1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:03,600
we will cover digital forensic procedures.

3
00:00:03,600 --> 00:00:06,630
Digital forensics is a systematic process of investigating

4
00:00:06,630 --> 00:00:09,120
and analyzing digital devices and data

5
00:00:09,120 --> 00:00:11,160
to uncover evidence for legal purposes,

6
00:00:11,160 --> 00:00:13,260
often in the context of criminal investigations

7
00:00:13,260 --> 00:00:14,790
or legal disputes.

8
00:00:14,790 --> 00:00:16,980
Whenever you are performing digital forensics,

9
00:00:16,980 --> 00:00:18,240
you must always adhere

10
00:00:18,240 --> 00:00:20,670
to your organization's well-defined written procedures

11
00:00:20,670 --> 00:00:22,350
to ensure that you are properly handling

12
00:00:22,350 --> 00:00:24,300
your forensics correctly, efficiently,

13
00:00:24,300 --> 00:00:27,360
and in accordance with the required regulation.

14
00:00:27,360 --> 00:00:28,740
This approach helps to ensure

15
00:00:28,740 --> 00:00:30,570
that you are always utilizing consistent

16
00:00:30,570 --> 00:00:32,070
and established protocols.

17
00:00:32,070 --> 00:00:33,420
Digital forensic procedures

18
00:00:33,420 --> 00:00:36,360
are broken down and categorized into four main phases,

19
00:00:36,360 --> 00:00:39,600
identification, collection, analysis, and reporting.

20
00:00:39,600 --> 00:00:41,280
First, we have identification.

21
00:00:41,280 --> 00:00:42,510
The identification step

22
00:00:42,510 --> 00:00:44,880
focuses on ensuring the safety of the scene,

23
00:00:44,880 --> 00:00:47,550
securing it to prevent any evidence contamination,

24
00:00:47,550 --> 00:00:50,760
and determining the scope of the evidence to be collected.

25
00:00:50,760 --> 00:00:52,530
Let's pretend you're working with law enforcement

26
00:00:52,530 --> 00:00:55,980
as a digital forensic examiner or data collection expert.

27
00:00:55,980 --> 00:00:58,740
You receive a call to enter a home to respond to a crime,

28
00:00:58,740 --> 00:01:00,510
but you know that this house

29
00:01:00,510 --> 00:01:02,250
may be a potentially dangerous environment

30
00:01:02,250 --> 00:01:05,099
since the threat actor may still be inside the building.

31
00:01:05,099 --> 00:01:06,660
So now your initial priority

32
00:01:06,660 --> 00:01:09,210
is to first secure the scene to ensure your safety

33
00:01:09,210 --> 00:01:11,940
and the safety of others with the help of the police.

34
00:01:11,940 --> 00:01:14,490
And then once the scene is properly secured,

35
00:01:14,490 --> 00:01:17,190
you can proceed to work to preserve the evidence

36
00:01:17,190 --> 00:01:19,350
from any kind of contamination,

37
00:01:19,350 --> 00:01:20,820
and then you can take videos

38
00:01:20,820 --> 00:01:22,470
or photographs of the crime scene

39
00:01:22,470 --> 00:01:24,210
to document where everything was

40
00:01:24,210 --> 00:01:26,340
when you arrived on the scene.

41
00:01:26,340 --> 00:01:27,600
At the same time,

42
00:01:27,600 --> 00:01:30,510
also need to begin to identify the scope of the evidence

43
00:01:30,510 --> 00:01:31,890
that you will need to collect

44
00:01:31,890 --> 00:01:33,660
by gaining a good understanding

45
00:01:33,660 --> 00:01:36,180
of where the relevant data might be stored,

46
00:01:36,180 --> 00:01:40,320
such as on a tablet, smartphone, smart TV, or a server

47
00:01:40,320 --> 00:01:43,890
based on the nature of the data specified in the warrant.

48
00:01:43,890 --> 00:01:45,930
Second, we have the collection phase.

49
00:01:45,930 --> 00:01:47,190
Once we have identified

50
00:01:47,190 --> 00:01:48,900
what information needs to be collected,

51
00:01:48,900 --> 00:01:50,850
we can begin our collection phase.

52
00:01:50,850 --> 00:01:51,930
When it comes to collection,

53
00:01:51,930 --> 00:01:54,870
it is imperative that you have the proper authorization

54
00:01:54,870 --> 00:01:57,540
before you begin collecting any potential evidence.

55
00:01:57,540 --> 00:01:59,280
If you are working with law enforcement,

56
00:01:59,280 --> 00:02:01,950
this authorization will come in the form of a warrant

57
00:02:01,950 --> 00:02:03,210
signed by a judge.

58
00:02:03,210 --> 00:02:06,030
But if you're working in a large enterprise environment

59
00:02:06,030 --> 00:02:08,009
while conducting an internal investigation,

60
00:02:08,009 --> 00:02:12,630
you may need authorization from the CIO, CSO, CEO,

61
00:02:12,630 --> 00:02:14,730
or other high-level executive

62
00:02:14,730 --> 00:02:17,340
before attempting any evidence collection.

63
00:02:17,340 --> 00:02:20,400
When it comes to evidence collection, you need to ensure

64
00:02:20,400 --> 00:02:22,800
you follow the proper acquisition procedures

65
00:02:22,800 --> 00:02:23,760
for your organization,

66
00:02:23,760 --> 00:02:26,070
including following the order of volatility

67
00:02:26,070 --> 00:02:28,050
and preserving the chain of custody.

68
00:02:28,050 --> 00:02:30,270
Order of volatility is a systematic approach

69
00:02:30,270 --> 00:02:31,410
in digital forensics

70
00:02:31,410 --> 00:02:33,780
that dictates the sequence in which data sources

71
00:02:33,780 --> 00:02:35,550
should be collected and preserved

72
00:02:35,550 --> 00:02:38,940
based on their susceptibility to modification or loss.

73
00:02:38,940 --> 00:02:41,400
General principles is to start with your collection efforts

74
00:02:41,400 --> 00:02:43,410
with the most volatile resources

75
00:02:43,410 --> 00:02:45,570
and work towards the least volatile resources

76
00:02:45,570 --> 00:02:47,160
in order to minimize data loss

77
00:02:47,160 --> 00:02:50,160
and maintain evidentiary integrity.

78
00:02:50,160 --> 00:02:52,470
Now, the typical order of volatility

79
00:02:52,470 --> 00:02:53,910
involves five main steps

80
00:02:53,910 --> 00:02:57,690
according to the NIST Special Publication 800-86.

81
00:02:57,690 --> 00:03:00,330
First, you must collect data from the system's memory,

82
00:03:00,330 --> 00:03:03,330
including the processor's cache and system's RAM.

83
00:03:03,330 --> 00:03:06,000
Second, we need to capture data from the system state,

84
00:03:06,000 --> 00:03:08,700
such as the system and network configurations,

85
00:03:08,700 --> 00:03:12,000
active user sessions, and any data that can be attained

86
00:03:12,000 --> 00:03:14,850
without altering the state of the system.

87
00:03:14,850 --> 00:03:17,700
Third, we need to collect data from your storage devices,

88
00:03:17,700 --> 00:03:19,920
such as hard drives, solid-state devices,

89
00:03:19,920 --> 00:03:22,263
and other non-volatile data storages.

90
00:03:23,220 --> 00:03:26,100
Fourth, we need to capture network traffic and logs,

91
00:03:26,100 --> 00:03:27,720
including data that can help us

92
00:03:27,720 --> 00:03:29,760
reconstruct any network-related activities

93
00:03:29,760 --> 00:03:31,680
or network events.

94
00:03:31,680 --> 00:03:35,220
Fifth, we need to collect remotely stored archive data,

95
00:03:35,220 --> 00:03:37,140
including backups, cloud storage,

96
00:03:37,140 --> 00:03:39,420
external devices, and printouts.

97
00:03:39,420 --> 00:03:41,400
As you can see, our whole goal here

98
00:03:41,400 --> 00:03:44,730
is to collect the things that change fastest first

99
00:03:44,730 --> 00:03:46,380
and then move into the more static

100
00:03:46,380 --> 00:03:50,460
or less frequently changed items like your offsite backups.

101
00:03:50,460 --> 00:03:52,410
When data's collected and acquired,

102
00:03:52,410 --> 00:03:55,170
you must ensure that the chain of custody is maintained.

103
00:03:55,170 --> 00:03:58,560
The chain of custody is a documented and verifiable record

104
00:03:58,560 --> 00:04:00,540
that tracks the handling, transfer,

105
00:04:00,540 --> 00:04:02,400
and preservation of digital evidence

106
00:04:02,400 --> 00:04:03,660
from the moment that it's collected

107
00:04:03,660 --> 00:04:06,090
until it is presented in a court of law.

108
00:04:06,090 --> 00:04:09,060
Now, maintaining a secure and unbroken chain of custody

109
00:04:09,060 --> 00:04:11,190
is essential to demonstrate the integrity

110
00:04:11,190 --> 00:04:13,410
and admissibility of evidence.

111
00:04:13,410 --> 00:04:15,150
Any time someone handles the evidence,

112
00:04:15,150 --> 00:04:17,880
from their initial collector to a forensic analysis,

113
00:04:17,880 --> 00:04:19,980
investigator, or other legal professional,

114
00:04:19,980 --> 00:04:21,690
they must carefully document their actions

115
00:04:21,690 --> 00:04:24,540
and any changes in the evidence custody status.

116
00:04:24,540 --> 00:04:25,980
This meticulous record-keeping

117
00:04:25,980 --> 00:04:28,590
ensures that the evidence remains untainted

118
00:04:28,590 --> 00:04:31,530
and can withstand scrutiny during legal proceedings

119
00:04:31,530 --> 00:04:33,180
that will ultimately contribute

120
00:04:33,180 --> 00:04:34,980
to a credible and robust case

121
00:04:34,980 --> 00:04:36,690
against a threat actor being charged

122
00:04:36,690 --> 00:04:38,430
with some type of cyber crime.

123
00:04:38,430 --> 00:04:39,990
When you collect your evidence,

124
00:04:39,990 --> 00:04:41,670
it should be collected using processes

125
00:04:41,670 --> 00:04:44,220
like disk imaging and file carving.

126
00:04:44,220 --> 00:04:47,070
Disk imaging involves creating a bit-by-bit

127
00:04:47,070 --> 00:04:49,410
or logical copy of a storage device,

128
00:04:49,410 --> 00:04:51,030
preserving its entire content,

129
00:04:51,030 --> 00:04:54,180
including deleted files and unallocated space.

130
00:04:54,180 --> 00:04:55,350
Disk imaging ensures

131
00:04:55,350 --> 00:04:57,240
that the original data remains untouched

132
00:04:57,240 --> 00:04:58,650
and allows forensic analysts

133
00:04:58,650 --> 00:05:02,130
to work with an exact duplicate of the device

134
00:05:02,130 --> 00:05:02,963
for the analysis.

135
00:05:02,963 --> 00:05:04,590
File carving, on the other hand,

136
00:05:04,590 --> 00:05:07,380
focuses on extracting files and data fragments

137
00:05:07,380 --> 00:05:10,260
from storage media without relying on the file system.

138
00:05:10,260 --> 00:05:12,330
File carving is particularly useful

139
00:05:12,330 --> 00:05:15,360
when file metadata is missing or corrupted.

140
00:05:15,360 --> 00:05:17,640
Both techniques can serve as a critical role

141
00:05:17,640 --> 00:05:21,090
in preserving evidence and providing forensic experts

142
00:05:21,090 --> 00:05:24,120
the data they need to conduct a thorough investigation

143
00:05:24,120 --> 00:05:26,070
while maintaining the original integrity

144
00:05:26,070 --> 00:05:27,540
of the evidence source.

145
00:05:27,540 --> 00:05:30,270
The third phase is the analysis phase.

146
00:05:30,270 --> 00:05:31,530
Once we have confirmed,

147
00:05:31,530 --> 00:05:34,620
forensically sound copy of the evidence available,

148
00:05:34,620 --> 00:05:35,910
our forensic analysts

149
00:05:35,910 --> 00:05:38,250
can employ repeatable methods and tools

150
00:05:38,250 --> 00:05:40,170
for the examination of the evidence.

151
00:05:40,170 --> 00:05:41,250
This rigorous process

152
00:05:41,250 --> 00:05:43,680
involves systematically scrutinizing the data

153
00:05:43,680 --> 00:05:45,540
to uncover relevant information,

154
00:05:45,540 --> 00:05:47,700
such as potential signs of criminal activity,

155
00:05:47,700 --> 00:05:51,090
hidden files, timestamps, and user interactions.

156
00:05:51,090 --> 00:05:54,210
Analysts follow strict procedures and documented protocols

157
00:05:54,210 --> 00:05:58,110
to ensure consistency and objectivity in their findings.

158
00:05:58,110 --> 00:06:00,270
By adhering to these established practices,

159
00:06:00,270 --> 00:06:01,710
digital forensic experts

160
00:06:01,710 --> 00:06:04,530
can derive valuable insights from the evidence

161
00:06:04,530 --> 00:06:07,830
to help unravel complex cases and provide crucial support

162
00:06:07,830 --> 00:06:10,110
for any potential legal proceedings.

163
00:06:10,110 --> 00:06:12,300
The fourth and final step of the process

164
00:06:12,300 --> 00:06:13,860
is known as reporting.

165
00:06:13,860 --> 00:06:15,660
Now, after the forensic analyst

166
00:06:15,660 --> 00:06:17,850
completes their analysis of the evidence,

167
00:06:17,850 --> 00:06:19,140
they must present a document

168
00:06:19,140 --> 00:06:21,060
that describes their methods and tools

169
00:06:21,060 --> 00:06:22,890
that they used in their investigation,

170
00:06:22,890 --> 00:06:24,990
any actions that they performed during analysis,

171
00:06:24,990 --> 00:06:26,010
their detailed findings,

172
00:06:26,010 --> 00:06:28,680
and their final conclusions about the investigation

173
00:06:28,680 --> 00:06:30,300
in their final report.

174
00:06:30,300 --> 00:06:32,490
This report serves as crucial evidence

175
00:06:32,490 --> 00:06:34,170
in legal proceedings and trials,

176
00:06:34,170 --> 00:06:36,390
and the forensic analysts must be prepared

177
00:06:36,390 --> 00:06:38,670
to testify in court about their findings.

178
00:06:38,670 --> 00:06:40,710
This is another reason why it's essential

179
00:06:40,710 --> 00:06:42,480
to adhere to strict procedures

180
00:06:42,480 --> 00:06:44,160
when conducting digital forensics,

181
00:06:44,160 --> 00:06:46,290
because you may be asked to defend your work

182
00:06:46,290 --> 00:06:48,870
against potential challenges by a defense attorney.

183
00:06:48,870 --> 00:06:51,150
Now, another important concept to understand

184
00:06:51,150 --> 00:06:51,983
is a legal hold.

185
00:06:51,983 --> 00:06:53,940
When litigation is reasonably expected,

186
00:06:53,940 --> 00:06:57,030
your organization will be forced to implement a legal hold.

187
00:06:57,030 --> 00:06:59,250
A legal hold is a formal notification

188
00:06:59,250 --> 00:07:00,390
that instructs employees

189
00:07:00,390 --> 00:07:03,480
to preserve all potentially relevant electronic data,

190
00:07:03,480 --> 00:07:05,040
documents, and records.

191
00:07:05,040 --> 00:07:07,740
Legal hold ensures that no evidence is tampered with,

192
00:07:07,740 --> 00:07:09,030
deleted, or lost,

193
00:07:09,030 --> 00:07:11,970
as any alteration or destruction of relevant data

194
00:07:11,970 --> 00:07:14,910
can lead to severe legal consequences.

195
00:07:14,910 --> 00:07:17,100
This process essentially freezes the state

196
00:07:17,100 --> 00:07:18,270
of electronic information

197
00:07:18,270 --> 00:07:19,830
to safeguard it for future use

198
00:07:19,830 --> 00:07:22,290
in an upcoming legal proceeding.

199
00:07:22,290 --> 00:07:23,910
When a legal hold is issued,

200
00:07:23,910 --> 00:07:26,250
you must ensure that preservation practices

201
00:07:26,250 --> 00:07:27,900
are used to protect the systems

202
00:07:27,900 --> 00:07:30,510
and potential evidence that they contain.

203
00:07:30,510 --> 00:07:32,880
Preservation involves taking proactive steps

204
00:07:32,880 --> 00:07:35,460
to maintain and protect electronic evidence

205
00:07:35,460 --> 00:07:37,620
in its original state, including ensuring that the data

206
00:07:37,620 --> 00:07:41,340
is not overwritten, deleted, or modified inadvertently.

207
00:07:41,340 --> 00:07:44,400
Preservation measures may include making backup copies

208
00:07:44,400 --> 00:07:47,310
of electronic records, isolating critical systems,

209
00:07:47,310 --> 00:07:49,260
and implementing access controls

210
00:07:49,260 --> 00:07:52,050
to prevent any unauthorized alterations.

211
00:07:52,050 --> 00:07:53,400
The goal of preservation

212
00:07:53,400 --> 00:07:55,890
is to maintain the evidentiary integrity

213
00:07:55,890 --> 00:07:57,420
of the electronic information,

214
00:07:57,420 --> 00:07:59,760
which is essential for building a strong case

215
00:07:59,760 --> 00:08:01,920
or responding to legal requests.

216
00:08:01,920 --> 00:08:04,380
Finally, we have e-discovery.

217
00:08:04,380 --> 00:08:06,630
E-discovery, or electronic discovery,

218
00:08:06,630 --> 00:08:09,000
is the process of identifying, collecting,

219
00:08:09,000 --> 00:08:11,700
and producing electronically stored information

220
00:08:11,700 --> 00:08:14,010
during potential legal proceedings.

221
00:08:14,010 --> 00:08:16,950
E-discovery encompasses searching through fast volumes

222
00:08:16,950 --> 00:08:19,620
of electronic data to locate relevant evidence,

223
00:08:19,620 --> 00:08:21,390
analyzing it, and presenting it

224
00:08:21,390 --> 00:08:23,910
in a format suitable for litigation.

225
00:08:23,910 --> 00:08:26,250
E-discovery tools and techniques are employed

226
00:08:26,250 --> 00:08:28,770
to efficiently sift through emails, documents,

227
00:08:28,770 --> 00:08:31,020
databases, and other digital records.

228
00:08:31,020 --> 00:08:32,520
Effective e-discovery practices

229
00:08:32,520 --> 00:08:34,080
are essential for legal teams

230
00:08:34,080 --> 00:08:35,970
to meet their disclosure obligations

231
00:08:35,970 --> 00:08:38,520
and navigate the complexities of modern litigation,

232
00:08:38,520 --> 00:08:41,789
where electronic data often plays a central role.

233
00:08:41,789 --> 00:08:44,610
Now, if all of this sounds like it has potential

234
00:08:44,610 --> 00:08:47,370
to have issues arise that could cause legal issues

235
00:08:47,370 --> 00:08:50,010
for you or your organization, you are right.

236
00:08:50,010 --> 00:08:51,870
In most cases, your organization

237
00:08:51,870 --> 00:08:53,850
should opt to appoint a liaison

238
00:08:53,850 --> 00:08:55,920
with legal knowledge and expertise

239
00:08:55,920 --> 00:08:58,170
to help facilitate communication and cooperation

240
00:08:58,170 --> 00:09:00,480
with law enforcement and forensic teams

241
00:09:00,480 --> 00:09:03,360
to ensure you stay on the right side of the law.

242
00:09:03,360 --> 00:09:05,790
This liaison can serve as a point of contact

243
00:09:05,790 --> 00:09:08,550
for interactions and ensuring a smoother process.

244
00:09:08,550 --> 00:09:10,800
And often, this person is someone who is a lawyer

245
00:09:10,800 --> 00:09:13,620
or works with your organization's in-house general counsel

246
00:09:13,620 --> 00:09:16,140
to keep your organization on the right side of the law.

247
00:09:16,140 --> 00:09:18,720
Finally, let's quickly talk about ethical considerations

248
00:09:18,720 --> 00:09:19,830
that are important to think about

249
00:09:19,830 --> 00:09:21,990
in the field of digital forensics.

250
00:09:21,990 --> 00:09:24,210
Your organization's forensic analysts

251
00:09:24,210 --> 00:09:26,100
must adhere to a code of ethics

252
00:09:26,100 --> 00:09:28,200
that emphasizes three key principles,

253
00:09:28,200 --> 00:09:30,420
avoiding bias, repeatable actions,

254
00:09:30,420 --> 00:09:32,490
and the preservation of evidence.

255
00:09:32,490 --> 00:09:34,740
All of your analysis must always be performed

256
00:09:34,740 --> 00:09:37,290
without any kind of bias or prejudice.

257
00:09:37,290 --> 00:09:39,510
Any conclusions you draw should be solely based

258
00:09:39,510 --> 00:09:41,550
on the evidence that you're analyzing.

259
00:09:41,550 --> 00:09:43,387
You should never have your own thoughts like,

260
00:09:43,387 --> 00:09:46,230
"Well, I don't like this person because of X, Y, and Z."

261
00:09:46,230 --> 00:09:48,870
Your investigation cannot be based on their color,

262
00:09:48,870 --> 00:09:50,610
their creed, their nationality,

263
00:09:50,610 --> 00:09:53,100
their sexual orientation, their political beliefs,

264
00:09:53,100 --> 00:09:55,410
what they look like, or anything else like that.

265
00:09:55,410 --> 00:09:57,870
It should be based only on the evidence.

266
00:09:57,870 --> 00:10:00,150
Personally, I have found that it is best practice

267
00:10:00,150 --> 00:10:01,620
to use a forensic analyst

268
00:10:01,620 --> 00:10:03,750
who is completely removed from the situation

269
00:10:03,750 --> 00:10:06,120
to avoid any kind of potential bias.

270
00:10:06,120 --> 00:10:08,400
For example, in some places that I worked,

271
00:10:08,400 --> 00:10:09,660
we would have one set of people

272
00:10:09,660 --> 00:10:12,360
who collect information called digital media collectors

273
00:10:12,360 --> 00:10:14,010
and another set that analyzes it

274
00:10:14,010 --> 00:10:16,140
called the digital forensic examiners.

275
00:10:16,140 --> 00:10:18,480
Under this model, the forensic analysts

276
00:10:18,480 --> 00:10:20,070
only have the data to rely on

277
00:10:20,070 --> 00:10:22,380
since they don't know the victim or attacker's name

278
00:10:22,380 --> 00:10:25,110
or anything else about the case up to that point,

279
00:10:25,110 --> 00:10:28,560
and that can help minimize and eliminate some of that bias.

280
00:10:28,560 --> 00:10:32,070
Also, all of your analysis must utilize repeatable processes

281
00:10:32,070 --> 00:10:33,960
that anyone else can perform

282
00:10:33,960 --> 00:10:36,060
and get the exact same results that you did.

283
00:10:36,060 --> 00:10:37,950
This is why documenting all of your actions

284
00:10:37,950 --> 00:10:39,840
in a final report is so important,

285
00:10:39,840 --> 00:10:41,820
because proper documentation of methods

286
00:10:41,820 --> 00:10:45,120
ensures that others can reproduce the same results

287
00:10:45,120 --> 00:10:46,770
using the same techniques.

288
00:10:46,770 --> 00:10:50,610
Now, what I mean is that if I take the exact same evidence

289
00:10:50,610 --> 00:10:51,840
and give it to somebody else,

290
00:10:51,840 --> 00:10:53,610
they should be able to get the same results

291
00:10:53,610 --> 00:10:55,710
if they use the same methods that you did.

292
00:10:55,710 --> 00:10:58,230
For example, when I do my forensic analysis,

293
00:10:58,230 --> 00:11:01,110
I will write down the time, the actions that I took,

294
00:11:01,110 --> 00:11:02,790
and the results of those actions.

295
00:11:02,790 --> 00:11:07,260
For example, on February 2nd, 2024, at 10:23,

296
00:11:07,260 --> 00:11:09,190
I entered the command "netstat -ano"

297
00:11:10,770 --> 00:11:13,500
at the command prompt of the Windows 10 system.

298
00:11:13,500 --> 00:11:15,990
I received a list of active network connections

299
00:11:15,990 --> 00:11:18,060
on that machine, and I noticed a connection

300
00:11:18,060 --> 00:11:20,220
to a potentially malicious server

301
00:11:20,220 --> 00:11:25,220
with an IP address of 66.55.44.33.

302
00:11:25,800 --> 00:11:28,740
In addition to this, I might also include a screenshot

303
00:11:28,740 --> 00:11:30,390
of the netstat results.

304
00:11:30,390 --> 00:11:33,300
This way, anyone who might be asked to double check my work

305
00:11:33,300 --> 00:11:36,150
can see what I did, when I did it,

306
00:11:36,150 --> 00:11:39,480
how I did it, and what results I received.

307
00:11:39,480 --> 00:11:41,400
It is almost critically important

308
00:11:41,400 --> 00:11:43,080
that any evidence you collect

309
00:11:43,080 --> 00:11:44,790
is not changed or manipulated.

310
00:11:44,790 --> 00:11:46,140
When I talk about evidence here,

311
00:11:46,140 --> 00:11:48,240
I am talking about both the device itself,

312
00:11:48,240 --> 00:11:50,220
like a hard disk of a laptop,

313
00:11:50,220 --> 00:11:53,040
and the files or data recovered from that device.

314
00:11:53,040 --> 00:11:56,520
For example, I am starting to perform a forensic analysis

315
00:11:56,520 --> 00:11:57,630
on your laptop.

316
00:11:57,630 --> 00:11:59,550
I should not start running commands on your laptop

317
00:11:59,550 --> 00:12:02,010
since that could change the contents of your swap file

318
00:12:02,010 --> 00:12:04,260
and potentially other files of your hard drive.

319
00:12:04,260 --> 00:12:07,050
So, I should first image that drive,

320
00:12:07,050 --> 00:12:09,870
then conduct my analysis on the disk image of that drive

321
00:12:09,870 --> 00:12:11,310
instead of the original drive

322
00:12:11,310 --> 00:12:14,370
to prevent any modifications or alterations

323
00:12:14,370 --> 00:12:17,430
of any potential evidence located on that hard drive.

324
00:12:17,430 --> 00:12:20,910
So remember, digital forensics is a systematic approach

325
00:12:20,910 --> 00:12:23,940
of investigating and analyzing digital devices and data

326
00:12:23,940 --> 00:12:26,730
to uncover evidence for legal purposes.

327
00:12:26,730 --> 00:12:28,140
Digital forensic procedures

328
00:12:28,140 --> 00:12:31,410
are broken down and categorized in four main phases,

329
00:12:31,410 --> 00:12:35,250
identification, collection, analysis, and reporting.

330
00:12:35,250 --> 00:12:38,220
You should always ensure that you follow a code of ethics

331
00:12:38,220 --> 00:12:40,320
that emphasizes three key principles,

332
00:12:40,320 --> 00:12:42,510
avoiding bias, repeatable actions,

333
00:12:42,510 --> 00:12:44,700
and the preservation of the evidence.

334
00:12:44,700 --> 00:12:46,590
If you begin to have any deviations

335
00:12:46,590 --> 00:12:48,450
from these ethical standards and procedures,

336
00:12:48,450 --> 00:12:49,740
a good defense attorney

337
00:12:49,740 --> 00:12:52,200
will be able to discredit your findings in court,

338
00:12:52,200 --> 00:12:54,060
which could lead to the evidence you collected

339
00:12:54,060 --> 00:12:55,830
being inadmissible in court,

340
00:12:55,830 --> 00:12:57,450
and the threat actor will be able

341
00:12:57,450 --> 00:13:00,030
to get away with their crimes without any prosecution.

342
00:13:00,030 --> 00:13:03,150
So remember, always follow the proper procedures

343
00:13:03,150 --> 00:13:05,040
when collecting and analyzing evidence

344
00:13:05,040 --> 00:13:06,900
so that justice can be upheld

345
00:13:06,900 --> 00:13:09,210
even if your work undergoes rigorous scrutiny

346
00:13:09,210 --> 00:13:10,510
during a legal proceeding.

