O'Reilly logo

Investigating the Cyber Breach: The Digital Forensics Guide for the Network Engineer, First Edition by Aamir Lakhani, Joseph Muniz

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Chapter 6

Collecting and Preserving Evidence

“Extraordinary claims require extraordinary evidence.”

—Carl Sagan

One of the most critical steps in a digital forensics investigation is collecting and preserving evidence. Why is this such a big deal? The answer is simple. If you get this step of the forensic process wrong, everything you do is likely ruined when it comes to legal matters. Entering evidence into a court system is about documentation, which means proving without a reasonable doubt that something was found without contamination during the investigation process. Any challenges from the defense that can’t be answered may cause your evidence to be denied as something that can be used for your case. You absolutely must nail proper collection ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required