[Company Logo Image]Data Forensics Engineering

Field Guide

 

 

Home DOS Incident Response Imaging Forensics Links Reference Phishing Guidelines

 

 

 

       to

       Computer Forensics

 

Computer forensics is a diverse field and needs many different type of programs and techniques.  This guide will assist you as a reference in having many options at your fingertips to investigate computer crime.

 

Documentation has to be the first consideration in any investigation.  When you arrive at a site to perform a forensic investigation, you may not know what type of equipment or circumstances of what is required.  You have to be prepared to image any kind of media, computer, laptop or server. 

Removing the hard drive may be a challenge and should  be documented with a camera.  Once the hard drive has been removed in the case of a workstation, you have to document the type model, and serial number of the hard drive.  Raid systems will be covered in another section. 

Xerox the hard drive label, record all the information relating to the hard drive.  Serial number, type, model and any other information that might be included on the drive information.  Record all the information about the computer, serial number, part number, model and any inventory tag or asset tag information.  mark all items inventoried with your initials and date entered into evidence. 

 

Send mail to  info@dataforensicsengineering.com with questions or comments about this web site.
Copyright © 2005 Data Forensics Engineering
Last modified: December 11, 2005