- Trying to preserver the state of crime scene.
- Actions / methods are depending on
- Legal requirements
- Business requirements
- Operational requirements
- Ex. Easy case that may require seize the machine and clone the disk. Also there are some complicated cases like spyware etc.
- Few cases will not go to court (business , military )
- In preservation phase investigator tries to avoid overwriting the evidence.
Preservation Techniques
- Basic aim to to reduce tempering / overwriting.
- For dead analysis i)turn off the machine ii) start making copies
- For live analysis i) kill harmful processes ii) kill network if required iii)logging timestamps etc.
- #values for integrity