Week 3 - Evidence Collection Flashcards
What is the acquisition stage of an investigation?
It involves capture and seizure of digital devices, hardware and data that is to be investigated.
What happens during acquisition of digital evidence?
It begins when information and/or physical items are collected for investigation purposes. Preserving (Imaging) and processing the content and data of the device is the next stage.
When acquiring digital devices/disks it is important to?
Where gloves when appropriate
Store in sealed backs
Sign by each person who the device with in possession of (Include name, and date obtained, and date passed on)
What does a device need to be connected to to faciliate imaging?
The analysts device.
What are the steps involved in imaging?
- Remove the storage media from suspect’s device
- Connect to imagin workstation
- Assess size and contents (Use mmls command in sleuthkit to display the partition layout of disk, DO NOT to change contents)
- Make a bit for bit copy of the disk (Using dd, dcfldd command or similar)
- Verify the integrity of copy using checksums
- Return the original disk to an evidence locker
How might you connect a disk to analysts machine?
Insert as an additional internal disk in the PC.
Add as an external drive (Using external connectors, disk caddy etc..).
What should be considered when storing an image copy?
Should you store the copy on a disk the same size as the original or bigger.
Should you use an identical disk
Should you use an local imaging fileserver.
What must you do to a target disk for an image before it is used?
It must be forensic-ly cleaned/wiped as to not tamper with the new data being copied to it.
What commands are used to make a bit for bit iamge copy of a disk?
The dd command in linux
The dcfldd command in sleuthkit