Collect a forensic disk image before analysis

Practice the sequence you already learned for “Collect a forensic disk image before analysis” until the order feels automatic. Practice NIST 800-86 from digital-forensics training. The suspect volume is not mounted read-write. Hash the source, image it, and hash the image as separate actions. Analysis is not done on the original.

  1. Photograph the scene and record how the system was found.
  2. Decide live vs. pull-the-plug per the playbook and legal hold.
  3. Start the chain-of-custody log.
  4. Attach a write blocker before any imaging of media.
  5. Hash the source media.
  6. Image the media.
  7. Hash the image and verify it matches the source.
  8. Analyze only a working copy.
  9. Log every handler on the chain-of-custody form.