Chapter 10: Reports Flashcards
what is the foundation to your reporting
your notes
what are the fundamental elements of notetaking
- when you did smth
- what you did
- what you saw
- why you did smth
when does notetaking start
- when you get the notification/ you have to respond to the scene
- including time, who notified you, when you arrive at scene
why are we willing to alter digital evidence when collecting RAM
cause it would be lost if it wasn’t collected in time
are notes taken by hand or digital?
up to the person (but be consistent)
what is the purpose of the report
- to document the results of your examination
- can be used in court/ administrative proceedings
what is a general template that can address the technical and non-technical audience
- administrative info
- executive summary
- narrative
- exhibits/ technical details
- glossary
what sort of info is in the administrative section
- name of agency, case number, participants
- when it started and what happened before you were called onto the case
what sort of info is in the executive summary
- should only be 10% of report
- short, concise paragraphs
- follow same timeline as narrative
- not include info not in narratuve
- contain findings/ conclusions
what is the difference between the executive summary and narrative
- executive summary is in easy plain language that anyone can understand, and very summed up and to the point
- narrative explains EVERYTHING with the precise terms for the experts
what are the sections within the narrative
- evidence analyzed
- acquisition details
- analysis details
- exhibit/ technical details
what is described in the evidence analyzed section of the narrative
include all evidence examined, including make/model, serial numbers etc
what is described in the acquisition details section of the narrative
- describe the acquisition process of creating the forensic image(s)
- hardware/software used in the process and version numbers
what is described in the analysis details section of the narrative
- analyse the artifacts and explain why it is relevant to the investigation to the reader
- include ss, AND explain what the ss is showing, don’t assume they know what the ss means
what is described in the exhibit/ technical details section of the narrative
- ss of the artifacts should be placed here
- include output reports of the tools used in the exam process
- literally anything you reference in your narrative should be here