Summary
In this chapter, we have discussed the forensic analysis process. You now know how to prepare to conduct a digital forensic examination, from getting the proper equipment to training and getting certification. You now understand the importance of obtaining information before seizing digital evidence and ensuring you talk to other investigators or personnel involved in the situation.
I cannot stress the importance of collecting volatile data enough; if you do not do so, you will lose a large amount of potential evidence. We discussed some strategies to conduct your examination and the differences between an OS artifact and a filesystem artifact. Lastly, we discussed reporting your findings so that they are easily understood by the reader.
In the next chapter, we will go into the specifics of the acquisition of evidence and how to validate your tools to create an error-free forensic image.