Host forensics is a ridiculous amount of work. There's a ton to write and read, or you can just do... guess what I recommend.
Using a combination of this CTFd site: https://defcon2019.ctfd.io/challenges
The files hosted at this link: https://drive.google.com/drive/folders/1JwK8duNnrh12fo9J_02oQCz8HlILKAdW
And this walkthrough: https://www.jaiminton.com/Defcon/DFIR-2019/#category-deadbox-forensics
Work through all the problems in the "Deadbox Forensics" category of the CTF.
Submit screenshots of your answers for "Hello, my name is", "Let’s chat", " Someone actually read that", and a brief writeup of how "her name is snow" works.