EMZETT.
Login

Forensics

In short: IT forensics secures and evaluates digital traces to clarify incidents and prove them in court.

In more detail: Completeness, traceability and an unbroken chain of custody are important.

In Depth

Procedure

  • Secure evidence without changing the original (write protection, disk image).
  • Prove integrity with hash values.
  • Volatile data first (memory, network connections), then disks, logs.
  • Evaluate and document.

Use

Investigating ransomware, data theft, insider cases. See audit log, malware.

See also: Hashing, Audit Log, Reverse Engineering