Week 1 - What Is LDF Flashcards
1
Q
Summarise what is LDF
A
- Collection & analysis of data from live systems. This means it relates to data that is:
VOLATILE
IN TEMPOARY STATES
includes
ACTIVE NETWORK CONNECTIONS
RUNNING PROCESSES
MEMORY CONTENTS.
Goal is to preserve and obtain data that would be lost when the device is powered down.
2
Q
Summarise the relationship between Live Response & Live Aquisition
A
LIVE RESPONSE is the immediate actions taken to preserve volatile data.
(e.g actions like isolating the system to prevent data exfiltration* and identifying active malicious processes)
LIVE AQUISITION involves the collection of the volatile data (e.g taking a RAM dump or capturing network traffic)
- Data exfiltration is the intentional, unauthorized, covert transfer of data from a computer or other device.
3
Q
List the basic steps when conducting LDF
A
- Preparation & planning (objectives of investigation clearly defined & necessary tools prepared. Includes which data to prioritise).
- Establishing a secure environment (e.g where possible isolate systems from the network).
- Volatile Data Acquisition. Capture data from RAM, active processes and network connections.
- Non volatile data collection
- Documentation & logging. Documentation must be thorough. Ensure actions are fully recorded, justified and traceable. Ensure reliability and integrity of evidence foradmissibility in court.
- Analysis of data
- Reporting
4
Q
Summary of LDF Requirements
A
- Requires careful planning, execution and thorough documentation
- Requires ability to act swiftly and accurately
- Requires regular practice and continuous learning and updating of knowledge and skills