{"id":365,"date":"2019-10-19T00:11:00","date_gmt":"2019-10-18T16:11:00","guid":{"rendered":"http:\/\/note.systw.net\/note\/?p=365"},"modified":"2023-10-31T00:12:19","modified_gmt":"2023-10-30T16:12:19","slug":"first-responder","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/365","title":{"rendered":"First Responder"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><strong>First Response Basics<\/strong><\/h2>\n\n\n\n<p><strong>Roles of first responder<\/strong><br>identifying the crime scene<br>protecting the crime scene<br>preserving temporary and fragile evidence<br>collecting the complete information about the incident<br>documenting all the findings<br>packaging and transporting the electronic evidence<\/p>\n\n\n\n<p>&#8230;&nbsp;<\/p>\n\n\n\n<p><strong>People for first response<\/strong><br>system administrators<br>non-laboratory staff<br>laboratory forensics staff<\/p>\n\n\n\n<p><br><strong>First response for laboatory forensics staff<\/strong><br>1 \u4fdd\u8b77\u73fe\u5834,securing and evaluating electronic crime scene<br>2 \u521d\u6b65\u8a2a\u8ac7,conducting preliminary interviews<br>3 \u73fe\u5834\u8a18\u9304,documenting electronic crime scene<br>4 \u63a1\u8b49,collecting and preserving electronic evidence<br>5 \u8b49\u7269\u6253\u5305,packaging electronic evidence<br>6 \u904b\u56delab,transporting electronic evidence<\/p>\n\n\n\n<p><strong>First response for non-laboratory staff<\/strong><br>contact a computer forensic examiner as soon as possible.<br>secure the scene until forensics staff advises.<br>make notes about the scene.<br>ps:<br>don&#8217;t try searching something, becasue timestamps of evidence can is changed.<br><br>&#8230;.<\/p>\n\n\n\n<p><strong>Documenting an electronic crime scene<\/strong><br>Document the physical scene<br>ex:the position of the mouse, the location of components near the system<br>Document related electronic components that are difficult to find.<br>Record the condition of the computer system, storage media, electronic devices and conventional evidence, including power status of the computer<\/p>\n\n\n\n<p>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Collecting and Preserving Electronic Evidence<\/strong><\/h2>\n\n\n\n<p><strong>Principle<\/strong><br>Do not turn the computer off or on<br>Do not run any programs, or attempt to access data on a computer<\/p>\n\n\n\n<p><strong>Dealing with powered on computers<\/strong><br>if monitor screen is viewable:<br>\u3000record the programs running on screen.<br>\u3000take a photograph.<br>if monitor shows some picture or screen saver:<br>\u3000move the mouse slowly without depressing any mouse button.<br>\u3000take a photograph.<br>if monitor is powered on and the display is blank<br>\u3000move the mouse slowly without depressing any mouse button.<br>\u3000take a photograph.<\/p>\n\n\n\n<p><strong>Dealing with powered off computers<\/strong><br>if computer is switched off<br>\u3000leave it off<br>if only monitor is switched off and display is blank:<br>\u3000turn the monitor on, move the mouse slightly. observe the changes from a blank screen. if it is not change, do not perform any keystroke<br>\u3000take a photograph<br>ps:<br>if the computer boots up, some files are written to the computer and computer is changed<br>&#8230;<\/p>\n\n\n\n<p><strong>OS shutdown procedure<\/strong><\/p>\n\n\n\n<p><strong>windows:<\/strong><br>1.give a explaination if any program is running<br>2.unplug the power cord ( don&#8217;t click poweroff by windows OS)<\/p>\n\n\n\n<p><strong>Mac OS:<\/strong><br>1.record time from the manu bar<br>2.click special -&gt; shutdown<br>3.unplug the power cord<\/p>\n\n\n\n<p><strong>UNIX\/Linux:<\/strong><br>1. in console: sync;sync;halt<br>2. unplug the power cord<br>ps: if step1 can&#8217;t work, unplug the power cord<\/p>\n\n\n\n<p>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Packaging and Transporting Electronic Evidence<\/strong><\/h2>\n\n\n\n<p><strong>Exhibit numbering for evidence<\/strong><br>format: aaa\/ddmmyy\/nnnn\/zz<br>\u3000aaa: ID of forensic analyst or law enforcement officer<br>\u3000ddmmyy: date<br>\u3000nnnn: project ID or SN of exhibits seized<br>\u3000zz: sequence number, like A could be CPU, B could be Moniter<\/p>\n\n\n\n<p>&#8230;<\/p>\n\n\n\n<p><strong>Common mistakes for first responder<\/strong><br>shutdown or reboot victim computer<br>access victim computer by command<br>not documenting the data collection process<\/p>\n","protected":false},"excerpt":{"rendered":"<p>First Response Basics Roles of &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[11],"tags":[],"class_list":["post-365","post","type-post","status-publish","format-standard","hentry","category-forensics"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=365"}],"version-history":[{"count":0,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/365\/revisions"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}