Digital Forensics Basics 5 lessons
  1. 1 What the machine remembers
  2. 2 Preserving evidence sign in to open
  3. 3 What the analysis looks at sign in to open
  4. 4 Reporting and the limits sign in to open
  5. 5 Preparing an organisation for an investigation sign in to open
Course overview
Data: video · change

This lesson: 122KB

Digital Forensics Basics · Lesson 1 of 5

What the machine remembers

Understand what forensics can establish.

Digital forensics is the work of finding out what happened on a system, from what it recorded, in a way that holds up when questioned.

Computers record a great deal that people do not realise. When a file was created, modified and last accessed. Which programs ran and when. Which devices were attached. Which sites were visited. Which accounts signed in from where. Deleted files that remain on the disk until the space is reused. And in memory, what was running at the moment it was captured.

Where this is used. After a security incident, to establish how somebody got in and what they reached. In employment disputes, over data theft or misuse. In fraud investigations. In litigation, where digital evidence is produced. And internally, to answer what actually happened before deciding what to do about it.

The central discipline is preserving rather than examining. The instinct on finding a compromised machine is to look at it, and looking changes it: opening a file updates its access time, running a program writes to the disk, and shutting it down destroys everything in memory.

So the first rule is to stop and preserve before investigating, which is the opposite of the instinct and is the single thing that separates an investigation that establishes something from one that destroys the evidence and then guesses.

And be honest about when to call somebody. Anything that may end in a court, a dismissal or a regulatory report should involve a qualified examiner early, because evidence handled badly cannot be repaired afterwards.

Lab — try it yourself

Write down what your first three actions would be on finding a compromised machine. If the first is "look at it", revise the list.

Check what you learned

Create your free BvLogic ID to take the quiz and record your score.

Create your BvLogic ID
Continue to lesson 2 Up next 2. Preserving evidence