Module 02 - Computer Forensics Investigation Process - AG - 25
Module 02 - Computer Forensics Investigation Process - AG - 25
First responder is the first person at the scene of the incident who
collects and preserves evidence.
The first responder should follow all laws while collecting the
evidence, and contact a computer forensic examiner as soon as
possible.
Collect the Evidence
Collect Physical Evidence
Backup Tapes
system-wide backups (monthly/weekly/incremental)
disaster recovery backups (stored off site)
personal or "ad hoc" backups (look for diskettes and other portable media)
To verify image integrity, calculate and match the MD5 hash for
the original evidence and the forensic image. Same hash values
shows that the image is same as the evidence. There are
various tools that can be used to calculate the hash value, such
as HashCalc, MD5 Calculator, HashMyFiles, and Md5sum.