Data acquisition best practices and DFIR frameworks
So far, we’ve covered a general overview of the DFIR procedures when collecting and preserving evidence. There are several official documents that I highly recommend you read and become familiar with, as they all give good details and guidelines on the documentation of the scene, evidence collection, and data acquisition.
The SWGDE has several best practice guidelines on forensic acquisition, evidence collection, forensic examination, and more. These very useful documents should be downloaded and kept as part of your DFIR playbook as they are concise and summarize all the necessary steps, which can act as a checklist for DFIR investigations. All documents can be found in the SWGDE’s Forensic Publications section at https://www.swgde.org/documents/published-by-committee/forensics, but for the purposes of this chapter, I recommend, at the very least, downloading and reading the following two best practices guidelines...