Digital Forensics – Evidence Handling guidelines – ACPO Digital Forensic

Digital Forensics – Evidence Handling guidelines – ACPO Digital Forensic Association of Chief Police Officers ACPO Guidelines for Computer Based Evidence Computer based electronic evidence is held to the same rules and expectations that apply to all other evidence before a court. The onus is on the prosecution to prove to a court that the… Continue reading Digital Forensics – Evidence Handling guidelines – ACPO Digital Forensic

Available Artefacts – Evidence of Execution

Available Artefacts – Evidence of Execution https://blog.1234n6.com/2018/10/available-artifacts-evidence-of.html?m=1 This week I have been working a case where I was required to identify users on a Windows Server 2003 system who had knowledge of, or had run, a particular unauthorised executable. As such, I found myself wracking my brain for all the user attributable artifacts which evidence… Continue reading Available Artefacts – Evidence of Execution

Incident Response

Incident Identification Step 1: Prepare your documentation You will need to document all your activities, from meeting minutes and decisions down to commands typed into your systems by your incident response team. For each step, you will need to record, at minimum: Identifying information (location, serial no, model no, hostname, MAC address, IP Address) Name,… Continue reading Incident Response