Duplication and Preservation of Digital Evidence
Project Name: Duplication and Preservation of Digital Evidence
Description: This blog will help all forensics investigator for Duplication and Preservation of Digital Evidence
Author: Rohit D Sadgune
Frequently Asked Question on Computer Forensics Investigation
- Checklist of Duplication and Preservation of Digital Evidence
- Shut down the computer.
- Document the hardware configuration of the system.
- Transport the computer system to a secure location.
- Make bit-stream backups of hard disks and floppy disks.
- Mathematically authenticate data on all storage devices.
- Document the system date and time.
- Make a list of key search words.
- Evaluate the Windows swap file.
- Evaluate file slack.
- Evaluate unallocated space (erased files).
- Search files, file slack, and unallocated space for keywords.
- Document file names, dates, and times.
- Identify file, program, and storage anomalies.
- Evaluate program functionality.
- Document your findings.
- Retain copies of software used.
- Establish a solid relationship with local law enforcement, as they will be a valuable resource in the evidence collection process.