acquisition","name":{"ar":"الحصول على الأدلة","en":"Acquisition"}},{"id":"memory","name":{"ar":"الذاكرة","en":"Memory"}},{"id":"disk","name":{"ar":"الأقراص وأنظمة الملفات","en":"Disk and file systems"}},{"id":"timeline","name":{"ar":"الخطوط الزمنية","en":"Timelines"}},{"id":"windows","name":{"ar":"آثار Windows وسجلاتها","en":"Windows artifacts and logs"}},{"id":"network","name":{"ar":"الشبكات","en":"Network"}},{"id":"browser","name":{"ar":"المتصفحات والروابط","en":"Browsers and URLs"}},{"id":"mobile","name":{"ar":"الأجهزة المحمولة","en":"Mobile"}},{"id":"triage","name":{"ar":"الاستجابة الحية والفرز","en":"Live response and triage"}},{"id":"malware","name":{"ar":"فرز البرمجيات الخبيثة","en":"Malware triage"}},{"id":"utility","name":{"ar":"أدوات مساعدة","en":"Utilities"}}],"checked":"2026-10-11","method":{"ar":"استُنسخ كل مستودع وقُرئ ملف ترخيصه في التاريخ أعلاه وذُكرت التراخيص المختلطة على أنها مختلطة.","en":"Each repository was cloned and its license file read on the date above. Mixed licenses are named as mixed."},"tools":[{"category":"acquisition","desc":{"ar":"أداة تصوير رسومية سريعة تنتج صوراً خاماً وصوراً بصيغة E01 مع حساب البصمات تلقائياً.","en":"Fast graphical imager for raw and E01 images with built in hashing."},"id":"guymager","license":"GPL-2.0","name":"Guymager","platform":"Linux","url":"https://guymager.sourceforge.io/"},{"category":"acquisition","desc":{"ar":"مكتبة وأدوات سطر أوامر لإنشاء ملفات الأدلة E01 وقراءتها والتحقق منها.","en":"Library and command line tools to create, read and verify E01 evidence files."},"id":"libewf","license":"GPL-3.0","name":"libewf (ewfacquire, ewfverify)","platform":"Linux, macOS, Windows","url":"https://github.com/libyal/libewf"},{"category":"memory","desc":{"ar":"تلتقط ذاكرة Linux من مساحة المستخدم بملف تنفيذي واحد مستقل.","en":"Captures Linux memory from user space with a single static binary."},"id":"avml","license":"MIT","name":"AVML","platform":"Linux","url":"https://github.com/microsoft/avml"},{"category":"memory","desc":{"ar":"تلتقط ذاكرة Windows في صورة خام أو بصيغة AFF4.","en":"Captures Windows memory to a raw or AFF4 image."},"id":"winpmem","license":"Apache-2.0","name":"WinPmem","platform":"Windows","url":"https://github.com/Velocidex/WinPmem"},{"category":"memory","desc":{"ar":"وحدة نواة تلتقط الذاكرة من أجهزة Linux وAndroid.","en":"Kernel module that captures memory from Linux and Android devices."},"id":"lime","license":"GPL-2.0","name":"LiME","platform":"Linux, Android","url":"https://github.com/504ensicsLabs/LiME"},{"category":"memory","desc":{"ar":"الإطار المعتمد لتحليل التقاطات الذاكرة من Windows وLinux وmacOS.","en":"The standard framework for analysing memory captures from Windows, Linux and macOS."},"id":"volatility3","license":"Volatility Software License 1.0","name":"Volatility 3","platform":"Python","url":"https://github.com/volatilityfoundation/volatility3"},{"category":"disk","desc":{"ar":"أدوات سطر أوامر لأنظمة الملفات والملفات المحذوفة وخطوط MACB الزمنية.","en":"Command line tools for file systems, deleted files and MACB timelines."},"id":"sleuthkit","license":"Mixed (Apache-2.0, GPL-2.0, others)","name":"The Sleuth Kit","platform":"Linux, macOS, Windows","url":"https://github.com/sleuthkit/sleuthkit"},{"category":"disk","desc":{"ar":"منصة قضايا رسومية مبنية على The Sleuth Kit وتصلح للتعليم وللفحوص الكاملة.","en":"Graphical case platform on top of The Sleuth Kit, good for teaching and full examinations."},"id":"autopsy","license":"Apache-2.0","name":"Autopsy","platform":"Windows, Linux, macOS","url":"https://github.com/sleuthkit/autopsy"},{"category":"disk","desc":{"ar":"تسترجع الأقسام المفقودة وتنحت مئات أنواع الملفات.","en":"Recovers lost partitions and carves hundreds of file types."},"id":"photorec","license":"GPL-2.0","name":"TestDisk and PhotoRec","platform":"Linux, macOS, Windows","url":"https://github.com/cgsecurity/testdisk"},{"category":"disk","desc":{"ar":"أداة نحت تعتمد على بدايات الملفات ونهاياتها وفق ملف إعدادات.","en":"Header and footer file carver driven by a configuration file."},"id":"scalpel","license":"Apache-2.0","name":"Scalpel","platform":"Linux, Windows","url":"https://github.com/sleuthkit/scalpel"},{"category":"disk","desc":{"ar":"تمسح البيانات الخام بحثاً عن عناوين البريد والروابط وأرقام البطاقات وغيرها دون تحليل نظام الملفات.","en":"Scans raw data for emails, URLs, card numbers and other features without parsing the file system."},"id":"bulk-extractor","license":"Mixed (see COPYING)","name":"bulk_extractor","platform":"Linux, macOS, Windows","url":"https://github.com/simsong/bulk_extractor"},{"category":"timeline","desc":{"ar":"تبني خطاً زمنياً شاملاً من مئات أنواع الآثار.","en":"Builds a super timeline from hundreds of artifact types."},"id":"plaso","license":"Apache-2.0","name":"Plaso (log2timeline)","platform":"Python","url":"https://github.com/log2timeline/plaso"},{"category":"timeline","desc":{"ar":"منصة ويب تعاونية للبحث في الخطوط الزمنية ووسمها والتعليق عليها ضمن فريق.","en":"Collaborative web platform to search, tag and annotate timelines as a team."},"id":"timesketch","license":"Apache-2.0","name":"Timesketch","platform":"Server","url":"https://github.com/google/timesketch"},{"category":"windows","desc":{"ar":"أدوات تحليل للسجل وجدول الملفات الرئيسي في NTFS والاختصارات وملفات Prefetch وغيرها.","en":"Parsers for the registry, the NTFS master file table, shortcuts, prefetch and more."},"id":"eztools","license":"MIT","name":"Eric Zimmerman's tools (RECmd, MFTECmd and others)","platform":"Windows","url":"https://github.com/EricZimmerman"},{"category":"windows","desc":{"ar":"إضافات تستخرج القيم الجنائية من ملفات السجل.","en":"Plugins that pull forensic values out of registry hives."},"id":"regripper","license":"MIT","name":"RegRipper 3.0","platform":"Windows, Perl","url":"https://github.com/keydet89/RegRipper3.0"},{"category":"windows","desc":{"ar":"تبحث بسرعة في سجلات أحداث Windows باستخدام قواعد Sigma.","en":"Hunts through Windows event logs fast with Sigma rules."},"id":"chainsaw","license":"GPL-3.0","name":"Chainsaw","platform":"Windows, Linux, macOS","url":"https://github.com/WithSecureLabs/chainsaw"},{"category":"windows","desc":{"ar":"تبني خطاً زمنياً لصيد التهديدات من سجلات أحداث Windows.","en":"Builds a threat hunting timeline from Windows event logs."},"id":"hayabusa","license":"AGPL-3.0","name":"Hayabusa","platform":"Windows, Linux, macOS","url":"https://github.com/Yamato-Security/hayabusa"},{"category":"windows","desc":{"ar":"صيغة مشتركة ومكتبة لقواعد الكشف في السجلات.","en":"A shared format and library of detection rules for logs."},"id":"sigma","license":"Mixed (Detection Rule License for rules)","name":"Sigma rules","platform":"Any","url":"https://github.com/SigmaHQ/sigma"},{"category":"network","desc":{"ar":"محلل الحزم المعتمد مع محللات لآلاف البروتوكولات.","en":"The standard packet analyser, with dissectors for thousands of protocols."},"id":"wireshark","license":"GPL-2.0","name":"Wireshark","platform":"Windows, Linux, macOS","url":"https://github.com/wireshark/wireshark"},{"category":"network","desc":{"ar":"تحوّل حركة الشبكة إلى سجلات غنية للاتصالات وDNS وHTTP وTLS والملفات.","en":"Turns traffic into rich logs of connections, DNS, HTTP, TLS and files."},"id":"zeek","license":"BSD-3-Clause","name":"Zeek","platform":"Linux, macOS","url":"https://github.com/zeek/zeek"},{"category":"network","desc":{"ar":"محرك لكشف التسلل يستطيع أيضاً فحص الالتقاطات المسجلة وفق القواعد.","en":"Intrusion detection engine that can also replay captures against rules."},"id":"suricata","license":"GPL-2.0","name":"Suricata","platform":"Linux, Windows, macOS","url":"https://github.com/OISF/suricata"},{"category":"browser","desc":{"ar":"تحلل سجل متصفحات Chromium وتنزيلاتها وذاكرتها المؤقتة وتفضيلاتها.","en":"Parses Chromium browser history, downloads, cache and preferences."},"id":"hindsight","license":"Apache-2.0","name":"Hindsight","platform":"Python","url":"https://github.com/obsidianforensics/hindsight"},{"category":"browser","desc":{"ar":"تفكك الرابط إلى أجزائه وتفك الطوابع الزمنية والمعرفات المخفية فيه.","en":"Breaks a URL into its parts and decodes timestamps and IDs hidden inside it."},"id":"unfurl","license":"Apache-2.0","name":"Unfurl","platform":"Python","url":"https://github.com/obsidianforensics/unfurl"},{"category":"mobile","desc":{"ar":"تحلل استخراجات Android إلى تقارير للمحادثات والمواقع واستخدام التطبيقات.","en":"Parses Android extractions into reports of chats, locations and app usage."},"id":"aleapp","license":"MIT","name":"ALEAPP","platform":"Python","url":"https://github.com/abrignoni/ALEAPP"},{"category":"mobile","desc":{"ar":"تحلل استخراجات iOS إلى تقارير للمحادثات والمواقع واستخدام التطبيقات.","en":"Parses iOS extractions into reports of chats, locations and app usage."},"id":"ileapp","license":"MIT","name":"iLEAPP","platform":"Python","url":"https://github.com/abrignoni/iLEAPP"},{"category":"mobile","desc":{"ar":"تفحص النسخ الاحتياطية في iOS وAndroid بحثاً عن آثار برمجيات تجسس معروفة.","en":"Checks iOS and Android backups for traces of known spyware."},"id":"mvt","license":"MVT License 1.1","name":"Mobile Verification Toolkit","platform":"Python","url":"https://github.com/mvt-project/mvt"},{"category":"triage","desc":{"ar":"تجمع الأدلة من أجهزة كثيرة في وقت واحد أثناء الحادثة وتستعلم فيها.","en":"Collects and queries evidence from many endpoints at once during an incident."},"id":"velociraptor","license":"AGPL-3.0","name":"Velociraptor","platform":"Windows, Linux, macOS","url":"https://github.com/Velocidex/velociraptor"},{"category":"triage","desc":{"ar":"أداة قابلة للتهيئة لجمع آثار Windows مصممة للفرز على نطاق واسع.","en":"Configurable Windows artifact collector built for large scale triage."},"id":"dfir-orc","license":"LGPL-2.1","name":"DFIR ORC","platform":"Windows","url":"https://github.com/DFIR-ORC/dfir-orc"},{"category":"triage","desc":{"ar":"إطار للتحليل الجنائي الحي عن بُعد لأساطيل الأجهزة.","en":"Remote live forensics framework for fleets of machines."},"id":"grr","license":"Apache-2.0","name":"GRR Rapid Response","platform":"Server","url":"https://github.com/google/grr"},{"category":"triage","desc":{"ar":"تتيح الاستعلام عن نظام يعمل كأنه قاعدة بيانات من العمليات والمستخدمين والمنافذ وغيرها.","en":"Lets you query a running system like a database: processes, users, ports and more."},"id":"osquery","license":"Apache-2.0 or GPL-2.0","name":"osquery","platform":"Windows, Linux, macOS","url":"https://github.com/osquery/osquery"},{"category":"malware","desc":{"ar":"قواعد أنماط لتحديد عينات البرمجيات الخبيثة وتصنيفها.","en":"Pattern rules to identify and classify malware samples."},"id":"yara","license":"BSD-3-Clause","name":"YARA","platform":"Windows, Linux, macOS","url":"https://github.com/VirusTotal/yara"},{"category":"malware","desc":{"ar":"تقرأ الملف التنفيذي وتبين بعبارات واضحة ما يستطيع فعله.","en":"Reads an executable and says in plain terms what it can do."},"id":"capa","license":"Apache-2.0","name":"capa","platform":"Windows, Linux, macOS","url":"https://github.com/mandiant/capa"},{"category":"utility","desc":{"ar":"تقرأ البيانات الوصفية وتكتبها في كل صيغ الملفات تقريباً.","en":"Reads and writes metadata in almost every file format."},"id":"exiftool","license":"GPL-3.0 (repository)","name":"ExifTool","platform":"Perl, Windows, macOS, Linux","url":"https://github.com/exiftool/exiftool"},{"category":"utility","desc":{"ar":"منصة في المتصفح لفك الترميز وحساب البصمات وتحويل البيانات وتحليلها.","en":"Browser workbench for decoding, hashing, converting and parsing data."},"id":"cyberchef","license":"Apache-2.0","name":"CyberChef","platform":"Browser","url":"https://github.com/gchq/CyberChef"}]},"ui":{"about.author":{"ar":"المؤلف","en":"Author"},"about.contribute":{"ar":"ساهم","en":"Contribute"},"about.contribute.p":{"ar":"نرحب على GitHub بتصحيحات سجل القوانين وبالدروس والقضايا الجديدة وتمر كل مساهمة باختبارات اللغة والسلامة نفسها التي يمر بها المشروع كله.","en":"Corrections to the law register, new lessons and new cases are welcome on GitHub. Every change runs the same language and integrity tests as the rest of the project."},"about.license":{"ar":"الترخيص","en":"License"},"about.license.p":{"ar":"تُنشر الشيفرة بترخيص MIT وتُنشر الدروس والصور والتعليق الصوتي بترخيص CC BY 4.0 فيمكنك استخدامها في صفوفك مع ذكر المصدر.","en":"The code is released under the MIT license and the lessons, images and narration under CC BY 4.0, so you may use them in your own classes with credit."},"about.media":{"ar":"الصور والتعليق الصوتي","en":"Images and narration"},"about.media.p":{"ar":"وُلّدت المشاهد الفوتوغرافية والشرح بأسلوب الملصقات باستخدام Higgsfield وسُجّل التعليق الصوتي باستخدام ElevenLabs ويعيد البرنامج الموجود في tools/explainer بناء الفيديو وترجمته النصية من هذه المصادر.","en":"Photographic scenes and the poster style explainer were generated with Higgsfield, and the narration was voiced with ElevenLabs. The builder in tools/explainer remakes the video and its captions from these sources."},"about.p1":{"ar":"سُمّي قصّاص على اسم قصّاصي الأثر في الكويت والجزيرة العربية الذين كانوا يقرؤون آثار الأقدام في الرمل وهو يعلّم الصبر نفسه في تتبع الأثر الرقمي.","en":"Qassas is named after the qassas al-athar, the trackers of Kuwait and Arabia who read footprints in the sand. It teaches the same patience for the digital trail."},"about.p2":{"ar":"وهو مكتوب للطلاب والمحللين الجدد وفرق تقنية المعلومات في الكويت والخليج بالعربية أولاً ثم بالإنجليزية مع القانون المحلي والأمثلة المحلية في كل أجزائه.","en":"It is written for students, new analysts and IT teams in Kuwait and the Gulf, in Arabic first and in English, with local law and local examples throughout."},"about.p3":{"ar":"وكل الأدلة في المختبرات مصطنعة فالأشخاص والشركات والنطاقات مختلقة وتنتهي النطاقات بـ .example وتأتي العناوين من النطاقات المخصصة للتوثيق.","en":"Every piece of evidence in the labs is synthetic. People, companies and domains are invented, domains end in .example and addresses come from documentation ranges."},"about.title":{"ar":"عن قصّاص","en":"About Qassas"},"act.analysed":{"ar":"حُلِّل","en":"Analysed"},"act.imaged":{"ar":"صُوّر جنائياً","en":"Imaged"},"act.opened":{"ar":"فُتح","en":"Opened"},"act.received":{"ar":"استُلم","en":"Received"},"act.resealed":{"ar":"أُعيد ختمه","en":"Resealed"},"act.returned":{"ar":"أُعيد","en":"Returned"},"act.sealed":{"ar":"خُتم","en":"Sealed"},"act.seized":{"ar":"ضُبط","en":"Seized"},"act.stored":{"ar":"حُفظ","en":"Stored"},"act.transferred":{"ar":"سُلِّم","en":"Transferred"},"act.verified":{"ar":"تُحقّق منه","en":"Verified"},"case.alt":{"ar":"حقيبة أدلة مختومة فيها هاتف","en":"A sealed evidence bag holding a phone"},"case.check":{"ar":"تحقق من إجاباتي","en":"Check my answers"},"case.download":{"ar":"نزّل القضية بصيغة ZIP وحجمها {mb} MB","en":"Download the case (ZIP, {mb} MB)"},"case.evidence":{"ar":"الأدلة","en":"Evidence"},"case.hint":{"ar":"تلميح","en":"Hint"},"case.open":{"ar":"افتح القضية","en":"Open the case"},"case.questions":{"ar":"الأسئلة","en":"Questions"},"case.score":{"ar":"النتيجة {n} من {of}","en":"Score {n} of {of}"},"country.AE":{"ar":"الإمارات","en":"UAE"},"country.BH":{"ar":"البحرين","en":"Bahrain"},"country.INTL":{"ar":"دولية","en":"International"},"country.KW":{"ar":"الكويت","en":"Kuwait"},"country.OM":{"ar":"عُمان","en":"Oman"},"country.QA":{"ar":"قطر","en":"Qatar"},"country.SA":{"ar":"السعودية","en":"Saudi Arabia"},"cus.archive":{"ar":"حمّل النسخة المؤرشفة","en":"Load the archived copy"},"cus.broken":{"ar":"السلسلة مكسورة وعدد القيود المتأثرة {n}.","en":"The chain is broken. Entries affected: {n}."},"cus.by":{"ar":"بواسطة","en":"by"},"cus.howto":{"ar":"غيّر أي وقت أو اسم أو ملاحظة ثم تحقق مرة أخرى وراقب موضع انكسار السلسلة.","en":"Change any time, name or note, then verify again and watch where the chain breaks."},"cus.intact":{"ar":"السلسلة سليمة وعدد قيودها {n}.","en":"The chain is intact across {n} entries."},"cus.note":{"ar":"ملاحظة","en":"note"},"cus.reset":{"ar":"إعادة الضبط","en":"Reset"},"cus.time":{"ar":"الوقت","en":"time"},"cus.verify":{"ar":"تحقق من السلسلة","en":"Verify the chain"},"exif.approx":{"ar":"مراكز المناطق تقريبية لذا أكد الموقع على خريطة دقيقة قبل ذكره في التقرير.","en":"Area centres are approximate. Confirm a location on a proper map before you report it."},"exif.device":{"ar":"الجهاز","en":"Device"},"exif.near":{"ar":"أقرب مناطق الكويت","en":"Nearest areas of Kuwait"},"exif.nogps":{"ar":"لا تحمل هذه الصورة موقع GPS.","en":"This photo carries no GPS position."},"exif.none":{"ar":"لم توجد بيانات EXIF في صورة JPEG هذه.","en":"No EXIF block found in this JPEG."},"exif.nooffset":{"ar":"(لم تُسجَّل المنطقة الزمنية فافتُرض UTC)","en":"(no zone recorded, UTC assumed)"},"exif.notjpeg":{"ar":"هذا الملف ليس صورة JPEG.","en":"This is not a JPEG file."},"exif.taken":{"ar":"وقت الالتقاط كما كُتب","en":"Taken (as written)"},"foot.author":{"ar":"علي العنزي","en":"Ali AlEnezi"},"foot.license":{"ar":"الشيفرة بترخيص MIT والمحتوى بترخيص CC BY 4.0","en":"Code MIT, content CC BY 4.0"},"foot.line":{"ar":"تعليم مفتوح للتحليل الجنائي الرقمي في الكويت والخليج","en":"Open digital forensics education for Kuwait and the Gulf"},"glo.module":{"ar":"في الدورة","en":"In the course"},"glo.search":{"ar":"ابحث بالعربية أو الإنجليزية","en":"Search in Arabic or English"},"glo.title":{"ar":"المصطلحات","en":"Glossary"},"hash.changed":{"ar":"تغيّر بتّ واحد في المدخلات فتغيّر في قيمة SHA-256 عدد من البتات قدره {n} من أصل 256.","en":"{n} of the 256 bits of the SHA-256 value changed after one bit of input changed."},"hash.flip":{"ar":"اقلب بتّاً واحداً","en":"Flip one bit"},"hash.input":{"ar":"اكتب أي نص أو الصقه","en":"Type or paste anything"},"hash.sample":{"ar":"التسعيرة النهائية لمناقصة 2026","en":"Tender 2026 final pricing"},"hero.alt":{"ar":"قصّاص أثر كويتي يجثو عند الفجر ليقرأ آثار الأقدام في الرمل","en":"A Kuwaiti tracker kneels at dawn to read footprints in the sand"},"hero.case":{"ar":"افتح القضية التدريبية","en":"Open the practice case"},"hero.lede":{"ar":"تعليم مفتوح للتحليل الجنائي الرقمي في الكويت والخليج يضم {m} وحدة و{l} مختبرات تطبيقية على أدلة مصطنعة ونحو {h} ساعة من الدراسة بالعربية والإنجليزية.","en":"Open digital forensics education for Kuwait and the Gulf, with {m} modules, {l} hands on labs on synthetic evidence and about {h} hours of study, in Arabic and English."},"hero.start":{"ar":"ابدأ التعلّم","en":"Start learning"},"hero.title":{"ar":"اقرأ الأثر وأثبت كل خطوة","en":"Read the trace. Prove every step."},"kit.lede":{"ar":"كل ما يعلّمه الموقع يعمل أيضاً على جهازك فقصّاص مجموعة أدوات بلغة Python بلا اعتماديات ومعها خادم MCP للمساعدات الذكية.","en":"Everything the site teaches also runs on your own machine. Qassas is a Python toolkit with no dependencies and an MCP server for AI assistants."},"kit.p1":{"ar":"البصمات وسجلات البصمات وسجل حيازة مسلسل بالبصمات","en":"Hashes, manifests and a hash chained custody log"},"kit.p2":{"ar":"التواقيع والنحت والبيانات الوصفية والنصوص العربية","en":"Signatures, carving, metadata and Arabic aware strings"},"kit.p3":{"ar":"تحليل المتصفح والاختصارات والسجلات والحزم على خط زمني واحد","en":"Browser, shortcut, log and packet analysis on one timeline"},"kit.title":{"ar":"مجموعة الأدوات","en":"The toolkit"},"lab.choose":{"ar":"اختر ملفاً","en":"Choose a file"},"lab.drop":{"ar":"أو أفلته هنا","en":"or drop it here"},"lab.samples":{"ar":"عينات من القضية","en":"Case samples"},"labs.all":{"ar":"كل المختبرات","en":"All labs"},"labs.col.do":{"ar":"ما الذي تفعله","en":"What you do"},"labs.col.lab":{"ar":"المختبر","en":"Lab"},"labs.col.module":{"ar":"الوحدة","en":"Module"},"labs.lede":{"ar":"يعمل كل مختبر داخل متصفحك بالكامل على الأدلة المصطنعة للقضية التدريبية أو على ملفات تختارها بنفسك.","en":"Each lab runs entirely in your browser on the synthetic evidence of the practice case, or on files you choose yourself."},"labs.private":{"ar":"تبقى الملفات التي تفتحها في المختبرات داخل متصفحك ولا تُرفع إلى أي مكان.","en":"Files you open in the labs stay in your browser and are never uploaded."},"labs.title":{"ar":"المختبرات","en":"Labs"},"lang.name":{"ar":"العربية","en":"English"},"law.all":{"ar":"السجل الكامل","en":"The full register"},"law.countries":{"ar":"الدول","en":"Countries"},"law.lede":{"ar":"قوانين الجرائم الإلكترونية والدليل الإلكتروني والإبلاغ عن الاختراق في دول الخليج مع المعايير الدولية وكل منها مرتبط بمصدره.","en":"Cybercrime, electronic evidence and breach reporting laws across the GCC, with international standards, each linked to its source."},"law.notadvice":{"ar":"هذه مادة تعليمية وليست استشارة قانونية لذا راجع الجريدة الرسمية قبل الاعتماد على أي نص.","en":"This is teaching material, not legal advice. Check the official gazette before relying on any provision."},"law.notes":{"ar":"ملاحظات البحث (بالإنجليزية)","en":"Research notes"},"law.source":{"ar":"المصدر","en":"Source:"},"law.title":{"ar":"القانون في الكويت والخليج","en":"Law in Kuwait and the Gulf"},"learn.all":{"ar":"كل الوحدات","en":"All modules"},"learn.haslab":{"ar":"مختبر","en":"lab"},"learn.hours":{"ar":"عدد الساعات {h}","en":"Hours {h}"},"learn.lede":{"ar":"تتبع خمس عشرة وحدة الأثر من أول علامة حتى قاعة المحكمة وفي كل وحدة درس وخطوات وأخطاء شائعة وملاحظة عن القانون الكويتي واختبار قصير.","en":"Fifteen modules follow the trail from the first trace to the courtroom. Each has a lesson, steps, common mistakes, a note on Kuwaiti law and a short quiz."},"learn.module":{"ar":"الوحدة {n}","en":"Module {n}"},"learn.title":{"ar":"الدورة","en":"The course"},"mod.commands":{"ar":"جرّبه بالأدوات","en":"Try it with the toolkit"},"mod.kuwait":{"ar":"في الكويت","en":"In Kuwait"},"mod.law":{"ar":"القوانين والمعايير","en":"Laws and standards"},"mod.lesson":{"ar":"الدرس","en":"The lesson"},"mod.next":{"ar":"التالية","en":"Next"},"mod.objectives":{"ar":"ستتمكن من","en":"You will be able to"},"mod.openlab":{"ar":"افتح المختبر {lab}","en":"Open the lab: {lab}"},"mod.pager":{"ar":"الوحدة السابقة والتالية","en":"Previous and next module"},"mod.pitfalls":{"ar":"أخطاء شائعة","en":"Common mistakes"},"mod.prev":{"ar":"السابقة","en":"Previous"},"mod.quiz":{"ar":"اختبر نفسك","en":"Check yourself"},"mod.steps":{"ar":"الخطوات","en":"Steps"},"mod.terms":{"ar":"المصطلحات","en":"Terms"},"mod.tools":{"ar":"أدوات مفتوحة المصدر","en":"Open source tools"},"nav.about":{"ar":"عن المشروع","en":"About"},"nav.case":{"ar":"القضية","en":"The case"},"nav.glossary":{"ar":"المصطلحات","en":"Glossary"},"nav.home":{"ar":"الرئيسية","en":"Home"},"nav.label":{"ar":"الأقسام","en":"Sections"},"nav.labs":{"ar":"المختبرات","en":"Labs"},"nav.law":{"ar":"القانون","en":"Law"},"nav.learn":{"ar":"التعلّم","en":"Learn"},"nav.skip":{"ar":"تخطَّ إلى المحتوى","en":"Skip to content"},"nav.tools":{"ar":"الأدوات","en":"Tools"},"nav.watch":{"ar":"شاهد","en":"Watch"},"nf.body":{"ar":"هذه الصفحة غير موجودة فعُد إلى البداية وتتبع الأثر من هناك.","en":"This page does not exist. Go back to the start and follow the trail from there."},"nf.title":{"ar":"لا أثر هنا","en":"No trail here"},"quiz.right":{"ar":"إجابة صحيحة.","en":"Correct."},"quiz.wrong":{"ar":"ليست الإجابة الصحيحة.","en":"Not quite."},"sig.detected":{"ar":"المحتوى","en":"Content is"},"sig.expected":{"ar":"الامتدادات المناسبة","en":"Names that would fit"},"sig.first":{"ar":"البايتات الأولى مع إبراز التوقيع","en":"First bytes, signature highlighted"},"sig.match":{"ar":"يطابق الاسم المحتوى.","en":"The name matches the content."},"sig.mismatch":{"ar":"لا يطابق الاسم المحتوى.","en":"The name does not match the content."},"sig.name":{"ar":"اسم الملف","en":"File name"},"sig.unknown":{"ar":"لا يوجد توقيع معروف لذا افحص البايتات بنفسك.","en":"No known signature, so look at the bytes yourself."},"site.short":{"ar":"قصّاص","en":"Qassas"},"site.title":{"ar":"قصّاص للتحليل الجنائي الرقمي في الكويت والخليج","en":"Qassas: digital forensics for Kuwait and the Gulf"},"src.auth_log":{"ar":"خادم الملفات","en":"File server"},"src.browser":{"ar":"المتصفح","en":"Browser"},"src.custody":{"ar":"الحيازة","en":"Custody"},"src.document":{"ar":"المستند","en":"Document"},"src.exif":{"ar":"الصورة","en":"Photo"},"src.lnk":{"ar":"الاختصار","en":"Shortcut"},"src.network":{"ar":"الشبكة","en":"Network"},"src.windows":{"ar":"أحداث Windows","en":"Windows events"},"stage.acquire":{"ar":"الحصول","en":"Acquire"},"stage.acquire.d":{"ar":"خذ نسخة موثقة عبر مانع الكتابة","en":"Take a verified copy through a write blocker"},"stage.analyse":{"ar":"التحليل","en":"Analyse"},"stage.analyse.d":{"ar":"اقرأ النسخة وابنِ الخط الزمني","en":"Read the copy and build the timeline"},"stage.identify":{"ar":"التحديد","en":"Identify"},"stage.identify.d":{"ar":"اعثر على ما قد يحوي الأدلة وأمّنه","en":"Find what could hold evidence and secure it"},"stage.present":{"ar":"العرض","en":"Present"},"stage.present.d":{"ar":"اعرض نتائج يستطيع غيرك تكرارها","en":"Report findings others can repeat"},"stage.preserve":{"ar":"الحفظ","en":"Preserve"},"stage.preserve.d":{"ar":"امنعه من التغير وابدأ سجل الحيازة","en":"Stop it changing and start the custody log"},"stages.title":{"ar":"خمس مراحل في كل مرة","en":"Five stages, every time"},"tl.kuwait":{"ar":"الكويت","en":"Kuwait"},"tl.pivots":{"ar":"اللحظات المفصلية فقط","en":"Key moments only"},"tl.strip":{"ar":"صباح 4 أكتوبر 2026 مع مسار لكل مصدر","en":"The morning of 4 October 2026, one lane per source"},"tl.zone":{"ar":"المنطقة الزمنية","en":"Time zone"},"tools.title":{"ar":"أدوات مفتوحة المصدر","en":"Open source tools"},"type.court":{"ar":"حكم قضائي","en":"Court ruling"},"type.decision":{"ar":"قرار","en":"Decision"},"type.framework":{"ar":"إطار أو معيار","en":"Framework or standard"},"type.law":{"ar":"قانون","en":"Law"},"type.regulation":{"ar":"لائحة","en":"Regulation"},"watch.caption":{"ar":"المدة بالثواني {d} مع ترجمة نصية","en":"Length in seconds {d}, with captions"},"watch.credit":{"ar":"صُنعت الرسوم باستخدام Higgsfield وسُجّل التعليق الصوتي باستخدام ElevenLabs بصوت راوٍ كويتي للعربية وصوت وثائقي للإنجليزية.","en":"Illustrations made with Higgsfield. Narration voiced with ElevenLabs, by a Kuwaiti narrator for Arabic and a documentary voice for English."},"watch.lede":{"ar":"شرح قصير للحرفة كلها من الأثر الأول حتى التقرير النهائي بصوت عربي وآخر إنجليزي.","en":"A short explainer of the whole craft, from the first trace to the final report, narrated in Arabic and English."},"watch.scenes":{"ar":"مشاهد من الدورة","en":"Scenes from the course"},"watch.title":{"ar":"كيف يعمل التحقيق الجنائي الرقمي","en":"How digital forensics works"}},"version":"1.0.0","videos":{"ar":{"seconds":79,"src":"media/explainer/qassas-explainer-ar.mp4","vtt":"media/explainer/qassas-explainer-ar.vtt"},"en":{"seconds":80,"src":"media/explainer/qassas-explainer-en.mp4","vtt":"media/explainer/qassas-explainer-en.vtt"}}}
