Evidence Collection and Handling
Proper evidence collection and handling preserves the integrity, reliability, and admissibility of information during investigations and legal processes.
5 slides · 4 min read · Domain 7
In the physical and digital world, all materials associated with a crime or incident could be pertinent to an investigation and used as evidence.
This includes but is not limited to the following:
- Monitoring data about the incident (e.g., logs from systems used to investigate or detect the compromise)
- Data potentially compromised during the incident (e.g., files, records, or user information accessed by attackers)
- Systems that may have been compromised, including hardware, software, and storage media
- Statements or observations from individuals with knowledge of the incident
- Other relevant details about the incident scene
As part of the initial response to an incident, the investigator must inventory all artifacts present at the incident scene or location.
In this context, an artifact refers to items found at the incident location, which differs from other uses of the term, such as in audits or assessments, where artifacts may include outputs like test results, screenshots, or interview records.
Artifacts can be physical objects, such as laptops, mobile phones, thumb drives, or communications devices and systems elements. Paper or printed documents, even the furniture or other equipment within the incident scene, need to be identified, inventoried, and evaluated as possible evidence. Some artifacts have no bearing on the incident, so they should not be inventoried or controlled. Others need to be examined further at the scene to make this determination. The rules of evidence and judicial procedure for the jurisdiction in which the incident has occurred will have a bearing on the details of these processes.
Digital investigations can be challenging. Cyber incident scenes may involve multiple geophysical locations and jurisdictions, including not only the site where the compromised systems and data reside, but the location of the intruder (if unauthorized intrusion access occurred), and any
intermediate locations where resources were used to aid the intrusion. This reality complicates both investigative efforts and the ability to bring the offenders to justice.
All sources and forms of evidence must be carefully collected, tracked, and preserved. The following are common evidence-handling practices that security professionals should be familiar with:
- Appoint an evidence custodian. | The first step in a digital forensics investigation is to appoint the evidence custodian, who is responsible for maintaining the chain of custody and overseeing the disposition of all relevant evidence until the matter is resolved.
- Maintain a chain of custody. Evidence needs to be handled and maintained securely, from the time it is collected until it is presented (usually to a court). The chain of custody entails maintaining a record of where and when the evidence was collected, its form (e.g., physical, data), where and how it is stored from the time of collection through presentation, and who always had access to it during that interval. It is imperative that the chain of custody be strictly maintained because any violation of the chain of custody introduces doubt into the sanctity of evidence that can render the evidence inadmissible.
- Use backups. All backups should be made at the bit level and without changing the data/state of the original whenever possible.
- Make copies of all original evidence. Future analysis should be performed one copies, not original systems/data, whenever possible. Again, this is for the sake of maintaining evidence integrity.
One concept fundamental to criminal investigations is the chain of evidence, the step-bystep description or time line of the location, movement, and activities involving a person or a piece of evidence as part of an incident.
For example, the chain of evidence for a weapon allegedly used in an assault would describe where the weapon was before the incident began. It would show how that weapon moved from place to place, until its arrival at the scene and use in the assault. Next, it would describe the last actions of anyone handling that weapon until it entered the evidence custodian's control.
The chain of custody would describe a different process— when the weapon was first taken up as a piece of evidence by a law enforcement officer, placed into evidence storage, and so on.
A ransomware attack investigation might construct a chain of evidence for the malware itself, showing where, when, and how it was introduced into the target system's infrastructure; how it moved through that system; and what happened to it or because of it at each place it touched. Since a malware weapon can spread rapidly and extensively through a poorly secured infrastructure, this chain of evidence could be the record of the overall investigation itself.
