Once a proper repository is configured for the image file, the incident response analyst is ready to perform the sequence to acquire the necessary evidence. In this chapter, three separate sequences are discussed. Two will be powered-off systems and one will examine the sequence for capturing a live image. The analyst should select the appropriate technique based upon the incident investigation. In any incident, no matter what technique is utilized, the incident response analyst should be prepared to properly document their actions for any subsequent forensic report.

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.