Professional Documents
Culture Documents
Todays (Digital) Forensic
Todays (Digital) Forensic
Todays (Digital) Forensic
A process to validate
3. Preservation 4. Analysis the Chain of Custody
in court examination
Steps for Digital Forensic First Responder 11
Identificatio
Admission
• Verify Legal Authority n • Hash Verification
• Search and Seizure • Bit Stream Imaging
Warrant • Location • Authentication • Interpretation
• Photographic • Date, Time • Chain of Custody • Retain Integrity
Documentation • Witnesses • (Audit Trail) • Filter Irrelevant Data
• Secure Collection • System Info • Analysis • Reconstruction
• Physical Evidence • Objective Unbiased
• Preservation • Present and Defend
Preparation Examination
Standardize Model Process 16
1. 2. 3. 4.
Identification Examination Analysis Admission
Target: Media Target: Data Result: Information Product: Evidence
• Well known and recognized Forensic Application Tools, tested and standardized by the
respected accreditation body and were approved in the field and widely accepted by
Digital Forensic practitioners, experts, and academia worldwide
• NIST Computer Forensic Tools Testing (CFTT) Labs. and Catalog
• Accredited Testing Labs. https://www.cftt.nist.gov/
• Tools Catalog https://toolcatalog.nist.gov/taxonomy/
• Free Tools https://forensiccontrol.com/resources/free-software/
• Anti DF https://en.wikipedia.org/wiki/Anti-computer_forensics
• Free Live General Forensic https://www.caine-live.net/
• Windows https://www.caine-live.net/page2/page2.html
• WIKI https://en.wikipedia.org/wiki/List_of_digital_forensics_tools
Branch of Digital Forensic 18
• Email Address
Author: pataka@csirt.id
General inquiry: info@csirt.id
Incident report: incident@csirt.id
• Postal Address