5.5 Basic concepts of forensics Flashcards
Order of volatility
Order of volatility of evidence from more to less:
- CPU registers and cache memory
- Routing table, arp cache, process table, kernel statistics
- Memory (RAM)
- Temporary file systems
- Disk
- Remote logging and monitoring data
- Physical configuration and network topology
- Archival media
Chain of custody
Form records where, when, and who collected the evidence, who subsequently handled it, and where it was stored.
Legal hold
Refers to the fact that information that may be relevant to a court case must be preserved.
Capture system image
The process of obtaining a forensically clean copy of data from a device held as evidence.
Task hashes
Demonstrates that analysis has been performed on an image of the data that is identical to the data present on the disk and that neither data set has been tampered with.
Preservation
Best practice is that evidence should be preserved and documented at the crime scene in its original state; that is, computers or other devices that are off should not be switched on and those that are on should not be switched off.
Recovery
Analyzing information from hard drives taken as evidence
Strategic intelligence/counterintelligence gathering
Counterintelligence is the process of information gathering to protect against espionage and hacking.