What are Digital Forensics?
Systematic process of investigating and analyzing digital devices and data to uncover evidence for legal purposes
What does the 1st phase of Digital Forensics - Identification do?
Focus on scene safety, prevention of evidence contamination, and scope determination
What does the 2nd phase of Digital Forensics - Collection do?
Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields
What is the Order of Volatility?
Dictates the sequence in which data sources should be collected and preserved based on their susceptibility to rapid changes during system operation
What is the Order of Volitility?
■ Collect data from the system’s memory
■ Capture data from the system state
■ Collect data from storage devices
■ Capture network traffic and logs
■ Collect remotely stored or archived data
What is a Chain of Custody
Documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment it is collected until it is presented in a court of law
What is Disk Imaging? (copying storage device)
Involves creating a bit-by-bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space
What does File Carving do?
Focuses on extracting files and data fragments from storage media without relying on the file system
What does the 3rd phase of Digital Forensics - Analysis do?
Systematically scrutinizing data to uncover relevant information like, timestamps, user interactions, and signs of criminal activity
What does the 4th phase of Digital Forensics - Reporting do?
Involves documenting the findings, processes, and methodologies used during a digital forensic investigation in a final report
What is a Legal Hold?
Formal notification that instructs employees to preserve potentially relevant electronic data, documents and records
What is an E-Discovery (Electronic Discovery)?
Process of identifying, collecting, and presenting electronically stored information for potential legal proceedings