Chapter 4

Collecting evidence

Abstract

Cases can be won or lost based on how the digital evidence was collected. Digital evidence is fragile and must be handled with care. We will explore how to properly collect evidence from various devices so that the examiner will get the opportunity to present their hard found evidence outside of the lab.

Keywords

Chain of Custody
Live System
Dead System
Volatile Memory
Order of Volatility
Hash Function
Algorithm
Faraday

“Never neglect the details …”

—Colin Powell

Information in this chapter
Introduction to Crime Scenes
Documenting the Scene and the Evidence
Establishing and Maintaining the Chain of Custody
Forensic Cloning of Evidence
Dealing with Live Systems and Dead Systems
Using Hashing ...

Get The Basics of Digital Forensics, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.