Evidence acquisition
There are a variety of methods that are used to not only access a potential evidence source but also determine the type of acquisition that can be undertaken. To define these methods, it is important to have a clear understanding of the manner and type of acquisition that can be utilized:
- Local: Having access to the system under investigation is often a luxury for most enterprises. Even so, there are many times when incident response analysts or other personnel have direct physical access to the system. A local acquisition can often be performed via a USB or other device and, in some circumstances, using the system itself.
- Remote: In a remote acquisition, incident response analysts leverage tools and network connections to acquire evidence. A remote acquisition is an obvious choice if incident response analysts are dealing with geographical challenges. This can also be useful if incident response analysts cannot be on-site immediately. (The next chapter...