Digital Forensics Flashcards
What is the Forensic Process by NIST?
Collection, Examination, Analysis, Reporting
What is Admissibility?
Relatability to disputed facts and violations
What is the Order of Volatility?
Securing more perishable evidence first
What is Random Access Memory (RAM)
Volatile memory used to run applications
What is the CPU Cache?
A fast block of volatile memory used by the CPU
What is used when RAM is exhausted?
Swap/Page File/ Virtual Memory
What does RAM stand for
Random Access Memory
What can command-line tools be used for?
Showing information about the computer and the established ports
What is the Chain of Custody?
Ensurance of evidence being collected with no breaks in the chain
Crucial Aspect
What is it known as when Chain of Custody has been carried out properly?
Data Provenance
What is it known as to protect documents that are evidence?
Legal or Litigation hold
What are Artifacts
Log files
Registry hives
DNA
Why do we have top take Forensic Copies?
For analyzing; we must keep the original data intact and unaltered
Why do we take System Images
To capture a PC and search for criminal activity
What can be reverse engineered, and is susceptible to rootkit and backdoor attacks?
Firmware or Embedded Systems