Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Like any other forensic task, recovering and analyzing digital evidence from network sources must be done in such a way that the results are both reproducible and accurate. In order to ensure a useful outcome, forensic investigators should perform our activities within a methodological framework. The overall step-by-step process recommended in this book is as follows:
• Obtain information
• Strategize
• Collect evidence
• Analyze
• Report
We refer to this methodology as “OSCAR,” and walk through each of these steps in the following section.
Whether you’re law enforcement, internal security staff, or a forensic consultant, you will always need to do two things at the beginning of an investigation: obtain information about the incident itself, and obtain information about the environment.