Week 1 - What Is LDF Flashcards

1
Q

Summarise what is LDF

A
  • Collection & analysis of data from live systems. This means it relates to data that is:

VOLATILE
IN TEMPOARY STATES
includes
ACTIVE NETWORK CONNECTIONS
RUNNING PROCESSES
MEMORY CONTENTS.

Goal is to preserve and obtain data that would be lost when the device is powered down.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Summarise the relationship between Live Response & Live Aquisition

A

LIVE RESPONSE is the immediate actions taken to preserve volatile data.
(e.g actions like isolating the system to prevent data exfiltration* and identifying active malicious processes)

LIVE AQUISITION involves the collection of the volatile data (e.g taking a RAM dump or capturing network traffic)

  • Data exfiltration is the intentional, unauthorized, covert transfer of data from a computer or other device.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

List the basic steps when conducting LDF

A
  1. Preparation & planning (objectives of investigation clearly defined & necessary tools prepared. Includes which data to prioritise).
  2. Establishing a secure environment (e.g where possible isolate systems from the network).
  3. Volatile Data Acquisition. Capture data from RAM, active processes and network connections.
  4. Non volatile data collection
  5. Documentation & logging. Documentation must be thorough. Ensure actions are fully recorded, justified and traceable. Ensure reliability and integrity of evidence foradmissibility in court.
  6. Analysis of data
  7. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Summary of LDF Requirements

A
  • Requires careful planning, execution and thorough documentation
  • Requires ability to act swiftly and accurately
  • Requires regular practice and continuous learning and updating of knowledge and skills
How well did you know this?
1
Not at all
2
3
4
5
Perfectly