Summary
Not every incident may dictate the need to obtain an image from a potentially compromised hard drive or other volume. Regardless, incident response analysts should be familiar with and able to perform this function when called upon. The evidence found on a hard drive may be critical to determine a sequence of events or to obtain actual files that can aid in determining the root cause. Finally, as with any process in a forensic discipline, imaging should be conducted in a systematic manner in which all steps are followed and properly documented. This will ensure that any evidence obtained will be sound and admissible in a courtroom. The next chapter will discuss examining network based evidence to what network activity is associated ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access