Acquisition of Evidence
Digital evidence is one of the most volatile pieces of evidence an investigator can handle, and the slightest error or mishandling on the investigator’s part can severely affect the investigation. For example, you may lose the data forever or lose pieces of it. In addition, the unintentional manipulation of data can cast doubt on your ability to investigate or question the integrity of the data in the investigation. This chapter will address minimizing or eliminating any of these issues by using a tool validation process to create an error-free and validated forensic image.
We will cover the following topics in this chapter:
- Exploring evidence
- Understanding the forensic examination environment
- Tool validation
- Creating sterile media
- Defining forensic imaging