Open cardosec

Case 5EBAD2 · Blue team / DFIR · L2 Practitioner

Evidence and Chain of Custody

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Follow order of volatility (RFC 3227): registers/cache, network and process tables, memory, temp files, disk, then archives.
  2. Image with write blockers; hash (SHA-256) at acquisition and verify before analysis; analyze copies only.
  3. Chain of custody form logs who handled evidence, when, where it was stored, and every transfer.
  4. Record time, timezone and tool versions; unexplained gaps can make evidence inadmissible.

If the interviewer pushes back

  • How does chain of custody work for cloud evidence like a snapshot of an EC2 volume?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.