Collect a forensic disk image before analysis
Practice the sequence you already learned for “Collect a forensic disk image before analysis” until the order feels automatic. Practice NIST 800-86 from digital-forensics training. The suspect volume is not mounted read-write. Hash the source, image it, and hash the image as separate actions. Analysis is not done on the original.
- Photograph the scene and record how the system was found.
- Decide live vs. pull-the-plug per the playbook and legal hold.
- Start the chain-of-custody log.
- Attach a write blocker before any imaging of media.
- Hash the source media.
- Image the media.
- Hash the image and verify it matches the source.
- Analyze only a working copy.
- Log every handler on the chain-of-custody form.