Summary
In this chapter, we have discussed evidence and how you need to ensure you validate your processes and your forensic tools to make sure you are getting accurate results. You learned about the Forensically Sound Examination Environment and how you have to maintain control of the environment. The environment is not just in the lab but encompasses when you start the Forensic Analysis Process. We have gone over how to validate your forensic tools, create sterile media, and explored the different write blocking options that are available. We have gone through creating a forensic image utilizing forensic tools such as FTK Imager and Paladin and gone into detail about the different formats available for the creation of a forensic image. Now, we can move on and explore how the computer operates and explore different filesystems.
In the next chapter, we will go into the workings of the computer system and the storage devices you may encounter.