Part 3 - The Preservation Phase of Investigation

Video Activity

This lesson covers the preservation phase of investigation. This must take place quickly to make sure evidence of preserved accurately. Investigators must take careful and accurate notes and record information such as times and actions taken and be sure to initial and sign off on everything.

Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

7 hours 56 minutes
Video Description

This lesson covers the preservation phase of investigation. This must take place quickly to make sure evidence of preserved accurately. Investigators must take careful and accurate notes and record information such as times and actions taken and be sure to initial and sign off on everything.

Video Transcription
so moving on from the preparation phase, we go into the preservation phase.
So the first part of the preservation phases that when encountering system
investigators must perform a rapid assessment of activity to ensure the preservation of any evidence. So what that means is being able to look at the system and being able to determine
if something is happening on that machine that essentially going to change state and damage any type of evidence that's going to occur and not just on the system, but maybe in the room where you find the system. So having that situation, awareness of not just
machine, but your entire surroundings,
eyes going to age you and being able to preserve all of that evidence. So one of the first things that the investigators going to want to do is part of that preservation process is to take notes,
and the note taking essentially relates what happened during the investigation.
A note. You're going to be very important, especially when you
where if you have to get court often times, a defense attorney will not necessarily attack the evidence per se, but they're going to attack the investigator, which would be you
and any little thing that they could find that you did wrong during your investigation, they're going to try and pick that apart and destroy your case. That's why it is right importance that you record in detail every action that you take
from the time that you become aware of the incident
time you complete your your essential investigation on your notes.
So here are some key note taking, um
point. So the first thing that you're gonna want to do is write in pink. Obviously, writing in pencil would subject your notes to change. Writing an ink essentially makes them permanent.
And then you're going to want to put your name and organization on the first line or the top of the page,
the location of where the incident occurred, to the smallest detail. So not just the address of 123 Main Street. But if you have a suite number, office number, desk number down to that very small granular detail,
you'll want to list any individuals who are present at the time of you. Acquiring that data are responding to the inside
on more enforcement investigations. They generally have a crime scene, tape up
and anyone who comes in and out of the crime scene. Their name must be written down on that on that log.
So on from that we have the initial each page
and putting a number on each page.
And then we want to cross out any mistakes that we make on her notes and, well, initial above them.
We must include any diagrams. Photographs that we make in our notes are referenced them and make them available.
At the end of the notes, we would include the statement. Nothing follows,
and then we detail any and all actions that we take. Something simple is arriving on the scene and securing the scene that should appear in your notes
and then very granular details about the operating system to include any information that we we return from the OS from any commands that we enter.
If we find any media laying around percent, we find a thumb drive, which we're gonna get into later. In the hands on portion, we have to write the granular detail. I found a gray Sandis cruiser 2.0 gigabyte thumb drive with serial number 1234
on the back,
and then lastly, we're gonna want to include a known good local time and and and take the source of where we obtain that
that known good local time will help us normalize all the times that we find throughout our investigation to that one time
so often. Systems may not be septic the appropriate time. You have a
suspect who's particularly savvy. They made crying and
finagle the settings the clock in order to help office Kate. Some of their activities said, including a known good local time on imitating that on your notes is a key importance.
So here's an example of the notes.
And as you can see,
uh, the top of the page, I have the
the title of investigator notes. We have our case. 1234
Um, if you are working particularly in an incident response office, you may have an incident response number. So that case member may replace that incident Response number three investigators names. But my name there,
your organization that you're doing this forensic investigation for and then, uh, the section headings dating time. The actions that were taken in the results
so essentially a week
respond to the incident on first of August 2016
we arrived at the scene of 123 Main Street. Any town Maryland. 12345 zip code.
And then from there we obtained a known good local time. You know you can use on Internet restore, such as time and date dot com. You can also use your cell phone
just as long as you annotate where that time came from.
And then the next thing that we see in her notes is that we
secured the scene and then any individuals that were present, we can attach a roster. Who was there?
Hopefully this third step you've already completed before you got to the incident scene. But in case you did not use any, you can wipe the media and then annotate that in your notes on, We'll show you how to white media using the in case
imager and the hands on section
and then down at the bottom, you can see the title of nothing follows,
followed by an investigator, Signature and Paige,
one of one.
So in conjunction with notes, photography will help build credence to your investigation and help keep track of what was done during your investigation,
and it is often the best way to record information of the scene. You can sit and write a lot
on. Essentially, write the novel War in Peace or I can take a photograph of it and write some cursory notes of what happened. I'm not in favor of writing warm piece. I would just rather take a photograph
of the scene and record that in my notes section.
Considerations, though, when using photography is that a flash can cause reflection onto the screen, which can distort your image and make it not usable.
Also, string refresh rates can obscure your photography,
so you're gonna want to use a slow shutter speed, usually about 1/60 of a second. That's about the refresh rate of most screens in the United States. I think overseas use a 1/50 of a second refresh rate.
However, the slower the shutter speed you can use, the better it's going to be.
However, if you get a lot slower than 1/60 because the shutter speed
eyes so slow, it's going to require a lot of balance and steadiness and your hands, and you're probably not going to be able to do that without the use of a tripod,
eso, once 1 60 of a second, is generally the recommended speed, especially for hand photography.
That being said, it's very important to know your equipment.
The time to figure out how your camera works is before you respond to the incident, not during. So if you get one of these very expensive DSLR cameras,
figure out how it works before you get there.
And then the old mantra to is one and one. It's none, even if you have this very nice, expensive,
uh, DSLR camera. If it's the only one you have, it's gonna break when you need it most. So having something as a backup, even an iPhone eyes better than nothing,
and they never all with photographs, because any evidence that you take, especially if you're gonna go to court,
it needs to be admissible, and you have to qualify that evidence. Altering the evidence after you take a picture essentially makes those photographs unusable in court process. And then after you take the photographs, you're gonna want hash stood of graphs,
and then we go into some detail on the hands on portion of how to use MD five cash.
We're going to hash a memory file that we
are going to create
from volatile memory from a system. The same process of running empty five hash on evolved memory file is applicable to any type of flower in ash. One file. You could hash,
but we'll show you how to to do the MD five passions.
Up Next