EnCE · Domain 2
Evidence Acquisition and Imaging
About 14% of the exam
Acquisition types
- Physical
- every sector including unallocated space
- Logical
- files visible to the file system
- Sparse
- selected items for scoped triage
- Live
- running system, state changes underneath
- Remote
- collected across a network link
- Targeted
- named items the authority permits
A narrower acquisition is defensible when the scope is stated, hashed and explained rather than quietly assumed
Write protection
- Hardware blockers refuse write commands physically
- Software blocking depends on the operating system
- Test the blocker before each acquisition
- Record the blocker model and cable type
- Mount images read only for analysis
- Blocking does not prevent read errors
Imaging workflow
- Photograph and record labels
- Check native capacity
- Attach through write protection
- Acquire with verification
- Compare hashes
- Seal and store
- Record make, model and serial number
- Note geometry and total sector count
- Verify while acquiring where supported
- Log unreadable sectors and error counts
Image formats
- Raw
- flat copy, universally readable
- Evidence container
- metadata, compression and integrity checks
- Segmented set
- one image split for portability
- Advanced container
- sparse aware with multiple streams
- Virtual disk
- descriptor plus extent files
- Proprietary risk
- long term access depends on vendor
Hard cases
Arrays
- Stripe and parity mean no disk stands alone
- Image each member where possible
- Record controller settings and order
- Reconstruct and verify before analysis
Solid state
- Trim clears deleted cells early
- Wear leveling scatters old content
- Over provisioned cells sit beyond addressing
- Intact deleted data deserves a second look
Encrypted and mobile
- Acquire while the volume is unlocked
- A locked device narrows the available methods
- Record lock state at the moment of seizure
- Encrypted image still verifies as an image
Document what the acquisition could not reach, because silence reads as an oversight later
Verification discipline
- Compute the source hash before acquisition
- Compute the image hash afterwards
- Compare image size against reported capacity
- Re-verify after transport and storage
- Record both values in the acquisition log
- Treat a mismatch as an investigation
When hashes disagree
- Bad sectors
- unreadable regions substituted during acquisition
- Transient read errors
- bus resets and unstable connections
- Live source
- the disk changed while copying
- Media degradation
- an old mismatch found years later
- Wrong scope
- hidden areas included in one pass
- Actual alteration
- the serious explanation to exclude
Hidden capacity
- Compare native capacity against reported capacity
- Protected areas hide sectors from normal reads
- Configuration overlays shrink the visible device
- Unpartitioned gaps sit between volumes
- Note whether the tool captured these areas
- Record the method used to detect them
Live and remote acquisition
- Capture volatile state before the disk
- Live hashes verify the image, not the source
- Authorization must reach the remote system
- Connecting changes the system you collect from
- Custody covers the data path, not an object
- Record every system the data crossed
With nothing changing hands, the custody record must describe the pull itself and who controlled each hop
Cloud and provider data
Legal route
- Process is directed at the provider
- Ask only for the relevant period
- Preservation requests stop routine deletion
- Cross border storage adds another regime
Technical route
- Use documented export interfaces
- Record parameters and record counts
- Hash the export when it completes
- Capture the platform audit trail too
Limits to state
- No physical seizure or write blocker
- Data may be commingled with other tenants
- Retention may already have removed periods
- Snapshots may reflect a later state
Acquisition log contents
- Examiner, date, time and location
- Device identifiers and reported capacity
- Tool name, version and settings
- Write protection method used
- Hash values before and after
- Errors, retries and equipment problems
- Reason for any re-acquisition
Triage collections
- Fixed checklist keeps coverage consistent
- Collect artifacts that answer the first questions
- Hash each collected item individually
- Note that a triage set is not complete
- Preserve the option of full imaging later
- Record why triage was chosen
Know the order
- Assess the device
- Choose the acquisition type
- Protect against writes
- Acquire and verify
- Log everything
- Seal the original
Acquire the most volatile and most fragile source first, and never rely on a second chance with a failing disk
Key artifacts
- Acquisition hash
- integrity baseline for the image
- Verification hash
- computed from the written image
- Sector count
- ties the image to the device
- Error log
- unreadable sectors and retries
- Blocker record
- which device protected the source
- First custody entry
- who created the image and when
Reference strip: acquisition
Types
- Physical, logical, sparse
- Live and remote
- Targeted within authority
- Cloud through provider interfaces
Protection
- Hardware write blockers
- Software blocking with caution
- Read only mounting
- Tested before every case
Formats
- Raw sector images
- Evidence containers with checks
- Segmented image sets
- Sparse aware containers
Verification
- Hash source and image
- Compare capacity and size
- Re-verify after moves
- Explain every mismatch
Difficult media
- Arrays and controller settings
- Solid state trim behavior
- Encrypted volumes and lock state
- Hidden firmware areas
Quick exam traps
- Trap: A live acquisition hash must match the running disk
- Trap: Trim guarantees deleted data is unrecoverable everywhere
- Trap: The reported capacity always equals the native capacity
- Trap: Imaging the array through the controller is always sufficient
- Trap: A re-acquisition simply replaces the earlier record
- Trap: An encrypted image that cannot be read is a failed acquisition
- Trap: Remote collection needs no chain of custody
cybercertprep.com · original revision sheet written from the public body of knowledge