Understanding the boot process
To control the environment as we start our investigation, we must understand the environment. Here, digital evidence is being stored, created, and accessed. In most cases, this will be a computer system. I use the term “computer system,” which comprises the operating system, the filesystem, and the hardware bundled together to create a computer. To be effective, you must understand the physical media the data is stored on, the filesystem used on the storage device, and how that data is tracked and accessed while on the storage device.
Once you understand the process, you can then implement controls to protect the integrity of the digital evidence.
So, what is the boot process? When you push the power button and electricity energizes the system, commands are issued. As it executes the commands, the system is taking steps (like on a ladder) to achieve the goal of a running operating system. If something breaks any of those steps...