Forensic Analysis Process Flashcards
1
Q
What should be included in a response kit?
A
- digital camera
- latex gloves
- notepads
- property report for seizing evidence
- antistatic bags
- write blocking devices
- frequency shielding material
- toolkit
- misc: power cables, data cables, usb drives
2
Q
Program to use USB devices remotely?
A
- http://virtualhere.com/home
- requires a network connection where the USB keys are plugged in
3
Q
What is the free open source forensic tool system?
A
- Autopsy
- www.sleuthkit.org/autopsy
4
Q
What is the order of volatility, from most to least volatile?
A
- live system
- running
- network
- virtual
- physical
5
Q
Forensic Image
A
- a bit-for-bit copy of the source device, stored in a forensic image format
- DD, E01, or AFF
6
Q
File signature analysis
A
- ensures the file extension matches the file type
7
Q
What website allows you to search File Signatures based on File Extension?
A
- https://filesignatures.net
8
Q
What are the steps in FTK to view/mount a forensic image?
A
- File > Image Mounting
- Mount Image to Drive menu
2a. Mount Type: Physical and Logical
2b. Drive Letter (select any letter)
2c. Mount Method: Block Device/Read Only
9
Q
What to include in Forensic Document?
A
- your narrative
- pertinent exhibits
- supporting documentation