Summary
In this chapter, we have discussed evidence and how you need to validate your processes and your forensic tools to ensure accurate results. You learned about the forensically sound examination environment and how you must maintain control of the environment. The environment is not just in the lab, but encompasses when you start the forensic analysis process. We have gone over how to validate your forensic tools, create sterile media, and explored the different write blocking options that are available. Next, we have gone through the process of creating a forensic image utilizing forensic tools such as FTK Imager and PALADIN and gone into detail about the different formats available to create a forensic image. Now, we can move on and explore how the computer operates and explore different filesystems.
In the next chapter, we will go into the workings of the computer system and the storage devices you may encounter.