Anatomy of an Active Incident: Incident Scoping & Live RAM
How examiners triage live corporate networks during security incidents (such as business email compromise deepfakes), the physical volatility of RAM evidence, and the legal constraints of employer search authority. Welcome to reWandt Courseware, an AI-narrated technology video series unpacking the latest lectures and thoughts from Professor Adam Scott Wandt of the John Jay College of Criminal Justice in New York City. This video covers Module 2 content. Key Cases/Standards Covered: *United States v. Jacobson* (1984) Private Search Doctrine limits, Arup $25M deepfake BEC, and Ferrari CEO voice clone incident. TIMESTAMPS: 0:00 - Intro / Video Start 0:49 - Introduction & Overview 2:50 - Focus on Incident Response 3:09 - Synthesis & Course Connections 5:26 - Conclusion & Outro ๐ Explore further research and courseware resources at: https://reWandt.com โ๏ธ DISCLAIMER: This video was generated using artificial intelligence narration and compilation. While we make every effort to ensure the accuracy and correctness of the courseware and materials presented, minor errors or incongruities may occasionally occur. The content and presentation do not necessarily represent the official viewpoints or personal opinions of Professor Adam Scott Wandt. #reWandt #Module2 #IncidentResponse
Key Takeaways & Core Ideas
- โชAI-narrated transformation
- โชSource-connected material analysis
Source Excerpt
"How examiners triage live corporate networks during security incidents (such as business email compromise deepfakes), the physical volatility of RAM evidence, and the legal constraints of employer search authority."
Related Episodes & Topics

Email Forensics & OSINT: Header Tracing, SPF/DKIM & CFAA
Tracing email infrastructure (SPF/DKIM/DMARC), geolocating originating IPs, harvesting open-source intelligence, username correlation, and legal boundaries of public collection. Welcome to reWandt Courseware, an AI-narrated technology video series unpacking the latest lectures and thoughts from Professor Adam Scott Wandt of the John Jay College of Criminal Justice in New York City. This video covers Module 14 content. TIMESTAMPS: 0:00 - Intro / Video Start 0:22 - Introduction & Overview 1:12 - Synthesis & Course Connections 7:32 - Conclusion & Outro ๐ Explore further research and courseware resources at: https://reWandt.com โ๏ธ DISCLAIMER: This video was generated using artificial intelligence narration and compilation. While we make every effort to ensure the accuracy and correctness of the courseware and materials presented, minor errors or incongruities may occasionally occur. The content and presentation do not necessarily represent the official viewpoints or personal opinions of Professor Adam Scott Wandt. #reWandt #Module14 #EmailHeaders

Browser Forensics: SQLite Timelines, Incognito & Credentials
Extracting user browser profiles, parsing SQLite history databases, WebKit Epoch timestamp conversions, incognito recovery, and stored local credentials. Welcome to reWandt Courseware, an AI-narrated technology video series unpacking the latest lectures and thoughts from Professor Adam Scott Wandt of the John Jay College of Criminal Justice in New York City. This video covers Module 13 content. Key Cases/Standards Covered: Sergey Aleynikov exfiltration, Silk Road digital timeline (Ross Ulbricht), and the *Brian Walshe* murder trial Google searches. TIMESTAMPS: 0:00 - Intro / Video Start 0:20 - Introduction & Overview 5:45 - Conclusion & Outro ๐ Explore further research and courseware resources at: https://reWandt.com โ๏ธ DISCLAIMER: This video was generated using artificial intelligence narration and compilation. While we make every effort to ensure the accuracy and correctness of the courseware and materials presented, minor errors or incongruities may occasionally occur. The content and presentation do not necessarily represent the official viewpoints or personal opinions of Professor Adam Scott Wandt. #reWandt #Module13 #SqliteHistory

Reconstructing Agentic Fraud: Cloud Logs, Prompt Injection & BEC
Cloud incident timeline reconstruction, indirect prompt injection (OWASP Top 10), Edge AI local processing limits, and due process standards for machine-generated evidence. Welcome to reWandt Courseware, an AI-narrated technology video series unpacking the latest lectures and thoughts from Professor Adam Scott Wandt of the John Jay College of Criminal Justice in New York City. This video covers Module 12 content. Key Cases/Standards Covered: Arup CFO deepfake BEC ($25 million transfer), *Mathews v. Eldridge* due process balancing framework, NSA/CISA cloud retention guidelines. TIMESTAMPS: 0:00 - Intro / Video Start 0:13 - Introduction & Overview 8:00 - Conclusion & Outro ๐ Explore further research and courseware resources at: https://reWandt.com โ๏ธ DISCLAIMER: This video was generated using artificial intelligence narration and compilation. While we make every effort to ensure the accuracy and correctness of the courseware and materials presented, minor errors or incongruities may occasionally occur. The content and presentation do not necessarily represent the official viewpoints or personal opinions of Professor Adam Scott Wandt. #reWandt #Module12 #CloudForensics