Summary
Proper evidence handling starts the overall process that aims to determine the root cause of an incident and potentially identify the responsible party. In order for evidence to be of any use in an incident investigation, it has to be acquired in a sound manner. Incident responders should have a solid foundation in understanding the various types of acquisition, the tools and the techniques available, and apply those tools and techniques to the various situations that may arise. By applying solid techniques and properly documenting their actions, incident responders will be in a position to utilize the evidence to not only determine the root cause of an incident, but also be able to back up their actions in a courtroom if necessary. The next chapter will look at capturing the non-volatile data or that data contained on the disk drive.