Not every incident may dictate the need to obtain an image from a potentially compromised hard drive or other volume. Regardless, incident response analysts should be familiar with and able to perform this function when called upon. The evidence found on a hard drive may be critical to determine a sequence of events or to obtain actual files that can aid in determining the root cause. Finally, as with any process in a forensic discipline, imaging should be conducted in a systematic manner in which all steps are followed and properly documented. This will ensure that any evidence obtained will be sound and admissible in a courtroom. The next chapter will discuss examining network based evidence to what network activity is associated ...

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.