Digital Forensics Basics · Lesson 1 of 5
What the machine remembers
Understand what forensics can establish.
Digital forensics is the work of finding out what happened on a system, from what it recorded, in a way that holds up when questioned.
Computers record a great deal that people do not realise. When a file was created, modified and last accessed. Which programs ran and when. Which devices were attached. Which sites were visited. Which accounts signed in from where. Deleted files that remain on the disk until the space is reused. And in memory, what was running at the moment it was captured.
Where this is used. After a security incident, to establish how somebody got in and what they reached. In employment disputes, over data theft or misuse. In fraud investigations. In litigation, where digital evidence is produced. And internally, to answer what actually happened before deciding what to do about it.
The central discipline is preserving rather than examining. The instinct on finding a compromised machine is to look at it, and looking changes it: opening a file updates its access time, running a program writes to the disk, and shutting it down destroys everything in memory.
So the first rule is to stop and preserve before investigating, which is the opposite of the instinct and is the single thing that separates an investigation that establishes something from one that destroys the evidence and then guesses.
And be honest about when to call somebody. Anything that may end in a court, a dismissal or a regulatory report should involve a qualified examiner early, because evidence handled badly cannot be repaired afterwards.
Write down what your first three actions would be on finding a compromised machine. If the first is "look at it", revise the list.
لکھیں کہ کمپرومائزڈ مشین ملنے پر آپ کے پہلے تین اقدامات کیا ہوں گے۔ اگر پہلا "دیکھنا" ہے تو فہرست بدلیں۔
Check what you learned
Create your free BvLogic ID to take the quiz and record your score.
Create your BvLogic ID