Digital Forensics Analyst

Digital Forensics Analyst completes 20 tasks that map core responsibilities and common exceptions. Each entry includes timing, required actions and how the Cybersecurity norms shape choices. Each one shows where we found it, and comes with an AI prompt you can copy and use straight away.

20evidenced tasks
20ready prompts
8tools of the trade
15-1299.06O*NET-SOC code
435,370hold this job (US, BLS 2025)
$116,580median pay/yr (US)
Open Digital Forensics Analyst in the interactive atlas →

What it pays

Government survey numbers — not estimates, not ads.

Half of all Computer Occupations, All Other in the U.S. earn more than $116,580 a year — the middle 80% land between $55,940 and $188,470. About 435,370 people in the U.S. do this work. Figures are for the U.S. occupation group “Computer Occupations, All Other”. (U.S. Bureau of Labor Statistics survey, published 2025.) In India, Professionals earn about ₹38,298 a month on average — around ₹4.6 lakh a year (government PLFS survey via ILOSTAT, occupation-family figure).
$116,580typical pay / year
435,370people in this work
$188,470+top 10% earn
₹4.6 lakha year in India (family avg)
Think you get this job?Six quick questions on how it really works — with a hint and the reason behind every answer.
Test yourself →

The work, task by task

These are the real jobs-to-be-done, not a wish list. Each task shows where we found it, and the prompt underneath is written for that exact task.

Analysing5

Recover digital information

+
Image a seized laptop and an evidence USB from the fraud desk: create a full forensic image of the laptop,…
Image a seized laptop and an evidence USB from the fraud desk: create a full forensic image of the laptop, verify hash integrity, document chain of custody, and stage the image for targeted recovery of deleted documents and email before 5pm today.
The tools that do the workBashESCOjob descriptionsO*NET

Analyze volatile data and malware

+
From the incident VM snapshot and memory dump from the SOC, extract running processes, network sockets and…
From the incident VM snapshot and memory dump from the SOC, extract running processes, network sockets and loaded modules, run behavior extraction on the suspicious binary, and produce a one-page summary of IOC and recommended containment actions for the IR lead by noon.
The tools that do the workC++job descriptionsO*NET

Analyse digital information

+
Gather disk images, mobile backups and relevant server logs for the client breach, correlate file timestamps…
Gather disk images, mobile backups and relevant server logs for the client breach, correlate file timestamps and account activity, identify likely exfiltration paths and vulnerable hosts, and deliver a prioritized list of artifacts and next investigative steps by tomorrow afternoon.
The tools that do the workGoogle WorkspaceESCOjob descriptions

Perform file signature analysis

+
Using the suspect file set from the case folder, calculate file signatures, compare them to known-good and…
Using the suspect file set from the case folder, calculate file signatures, compare them to known-good and known-bad signature sets, flag mismatches and probable obfuscated files, and write a short evidential note for the prosecutor by end of day.
The tools that do the workGojob descriptionsO*NET

Preserve digital information

+
Take custody of the mobile handset and workstation, write tamper-proof preservation records, apply for the…
Take custody of the mobile handset and workstation, write tamper-proof preservation records, apply for the forensic warrant chain, isolate storage with write-blocking, and create verified copies with hashes so the legal team can review them tomorrow morning.
The tools that do the workApple macOSESCOO*NET
Protecting1

Strengthen cybersecurity protections

+
Assess the breached subnet and failed detective controls: map outward-facing services, enumerate exploitable…
Assess the breached subnet and failed detective controls: map outward-facing services, enumerate exploitable configurations, recommend three prioritized hardening measures and a monitoring plan to reduce repeat incidents for the IT director within 48 hours.
The tools that do the workAnsibleBashjob descriptionsO*NET
The daily work14

Develop information security strategy

+
Draft a concise information security strategy for the next 12 months that prioritises protecting case…
Draft a concise information security strategy for the next 12 months that prioritises protecting case evidence and client data, maps current gaps in controls, assigns owners for encryption, access reviews and incident response, and lists compliance milestones by quarter.
The tools that do the workAmazon Web Services AWSESCOsee the evidence ↗

ICT network security risks

+
Produce a risk assessment of our network infrastructure showing top five ICT network threats, the affected…
Produce a risk assessment of our network infrastructure showing top five ICT network threats, the affected devices and services, likelihood and impact scores, recommended mitigations for perimeter and internal segmentation, and an action list with owners and two-week priorities.
The tools that do the workBorder Gateway Protocol BGPESCOsee the evidence ↗

Identify clues in source code and configurations

+
Scan the repository and live configs for suspicious functions, hardcoded credentials, commented-out endpoints…
Scan the repository and live configs for suspicious functions, hardcoded credentials, commented-out endpoints and unexpected service calls, extract the relevant source snippets with file paths and timestamps, and flag anything that could expose confidential data to the incident lead by 1600 today.
The tools that do the workBashjob descriptionsO*NET

Assist in criminal investigations

+
Collect device images, user activity logs, and network flow snippets that relate to the suspect accounts,…
Collect device images, user activity logs, and network flow snippets that relate to the suspect accounts, preserve chain-of-custody notes, and prepare an evidence bundle with a concise timeline for Detective Marquez before the morning briefing on Wednesday.
The tools that do the workApple macOSjob descriptionsO*NET

Report findings to cybersecurity frameworks

+
Map our validated findings to the organisation's control set, list affected controls with severity and…
Map our validated findings to the organisation's control set, list affected controls with severity and suggested remediations, and produce a one-page summary for the compliance manager and the CISO by Friday COB.
The tools that do the workGoogle Workspacejob descriptionsO*NET

Preserve and maintain digital forensic evidence for analysis.

+
Create bit-for-bit copies of the target drives, verify hashes, store originals in evidence lockers, and build…
Create bit-for-bit copies of the target drives, verify hashes, store originals in evidence lockers, and build a documented archive with access restrictions so analysts can examine copies without touching original media.
The tools that do the workApple macOSO*NET

Develop policies or requirements for data collection, processing, or reporting.

+
Draft mandatory collection, processing and reporting rules that require hashed identifiers, retention limits,…
Draft mandatory collection, processing and reporting rules that require hashed identifiers, retention limits, approved acquisition methods, and reviewer sign-off, circulate to legal and privacy by Tuesday for feedback.
The tools that do the workGoogle WorkspaceO*NET

Write and execute scripts to automate tasks, such as parsing large data files.

+
Write a parsing script to ingest the five largest log files, normalise timestamps, extract IPs, user IDs and…
Write a parsing script to ingest the five largest log files, normalise timestamps, extract IPs, user IDs and error codes, and output filtered CSVs that update when new logs are dropped into the intake folder.
The tools that do the workGoO*NET

Conduct threat assessment audits

+
Run a threat assessment across the corporate network, catalogue exposed services and misconfigurations, score…
Run a threat assessment across the corporate network, catalogue exposed services and misconfigurations, score each finding by business impact and exploitability, and hand a one-page risks summary with remediation priorities to the CISO by Wednesday.
The tools that do the workBashBorder Gateway Protocol BGPjob descriptions

Support incident response teams

+
Join the active incident response call, triage newly acquired artefacts, extract Indicators of Compromise,…
Join the active incident response call, triage newly acquired artefacts, extract Indicators of Compromise, update the incident timeline and notify the SOC and legal teams of high-priority IOC changes within the hour.
The tools that do the workGoogle WorkspaceBashjob descriptions

Follow chains of custody for evidence

+
Create and maintain an evidence log for the case file, record every transfer, who handled it, timestamps and…
Create and maintain an evidence log for the case file, record every transfer, who handled it, timestamps and hash values, then produce a signed chain-of-custody report for the prosecution by close of business Friday.
The tools that do the workGoogle Workspacejob descriptions

Investigate hacking and fraud cases

+
Perform a deep-dive on the suspected intrusion, reconstruct attacker actions from logs and disk images, link…
Perform a deep-dive on the suspected intrusion, reconstruct attacker actions from logs and disk images, link fraudulent transactions to compromised hosts, and prepare a forensically sound investigation brief for the fraud team next Tuesday.
The tools that do the workBashjob descriptions

Analyse information from computers and data storage devices

+
Acquire and image the suspect computers and external drives, extract file metadata and deleted artifacts,…
Acquire and image the suspect computers and external drives, extract file metadata and deleted artifacts, produce a searchable evidence bundle and deliver a technical findings memo to the legal lead within three working days.
The tools that do the workBashESCO

Educate on data confidentiality

+
Draft and deliver a forty-five minute briefing for managers explaining data confidentiality risks observed,…
Draft and deliver a forty-five minute briefing for managers explaining data confidentiality risks observed, required handling controls, and three actionable policy changes they must approve at next Thursday's security meeting.
The tools that do the workGoogle WorkspaceESCOsee the evidence ↗

Says who?

These are the pages we read to build this. Open any of them and check us.

The logs, files & records this job keeps

Shared with other careers — the same record means something different in each.

Related careers

Same family of work — each with its own tasks and prompts.

The LLOS Work Atlas is the world's largest evidenced task library — a map of human work, with a ready prompt behind every task. 1,774 careers · every task named by the sources that witnessed it — O*NET, ESCO, real job descriptions, Wikipedia — and the deepest tasks by several at once. And it is honest about limits: where AI cannot help, the map says so.

The rest of the map

Same library, five ways in.

Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.
Built on public evidence: O*NET®, ESCO, Wikipedia, U.S. Bureau of Labor Statistics, ILOSTAT. All sources & licenses