1. Attend workshops related to Forensics
Task
Follow workshops related to forensics |
T |
0.5day |
Must |
Execution
Security incidents possible for research
APT detected
Defacement of a website
Fraud occuring within an organization
Sudden network issues
A failing/crashing server
Dataleak containing personal data
Endpoint detection of malware
Real world cases
Privacy of correspondance
The privacy of correspondance shall not be violated except in the cases laid down by Act of Parliament, by order of the courts.
The privacy of the telephone and telegraph shall not be violated except, in the cases laid down by Act of Parliament, by or with the authorisation of those designated for the purpose by Act of Parliament.
Technical forensics:
Disk research (Smartphones, PC’s, cloud, usb, etc.).
RFC3227 is the base of the research approach
Minimize modifications data during preservation
Begin preserving most volatile traces
Do not shutdown until all relevant traces have been captured
Do not trust the present system programs
Record actions meticulously
Responsible research:
Chain of Custody
Privacy
Lawyer proof report
Identify: Document type of finding of incident/case
Preserve: Secure data & document
Collect: Image storage devices
Analyze: Examine recovered disk search for potential evidence
Report: Document fact & findings summarize evidence, proper testimony