First Responders Guide to Computer Forensics

Abstract

This handbook is for technical staff members charged with administering and securing information systems and networks. It targets a critical training gap in the fields of information security, computer forensics, and incident response: performing basic forensic data collection. The first module describes cyber laws and their impact on incident response. The second module builds understanding of file systems and outlines a best practice methodology for creating a trusted first responder tool kit for investigating potential incidents. The third module reviews some best practices,techniques, and tools for collecting volatile data from live Windows and Linux systems. It also explains the importance of collecting volatile data before it is lost or changed. The fourth module reviews techniques for capturing persistent data in a forensically sound manner and describes the location of common persistent data types. Each module ends with a summary and a set of review questions to help clarify understanding. This handbook was developed as part of a larger project. The incorporated slides are from the five day hands on course Forensics Guide to Incident Response for Technical Staff developed at the SEI. The focus is on providing system and network administrators with methodologies, tools, and procedures for applying fundamental computer forensics when collecting data on both a live and a powered off machine. A live machine is a machine that is currently running and could be connected to the network. The target audience includes system and network administrators, law enforcement, and any information security practitioners who may find themselves in the role of first responder.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2005
Accession Number
ADA443483

Entities

People

  • Cal Waits
  • Colin O'sullivan
  • Jake Branson
  • Richard Nolan

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies

DTIC Thesaurus Topics

  • Application Software
  • Computational Forensics
  • Computer Crime
  • Computer Network Security
  • Computer Networks
  • Computer Program Reliability
  • Computer Programming
  • Computer Programs
  • Computers
  • Cybersecurity
  • First Responders
  • Information Security
  • Information Systems
  • Malware
  • Network Protocols
  • Operating Systems
  • Web Browsers

Readers

  • Business Analytics
  • Enterprise Information Systems Architecture and Joint Command Capability Interoperability Support.
  • Software Engineering.

Technology Areas

  • Cyber