This document summarizes solutions to forensic analysis problems from the 3th HolyShield Forensics competition. It includes explanations for 4 problems of increasing difficulty: Forensics 200, finding a hidden file in an image by analyzing slack space and file metadata; Forensics 300, discovering a secret file downloaded and accessed on a computer; Forensics 400, recovering an airport access key sent by an internal computer user to an external hacker; and a final section for question and answers. The document provides technical details on digital forensic techniques used such as filesystem analysis, jumplist parsing, password cracking, and memory analysis.