This lesson covers how to capture the data in order to preserve evidence. Investigators need to be able to capture on screen data such as open files, task bar, open windows, system tray as well as gadgets and sidebars, system time and date. Collecting information following an incident needs to be thought of as a triage: know what information is being sought, what are the requirements and what will answer them and what techniques are needed to obtain the information? After the triage process, the data is imaged.

Incident Response & Advanced Forensics