Earlier this year, Beyond Securitys beSIRT released an incident response forensic analysis of a defacement attack by Team Evil [Team Evil Incident (Cyber-terrorism defacement analysis and response)]. A follow up is being released today, on a second incident. Following what Team Evil did, their methodology and how it changed since the first document was released. The aim of this document is more to show how such analysis is done, on an educational note.