7.1 Investigations & Digital Forensics

CISSP Domain 7 ยท Security Operations

7.1 Investigations & Digital Forensics

When a security incident, policy violation, fraud allegation or other suspicious event occurs, the organisation needs to determine what happened without destroying the evidence needed to answer that question.

Digital forensics provides structured methods for identifying, preserving, collecting, examining, analysing and reporting digital evidence.

๐Ÿ›ก๏ธ

Preserve

Protect evidence from unnecessary alteration, loss or contamination.

KEEP IT TRUSTWORTHY
๐Ÿ”Ž

Investigate

Examine artifacts and reconstruct relevant activity.

WHAT HAPPENED?
๐Ÿ“‹

Document

Record methods, evidence, custody, findings and limitations.

CAN WE SUPPORT IT?
Current CISSP 7.1 Scope

Understand and Comply With Investigations

Evidence Collection & Handling

Identify, preserve, acquire, protect and track relevant evidence.

Reporting & Documentation

Maintain clear records showing what was done, what was found and how conclusions were reached.

Investigative Techniques

Use appropriate methods to reconstruct events and understand relevant activity.

Digital Forensics Tools, Tactics & Procedures

Use suitable and validated forensic capabilities according to established procedures.

Artifacts

Analyse evidence from data, computers, networks, mobile devices and related digital environments.

7.1 Official Topics

EVIDENCE Collect + protect
DOCUMENT Record everything
INVESTIGATE Reconstruct events
TOOLS Use reliable methods
ARTIFACTS Find digital traces

The Big Idea

Investigation is not simply searching a computer until something suspicious appears.

The investigator must consider authority, evidence integrity, reproducibility, documentation and the purpose of the investigation.

Authority โ†’ Are We Allowed to Investigate?
Identify โ†’ What Evidence May Exist?
Preserve โ†’ Prevent Unnecessary Change
Collect โ†’ Acquire Evidence
Examine โ†’ Extract Relevant Artifacts
Analyse โ†’ Interpret What Happened
Report โ†’ Document Findings

Investigation Flow

AUTHORISE Permission
PRESERVE Protect
COLLECT Acquire
EXAMINE Extract
ANALYSE Interpret
REPORT Explain
Before You Touch Evidence

Investigative Authority

Investigators should understand what authority permits the investigation and what limitations apply before accessing systems or information.

Organisational Authority

Internal policy, employment agreements and authorised investigation procedures may govern internal investigations.

Legal Authority

Laws, court processes and investigative powers may govern civil or criminal investigations.

Regulatory Requirements

Regulators may impose investigation, preservation or reporting obligations.

Contractual Authority

Third-party systems may require contractual rights or provider cooperation.

Privacy Requirements

Access to communications and personal information may be restricted even during legitimate security investigations.

Jurisdiction

Requirements may differ according to location and applicable law.

Technical ability to access evidence โ‰  authority to access it.
โš–๏ธ Investigation Context Matters Different investigations can have different requirements

Domain 1 introduces several investigation types. Domain 7 focuses more strongly on how security operations support those investigations.

Administrative

Internal policy, employee misconduct or organisational procedures.

Civil

Disputes between parties where electronically stored information may become relevant.

Criminal

Potential criminal activity requiring particularly careful coordination with appropriate legal and investigative authorities.

Regulatory

Investigation conducted under regulatory obligations or oversight.

Industry / Contractual

Investigations arising from standards, contracts or sector requirements.

Do not assume one procedure fits every investigation

Authority, privacy, reporting, retention and evidence requirements can depend on the investigation's purpose and jurisdiction.

Digital Forensics

What Is Digital Forensics?

Digital forensics applies investigative and computer-science methods to digital evidence while preserving the integrity of the information and maintaining appropriate evidence-handling records.

Identification

Determine where potentially relevant evidence may exist.

Collection

Acquire relevant information using suitable procedures.

Examination

Extract, recover, filter and organise relevant digital artifacts.

Analysis

Interpret artifacts and reconstruct events.

Reporting

Explain methods, evidence, findings, limitations and conclusions.

๐Ÿง  Examination vs Analysis Extracting evidence is different from interpreting it
Examination

Identify and extract potentially relevant information from the evidence.

Example

Recover browser history and authentication logs.

Analysis

Interpret that information to determine what it means in the context of the investigation.

Example

Correlate browser activity with authentication events to reconstruct the attacker's actions.

Examine vs Analyse

EXAMINE What artifacts exist?
ANALYSE What do they mean?
Official 7.1 Topic 1

Evidence Collection & Handling

Digital evidence can be altered extremely easily.

Collection procedures therefore aim to preserve the integrity, provenance and context of the information being investigated.

Identify โ†’ Potential Evidence
Document โ†’ Original State
Preserve โ†’ Prevent Unnecessary Change
Acquire โ†’ Forensic Copy / Collection
Verify โ†’ Integrity
Track โ†’ Chain of Custody
Store โ†’ Protect Evidence
Essential CISSP Concept

Chain of Custody

Chain of custody records the movement and handling of evidence throughout its lifecycle.

It helps demonstrate:

who possessed the evidence, when they possessed it, why it was transferred and what happened while it was under their control.

Evidence ID

Unique identifier for the item.

Description

What exactly was collected?

Collector

Who collected it?

Location

Where was it obtained?

Date & Time

When was it collected or transferred?

Transfer

Who gave it to whom?

Purpose

Why was possession transferred?

Storage

Where was the item safeguarded?

Chain of Custody

WHO? Handled it
WHAT? Evidence item
WHEN? Date + time
WHERE? Location
WHY? Purpose / transfer
๐Ÿ”— Broken Chain of Custody Unexplained possession can undermine confidence in evidence
Example

A laptop is collected at 10:00.

The evidence record shows:

Investigator A โ†’ evidence storage.

Three days later, Investigator B analyses it.

Nobody recorded:

when B received it or who removed it from storage.

Missing transfer record = chain-of-custody problem.

Hashing & Evidence Integrity

Cryptographic hashes are commonly used to help demonstrate that digital evidence has not changed between acquisition and later examination.

Original Evidence โ†’ Calculate Hash
Forensic Image โ†’ Calculate Hash
Hashes Match โ†’ Integrity Supported
Later examination

Before analysing the evidence copy, the examiner recalculates the hash.

If the expected and calculated values match, this provides evidence that the copy has remained unchanged.

Hash = integrity evidence. Chain of custody = handling history.
#๏ธโƒฃ A Hash Does Not Replace Chain of Custody They answer different questions
Hash

Helps answer:

"Is this data unchanged from the reference value?"

Chain of Custody

Helps answer:

"Who controlled this evidence throughout its lifecycle?"

Matching hash โ‰  documented custody
Preservation

Preserve the Original

Where practical and appropriate, forensic examination is performed using a verified working copy rather than repeatedly modifying or interacting with original evidence.

Original Device โ†’ Preserve
Acquire โ†’ Forensic Image
Verify โ†’ Hash
Working Copy โ†’ Examine

Evidence Rule

ORIGINAL Preserve
COPY Verify
WORKING COPY Analyse
๐Ÿ’ฝ Forensic Imaging Acquire evidence while preserving its original content
Physical / Bit-Level Acquisition

Acquires the underlying storage content at a low level and may include areas not visible through normal filesystem access.

Logical Acquisition

Collects selected files, objects or data available through a filesystem, application, operating system or service interface.

Choose acquisition according to the investigation

Device type, encryption, system state, authority, available tools, business impact and investigation objectives all affect the appropriate method.

Write Blockers

A write blocker is used during appropriate storage-media acquisition to prevent or restrict writes to the source evidence.

Hardware Write Blocker

Physical device positioned between forensic workstation and source media.

Software Write Blocking

Software-based mechanism used to prevent changes to evidence media.

Read the evidence. Avoid writing to the evidence.
Acquisition Decision

Live vs Offline Acquisition

Live Acquisition

Collect evidence while the system is operating.

RAM Processes Network Sessions Logged-In Users Decryption Context

ADVANTAGE: VOLATILE DATA

Offline / Dead Acquisition

Acquire persistent storage after the system is no longer actively operating.

Disk Files Filesystem Deleted Data Persistent Logs

ADVANTAGE: LESS LIVE-SYSTEM CHANGE

Live acquisition has a trade-off

Running forensic tools on a live machine inevitably changes some system state, but shutting the machine down may destroy volatile evidence.

Preserve what will disappear before collecting what will remain.
๐Ÿ’จ Order of Volatility Some digital evidence disappears much faster than other evidence

When volatile evidence is important, investigators generally consider collecting the most transient information before more persistent sources.

Most Volatile โ†’ Memory / Active State
Running System โ†’ Processes / Sessions / Connections
Temporary State โ†’ Caches / Temporary Information
Persistent Storage โ†’ Disk / Files / Logs
Less Volatile โ†’ Archived / Backup Evidence
The exact collection sequence is situation-dependent

Safety, business impact, encryption, authority, available tools and evidential value can affect the actual decision.

Volatility

DISAPPEARS FAST? Collect earlier
PERSISTS? Can usually wait longer
๐Ÿง  Memory Forensics RAM can reveal evidence that never reaches disk

Possible Memory Artifacts

Processes Injected Code Network Connections Command History Loaded Modules Credentials / Tokens Encryption Material
Scenario

A ransomware process is currently executing entirely in memory.

Powering off the workstation before collecting volatile evidence may destroy some of the most useful investigative information.

RAM is volatile. Disk is persistent.
โป Do Not Automatically Power Off a System The correct action depends on investigative and operational priorities

Immediate shutdown may:

  • destroy volatile memory evidence;
  • terminate active network sessions;
  • lose running-process information;
  • remove access to decrypted data.

Leaving the system running may:

  • allow an attacker to continue operating;
  • allow malware to continue modifying data;
  • create additional system changes;
  • increase business or safety impact.
There is no universal "always shut it down" rule.
Preservation

Evidence Must Survive the Investigation

Evidence preservation means maintaining digital evidence in a condition that supports reliable later examination and analysis.

Prevent Modification

Avoid unnecessary changes to original evidence.

Protect Integrity

Use integrity verification where appropriate.

Control Access

Limit handling to authorised personnel.

Maintain Metadata

Preserve timestamps, attributes and relevant context.

Protect Storage

Safeguard physical and digital evidence repositories.

Retain Appropriately

Apply applicable investigative, organisational and legal retention requirements.

๐Ÿ”ฌ Forensically Sound Methods The method should support confidence in the evidence and conclusions
Documented

Record what procedures were performed.

Repeatable

Another competent examiner should be able to understand and, where appropriate, repeat the technique.

Reliable

Use suitable techniques and tools with understood limitations.

Integrity Preserving

Minimise unnecessary alteration of evidence.

Traceable

Connect findings back to supporting evidence.

Authorised

Operate within the investigation's legal and organisational scope.

Official 7.1 Topic 3

Investigative Techniques

Investigators combine multiple techniques to reconstruct relevant activity.

Timeline Analysis

Arrange events chronologically to understand what happened before, during and after an incident.

Log Correlation

Compare events from multiple systems to identify relationships.

Metadata Analysis

Examine timestamps, ownership, attributes and other information about digital objects.

Keyword / Pattern Search

Locate relevant strings, identifiers, addresses or known patterns.

Deleted-Data Recovery

Identify recoverable information no longer visible through normal application interfaces.

File Carving

Recover files or fragments using identifiable structures when normal filesystem metadata is unavailable.

Memory Analysis

Examine volatile system state.

Network Analysis

Examine packets, flows and network-service records.

Event Reconstruction

Combine artifacts into a defensible explanation of relevant events.

๐Ÿ•’ Timeline Analysis One artifact gives a clue; several correlated artifacts tell a story
09:02 โ†’ Phishing Email Delivered
09:08 โ†’ User Opens Attachment
09:09 โ†’ New Process Starts
09:10 โ†’ Outbound Connection
09:14 โ†’ New Administrator Account
09:31 โ†’ Data Transfer Begins
Timeline = turn isolated events into sequence.
โฑ๏ธ Time Matters Poor time information can make correlation difficult

Consider

Time Zones Clock Drift UTC Daylight Saving Device Clock Timestamp Format Time Synchronisation
Example

Firewall event: 14:00 UTC.

Application event: 15:00 BST.

These may describe:

the same moment.

Before building a timeline, understand the clocks.

Correlate Multiple Evidence Sources

Suspicious login

Identity log says: User A authenticated at 02:14.

Identity Provider โ†’ Authentication
VPN โ†’ Source Address
Endpoint โ†’ Device State
Cloud โ†’ API Actions
DLP โ†’ Data Transfer
Correlation increases context.
Official 7.1 Topic 5

Digital Artifacts

A digital artifact is information created, stored or transmitted by digital activity that may become relevant to an investigation.

Example

An attacker authenticates to a server.

The action may leave artifacts in:

Identity Logs VPN Logs Server Logs Memory Network Flow Shell History
Activity leaves traces. Forensics finds and interprets those traces.
๐Ÿงฉ Artifact vs Indicator of Compromise Not every artifact means an attack occurred
Artifact

A digital trace or object relevant to analysis.

Example

Browser-history entry.

Indicator of Compromise - IoC

Evidence or observable information suggesting that malicious activity may have occurred.

Example

Known malicious command-and-control address appearing in network logs.

Artifact โ‰  automatically malicious
Artifact Type

Data Artifacts

Files

Documents, images, archives, executables and other stored objects.

Metadata

Creation times, modification times, ownership and object attributes.

Databases

Application records, transaction history and structured information.

Email

Messages, headers, attachments and routing information.

Application Logs

Authentication, transactions, errors and user actions.

Cloud Objects

Files, versions, snapshots and service-generated records.

Artifact Type

Computer Artifacts

Filesystem Operating-System Logs Registry / Configuration RAM Browser History Downloads Recent Files User Profiles Scheduled Tasks Services Persistence Mechanisms Shell History
Example

An attacker downloads malware.

Possible evidence may include:

Browser โ†’ Download Record
Filesystem โ†’ Malicious File
OS โ†’ Execution Evidence
Memory โ†’ Running Process
Artifact Type

Network Artifacts

Packet Capture

Detailed network communications where capture exists.

Network Flow

Metadata describing communicating endpoints and traffic patterns.

DNS

Name-resolution activity.

DHCP

Evidence connecting devices with dynamically assigned addresses.

Firewall

Allowed and blocked network connections.

Proxy

Web requests, destinations and user activity.

VPN

Remote sessions and identity-related connection evidence.

IDS / IPS

Security detections and associated network information.

Network Forensics

WHO? Endpoints
WHERE? Addresses
WHEN? Time
WHAT? Protocol / traffic
๐ŸŒ Packets vs Flow Data Detail versus summary
Packet Capture

May contain detailed packet-level communication information.

DEEP DETAIL

Flow Records

Summarise communication relationships without necessarily retaining full packet payloads.

CONNECTION SUMMARY

Packet = conversation detail. Flow = who talked to whom.
Artifact Type

Mobile Device Artifacts

Calls Messages Contacts Application Data Photos Videos Location Data Browser History Device Logs Wi-Fi Networks Cloud Synchronisation
Mobile devices require specialist handling

Device locking, encryption, remote-wipe capability, cloud synchronisation and rapidly changing mobile platforms can affect acquisition and preservation decisions.

๐Ÿ“ฑ Mobile Device Preservation Connectivity can affect evidence

Depending on circumstances, investigators may need to consider whether network connectivity could:

  • allow remote wiping;
  • cause new messages or synchronisation events;
  • change device state;
  • permit remote access.
Do not improvise mobile-device actions without understanding their effect.
Modern Forensics

Cloud Forensics

Evidence in cloud environments may be distributed across provider and customer systems rather than existing on a single physical computer.

Control-Plane Logs

Administrative and API actions performed against cloud resources.

Identity Logs

Authentication and authorization events.

Service Logs

Evidence created by individual cloud services.

Snapshots

Point-in-time copies of relevant cloud resources where supported.

Object Versions

Previous versions of cloud-hosted data where versioning exists.

Provider Evidence

Some required information may be controlled by the cloud provider.

Cloud evidence may exist somewhere you do not physically control.
โ˜๏ธ Cloud Forensic Challenges Forensic readiness becomes especially important in distributed environments
Shared Responsibility Provider Dependency Distributed Data Multi-Tenancy Jurisdiction Ephemeral Resources Log Availability Retention API Access Time Synchronisation
Example

A compromised virtual server is automatically destroyed by an orchestration platform.

Without adequate external logging or snapshots:

important evidence may disappear with the workload.

Cloud Forensics

LOG Before you need it
RETAIN Long enough
ACCESS Know how
PRESERVE Before resources disappear
Prepare Before the Incident

Forensic Readiness

Forensic readiness means designing systems and processes so useful evidence can be identified and collected effectively when an investigation occurs.

Logging

Generate evidence before an incident occurs.

Retention

Keep relevant evidence for an appropriate period.

Time Synchronisation

Make event correlation possible.

Cloud Configuration

Enable required audit and control-plane logging.

Access

Ensure investigators can obtain necessary evidence when authorised.

Tools & Skills

Prepare forensic capabilities before they are urgently required.

Procedures

Define roles, escalation and evidence-handling processes.

Provider Agreements

Understand how evidence will be obtained from external providers.

The worst time to discover that logs were disabled is after the breach.
Official 7.1 Topic 4

Digital Forensics Tools, Tactics & Procedures

Different evidence sources require different forensic capabilities.

Acquisition Tools

Create forensic images or collect relevant data.

Write Blocking

Protect source media during appropriate acquisition.

Memory Capture

Acquire volatile memory from running systems.

Filesystem Analysis

Examine files, metadata and deleted information.

Network Analysis

Analyse packets, flows and network-service records.

Mobile Forensics

Extract and examine evidence from mobile devices.

Timeline Tools

Aggregate timestamps and events for reconstruction.

Cloud Evidence Tools

Export logs, snapshots and service evidence through supported interfaces.

๐Ÿงฐ Forensic Tools Need Trust A tool's output should not be accepted blindly

Understand

Tool Purpose Tool Version Configuration Supported Formats Known Limitations Validation Output Interpretation
Example

A forensic program reports:

"File created at 14:03."

Before relying on this conclusion, the examiner should understand:

  • which timestamp the tool displayed;
  • how that filesystem records time;
  • whether the timestamp can be changed by copying or restoring;
  • which time zone was applied.
Tool output still requires examiner understanding.

Artifacts Require Interpretation

A digital artifact may demonstrate that something exists without proving exactly how or why it was created.

Finding

A suspicious file exists in a user's Downloads folder.

Unsupported conclusion

"The user intentionally downloaded and executed malware."

Further evidence may be required to determine:

How File Arrived Which Process Created It Whether It Executed Which User Was Active What Happened Afterwards
Artifact โ‰  entire story.
๐Ÿง  Fact vs Inference Separate what the evidence shows from what you conclude from it
Observed Fact

Authentication logs show Account A successfully authenticated at 03:12.

Reasonable Inference

Account A's credentials were used at 03:12.

Unsupported Leap

The human owner of Account A personally performed the login.

Account activity identifies the account. It may not automatically identify the human behind the keyboard.
๐Ÿ•ต๏ธ Be Careful With Attribution Technical evidence can support attribution without necessarily proving identity by itself
Evidence

Malicious traffic originates from:

IP address X.

This may establish:

where the observed traffic came from.

It does not automatically prove:

who controlled the system generating that traffic.

IP address โ‰  automatic human identity.
Official 7.1 Topic 2

Reporting & Documentation

Documentation creates the record that allows another person to understand what the investigator did and how conclusions were reached.

Case Information

Investigation identifier, objective and scope.

Authority

Relevant authorisation and restrictions.

Evidence Inventory

What evidence was collected?

Chain of Custody

Who handled the evidence?

Methods

Which acquisition and examination methods were used?

Tools & Versions

Which forensic tools generated the results?

Integrity Values

Relevant hashes or other integrity records.

Timeline

What significant events occurred?

Findings

What does the evidence demonstrate?

Limitations

What could not be determined?

Conclusion

What is the evidence-supported outcome?

๐Ÿ“ Contemporaneous Notes Record important actions while the investigation is occurring
Useful note

14:11 - Laptop located powered on and connected to wired network.

14:13 - Photographed screen and physical connections.

14:16 - Incident lead authorised network isolation while maintaining power.

14:21 - Volatile-memory acquisition initiated.

Document what you did while you still remember exactly what you did.
๐Ÿ“„ Objective Reporting Report what the evidence supports, including uncertainty

A Strong Report Distinguishes

Observed Facts Interpretation Inference Uncertainty Limitations
Better language

"The logs show that Account A downloaded 4.2 GB from the customer database between 02:14 and 02:38."

Overstatement

"Employee A stole customer data."

Let the evidence support the conclusion. Do not make the conclusion stronger than the evidence.

Document Limitations

Digital investigations cannot always recover every artifact or answer every question.

Missing Logs

Relevant events were not recorded or retained.

Encryption

Relevant content could not be accessed.

Overwritten Data

Deleted information is no longer recoverable.

Tool Limitation

The forensic tool does not correctly interpret a particular artifact.

Missing Device

Relevant evidence source is unavailable.

Provider Limitation

Cloud or third-party information is unavailable.

"Unable to determine" can be the correct forensic conclusion.
๐Ÿ”’ Preservation & Legal Hold Normal deletion processes may need to stop when information must be preserved

When an appropriate preservation obligation applies, relevant information may need to be protected from routine deletion or destruction.

Normal operation

Email logs are automatically deleted after 90 days.

Investigation

Relevant records are identified for preservation.

The organisation may need to prevent those records from being deleted according to applicable legal and organisational requirements.

Routine retention schedule may be overridden by an authorised preservation requirement.
๐Ÿ” Investigation Does Not Eliminate Privacy Collect what is authorised and relevant

Investigators may encounter:

Personal Data Private Communications Health Information Financial Information Unrelated Employee Data Customer Records
Investigation authority should not be interpreted as unlimited curiosity.
Evidence Security

Protect the Evidence Repository

Forensic evidence may contain passwords, confidential information, malware, personal data and detailed information about security weaknesses.

Access Control

Restrict access to authorised investigators.

Encryption

Protect evidence where appropriate during storage and transfer.

Audit Logging

Record access to evidence repositories.

Integrity

Detect unauthorised changes.

Backup

Prevent loss of critical investigative evidence.

Retention & Disposal

Retain and eventually dispose according to applicable requirements.

Evidence is itself a sensitive asset.

Incident Response vs Digital Forensics

Incident Response

Focuses on containing, mitigating and recovering from a security incident.

STOP THE DAMAGE

Digital Forensics

Focuses on preserving and examining evidence to understand relevant activity.

UNDERSTAND THE EVIDENCE

The objectives can conflict

Incident responders may want to shut down a compromised server immediately.

Forensic investigators may want to preserve volatile evidence first.

The organisation must balance evidence value with operational, security, safety and business requirements.

Practical Scenario

Ransomware Is Running Right Now

A workstation is actively encrypting network files.

The computer is:

Powered On User Logged In Malware Running Network Connected
Incident Priority โ†’ Stop Further Damage
Forensic Priority โ†’ Preserve Volatile Evidence
Decision โ†’ Isolate Network While Maintaining Power
Collect โ†’ Memory + Running Processes
Then โ†’ Acquire Persistent Evidence
This is an example, not a universal procedure

Actual actions depend on authorisation, incident severity, business impact, available skills and the environment.

Investigation Scenario

Possible Insider Data Theft

An employee is suspected of copying confidential customer information before leaving the organisation.

Authorisation โ†’ Security + HR + Legal
Identity โ†’ Authentication Logs
Endpoint โ†’ Computer Artifacts
DLP โ†’ Data Transfer Records
Email โ†’ Relevant Messages
Network โ†’ Proxy / Cloud Activity
Correlate โ†’ Timeline
Investigation should follow the evidence, not start from the assumption that the employee is guilty.
Cloud Scenario

Compromised Cloud Administrator

A cloud administrator account is suspected of creating unauthorised access keys and downloading sensitive information.

Identity Logs โ†’ Authentication
Control Plane โ†’ API Activity
IAM โ†’ Key Creation
Storage โ†’ Object Access
Network โ†’ Source Addresses
Timeline โ†’ Reconstruct Activity
In cloud investigations, control-plane logs can be as important as traditional host evidence.
Mobile Scenario

The Unlocked Phone

Investigators receive an unlocked mobile phone relevant to an authorised investigation.

An inexperienced analyst starts:

  • opening applications;
  • reading messages;
  • taking screenshots;
  • changing device settings.
These actions may modify device state and undermine forensic preservation.
Preserve first. Explore later using appropriate forensic procedures.
Forensic Readiness Scenario

The Attack Happened 91 Days Ago

Security discovers evidence indicating that an attacker entered the environment three months earlier.

The relevant authentication logs are retained for:

90 days.

They were deleted yesterday.

Logging without suitable retention may still leave the investigation blind.
๐ŸŽ“ CISSP Scenarios Recognise the investigation or forensic principle being tested
Scenario 1

A security analyst discovers suspicious activity and immediately accesses an employee's private mailbox without verifying whether this is authorised.

Primary concern?

Investigative authority and privacy requirements.

Scenario 2

A forensic examiner needs to determine who handled a laptop after it was collected.

Which record?

Chain of custody.

Scenario 3

Evidence was transferred to another investigator, but no transfer was documented.

Which problem?

Break in chain-of-custody documentation.

Scenario 4

The organisation wants to demonstrate that a forensic image has not changed since acquisition.

Which control is particularly useful?

Cryptographic hash verification.

Scenario 5

A forensic image has the correct hash but nobody knows who possessed the drive for two weeks.

Is the hash a replacement for custody records?

No.

Scenario 6

An investigator analyses the only original copy of evidence and repeatedly modifies it.

Better approach?

Preserve the original and analyse verified working copies where practical.

Scenario 7

A forensic examiner connects a storage drive to an analysis computer while preventing writes to the evidence device.

Which mechanism?

Write blocker.

Scenario 8

Investigators need information about processes and active network sessions on a running computer.

Which evidence source?

Volatile / live-system evidence.

Scenario 9

The investigator powers off a machine before collecting RAM.

What happens?

The volatile-memory evidence is lost.

Scenario 10

An investigator needs both RAM and disk evidence.

Which should generally receive earlier consideration?

The more volatile evidence.

Scenario 11

Running a memory-acquisition tool changes some system state.

Does that automatically make live forensics invalid?

No.

The changes and method should be understood and documented.

Scenario 12

The examiner extracts browser history from a forensic image.

Examination or analysis?

Examination.

Scenario 13

The examiner correlates browser history with login records to determine the sequence of attacker activity.

Examination or analysis?

Analysis.

Scenario 14

Security combines endpoint, VPN, identity and firewall events into a chronological sequence.

Which technique?

Timeline analysis / event reconstruction.

Scenario 15

Two logs appear one hour apart because one records UTC and the other records local summer time.

Which consideration?

Time normalisation and time-zone interpretation.

Scenario 16

A deleted document no longer has normal filesystem references, but its identifiable data structure can still be recovered.

Which technique?

File carving.

Scenario 17

An investigation analyses packets captured from a compromised network segment.

Which artifact category?

Network artifact.

Scenario 18

Investigators know which hosts communicated but do not have the full packet payload.

Which evidence may provide this summary?

Network flow data.

Scenario 19

Investigators want details about calls, messages and application data from a smartphone.

Which speciality?

Mobile-device forensics.

Scenario 20

An investigator casually opens applications on a seized mobile device before acquiring evidence.

Primary concern?

Modification of evidence state.

Scenario 21

A cloud virtual machine has already been automatically destroyed.

Which other evidence may be especially important?

Cloud audit logs, identity events, snapshots and provider evidence.

Scenario 22

A cloud provider possesses evidence that the customer cannot directly access.

Which consideration?

Provider dependency and shared responsibility.

Scenario 23

An organisation enables detailed cloud audit logging before any incident occurs.

Which concept?

Forensic readiness.

Scenario 24

Security discovers an intrusion after all relevant logs have already expired.

Which programme weakness?

Insufficient forensic logging / retention readiness.

Scenario 25

A forensic tool generates a timestamp but the examiner cannot explain what that timestamp represents.

Primary concern?

Tool output is being used without sufficient interpretation.

Scenario 26

A forensic tool version has never been validated and produces inconsistent results.

Primary concern?

Tool reliability and validation.

Scenario 27

A suspicious executable exists in a user's download directory.

Does this prove the user intentionally executed it?

No.

Additional evidence is required.

Scenario 28

Logs show that an employee's account authenticated from a remote address.

Does this alone prove the employee personally performed the login?

No.

Scenario 29

Malicious traffic originates from a particular IP address.

Does this automatically identify the human attacker?

No.

Scenario 30

An investigator records every collection step, tool version, hash and significant action.

Which 7.1 objective?

Reporting and documentation.

Scenario 31

An investigation report describes facts, interpretations and limitations separately.

Why is this useful?

It supports objective and defensible reporting.

Scenario 32

Relevant data cannot be recovered because it was overwritten.

What should the examiner do?

Document the limitation rather than invent a conclusion.

Scenario 33

An investigator finds unrelated confidential employee information while examining an authorised evidence source.

What principle remains relevant?

Privacy, scope and appropriate handling.

Scenario 34

Evidence needed for an active legal matter would normally be deleted tomorrow under the routine retention schedule.

What may be required?

Authorised preservation / legal-hold procedures.

Scenario 35

Incident response wants to shut down a compromised machine while forensic investigators want to capture RAM.

Which issue?

Balance operational containment with preservation of volatile evidence.

Scenario 36

A security team preserves memory before acquiring the hard disk.

Which principle?

Order of volatility.

Scenario 37

Investigators secure evidence in a repository but every administrator has unrestricted access to it.

Primary problem?

Evidence access control and integrity risk.

Scenario 38

A report says: "The evidence does not allow us to determine which individual used the compromised account."

Is that necessarily a weak conclusion?

No.

It may be the most accurate evidence-supported conclusion.

Scenario 39

An investigator examines only endpoint evidence even though the incident occurred in a SaaS platform.

What is missing?

Relevant cloud/service artifacts.

Scenario 40

The investigation cannot determine the sequence of events because each system uses a different unsynchronised clock.

Which preparedness weakness?

Time synchronisation / forensic readiness.

CISSP Exam Perspective

Recognise the Clue Words

Before Collecting

Permission.

Authorisation

Who Handled It?

Evidence history.

Chain of Custody

Has Data Changed?

Integrity.

Hash

Prevent Writing

Source media.

Write Blocker

Preserve Original

Analyse copy.

Forensic Image

RAM

Disappears on power loss.

Volatile Evidence

Most Transient First

Collection priority.

Order of Volatility

Extract Artifacts

Before interpretation.

Examination

What Do Artifacts Mean?

Interpretation.

Analysis

Events in Sequence

Reconstruction.

Timeline Analysis

Multiple Log Sources

Connect evidence.

Correlation

Recover File Without Metadata

Structure.

File Carving

Full Network Detail

Communication.

Packet Capture

Who Talked to Whom?

Network summary.

Flow Data

Calls + Apps + Location

Device evidence.

Mobile Forensics

Cloud API Actions

Administrative evidence.

Control-Plane Logs

Prepare Logging in Advance

Investigation capability.

Forensic Readiness

Tool Says...

Understand output.

Validate / Interpret

What Evidence Shows

Direct observation.

Fact

What It Probably Means

Reasoning.

Inference

Cannot Determine

Evidence insufficient.

Document Limitation

Routine Deletion Must Stop

Preserve evidence.

Legal Hold / Preservation

Incident Needs Containment

Stop damage.

Incident Response

Need to Understand Events

Preserve + investigate.

Digital Forensics
โš ๏ธ Common CISSP Mistakes Digital evidence is useful only when it remains trustworthy and correctly interpreted
Technical Access โ‰  Investigative Authority

Confirm scope and authority before accessing evidence.

Security Investigation โ‰  Privacy No Longer Matters

Relevant legal, organisational and privacy requirements still apply.

Hash โ‰  Chain of Custody

Hashing supports integrity.

Chain of custody records evidence handling.

Working on Original Evidence โ‰  Best Default

Preserve original evidence and use verified copies where appropriate.

Copying Files โ‰  Always Forensic Imaging

Logical acquisition and physical acquisition provide different evidence.

Power Off Immediately โ‰  Universal Rule

Shutdown can destroy volatile evidence.

Leave It Running โ‰  Universal Rule Either

Continued operation can create additional security and evidential risk.

Disk First โ‰  Always Correct

Consider more volatile evidence when it is relevant.

Live Forensics โ‰  Zero System Change

Live acquisition itself affects system state and should be performed deliberately and documented.

Examination โ‰  Analysis

Examination extracts artifacts.

Analysis interprets them.

Artifact โ‰  Indicator of Compromise

Many normal system activities create digital artifacts.

Artifact Exists โ‰  User Intentionally Created It

Determine the process and context that generated it.

Account Used โ‰  Account Owner Proved Responsible

Credentials can be stolen or delegated.

IP Address โ‰  Human Identity

Attribution may require additional evidence.

Tool Output โ‰  Automatically Correct Interpretation

Understand the tool, artifact and limitations.

More Forensic Tools โ‰  Better Investigation

Correct methods and interpretation matter more than tool count.

Packet Capture โ‰  Flow

Packet capture can provide detailed communication information.

Flow records primarily summarise communications.

Cloud โ‰  No Forensics

Evidence sources change, and provider cooperation may become important.

Cloud Logs Enabled After Incident โ‰  Historical Evidence Recovered

Forensic readiness must exist before evidence is needed.

Logging โ‰  Useful Forensics

Retention, integrity, timestamps and access to the logs also matter.

Forensics โ‰  Incident Response

Incident response focuses on controlling the incident.

Forensics focuses on evidence and reconstruction.

Evidence Collection โ‰  Investigation Complete

Evidence must still be examined, analysed and interpreted.

Confident Language โ‰  Strong Evidence

Conclusions should reflect the strength and limitations of the evidence.

"Unable to Determine" โ‰  Failure

It may be the only defensible conclusion when evidence is insufficient.

Evidence Repository โ‰  Ordinary Shared Folder

Evidence requires appropriate confidentiality, integrity, access control and retention.

Quick Reference

If you see...Think...
Can we legally / organisationally investigate?Authority
Who handled evidence?Chain of Custody
Prove data remained unchangedHash
Prevent evidence drive modificationWrite Blocker
Low-level storage copyPhysical / Forensic Image
Selected files or service dataLogical Acquisition
RAM, processes, sessionsVolatile Evidence
Collect transient information firstOrder of Volatility
Extract artifactsExamination
Interpret artifactsAnalysis
Events chronologicallyTimeline Analysis
Connect several evidence sourcesCorrelation
Recover based on file structureFile Carving
Full network communication detailPacket Capture
Communication metadata / summaryFlow Data
Calls, messages, apps, locationMobile Forensics
Cloud administrative activityControl-Plane / API Logs
Prepare logging before incidentForensic Readiness
Tool produces resultValidate + Interpret
Evidence directly demonstrates somethingFact
Conclusion derived from evidenceInference
Evidence cannot answer questionDocument Limitation
Stop ordinary deletionPreservation / Legal Hold
Stop incident damageIncident Response
Understand what occurredDigital Forensics

Chain of Custody Memory Aid

IDENTIFY Which evidence?
COLLECT Who + where?
TRANSFER Who to whom?
TIME When?
PURPOSE Why?
STORE Where?

Digital Forensics Memory Aid

IDENTIFY Where is the evidence?
PRESERVE Protect it
COLLECT Acquire it
EXAMINE Extract artifacts
ANALYSE Interpret events
REPORT Explain findings

Artifact Memory Aid

DATA Files ยท databases ยท metadata
COMPUTER Disk ยท RAM ยท OS
NETWORK Packets ยท flows ยท logs
MOBILE Apps ยท messages ยท location
CLOUD API ยท identity ยท service logs

Volatility Memory Aid

RAM Very volatile
PROCESSES Running state
CONNECTIONS Active state
DISK Persistent
BACKUP More persistent

Collect what disappears before what remains.

7.1 Master Memory Aid

AUTHORISE Are we allowed?
PRESERVE Protect evidence
COLLECT Acquire evidence
VERIFY Integrity + custody
EXAMINE Find artifacts
ANALYSE Reconstruct events
REPORT Document objectively

Authorise โ†’ Preserve โ†’ Collect โ†’ Examine โ†’ Analyse โ†’ Report

The Investigator's Questions

AUTHORITY? Are we allowed?
WHAT? Which evidence matters?
VOLATILE? Will it disappear?
PRESERVED? Has it been protected?
INTEGRITY? Has it changed?
CUSTODY? Who handled it?
ARTIFACTS? What traces exist?
TIMELINE? In what order?
CORRELATE? What else supports it?
FACT? What does evidence directly show?
INFERENCE? What are we concluding?
LIMIT? What cannot we determine?
DOCUMENTED? Can another examiner understand it?

Key Takeaways

CISSP 7.1 focuses on understanding and complying with investigations.

The current CISSP outline specifically includes evidence collection and handling, reporting and documentation, investigative techniques, digital-forensics tools, tactics and procedures, and artifacts such as data, computer, network and mobile-device evidence.

Investigative authority should be understood before investigators access, collect or examine information.

Legal, privacy, employment, contractual and regulatory requirements can affect how an investigation is conducted.

Technical ability to access information does not automatically provide authority to investigate it.

Digital forensics applies structured investigative methods to electronic evidence.

A practical forensic lifecycle is:

Identify โ†’ Preserve โ†’ Collect โ†’ Examine โ†’ Analyse โ†’ Report.

Examination identifies and extracts relevant artifacts.

Analysis interprets those artifacts and reconstructs relevant activity.

Examine = what artifacts exist? Analyse = what do they mean?

Digital evidence is easy to alter and should therefore be collected and handled using procedures that maintain integrity and provenance.

Chain of custody records the handling and movement of evidence throughout its lifecycle.

Important chain-of-custody information includes the evidence identifier, handler, collection details, transfers, dates, times, locations and reasons for transfer.

Chain of custody answers: Who had the evidence, when, where and why?

Cryptographic hashes can help demonstrate that digital evidence has not changed from a known reference value.

Hashing and chain of custody support different aspects of evidence assurance.

Hash = integrity. Chain of custody = handling history.

Where practical, original digital evidence should be preserved while examination is performed using verified copies.

A physical or bit-level acquisition and a logical acquisition provide different kinds of evidence.

Write blockers can help prevent modification of source storage during appropriate forensic acquisition.

Some digital evidence is volatile.

RAM, running processes and active network sessions may disappear when a system loses power.

Persistent storage such as disks generally survives power loss.

Preserve evidence that may disappear before evidence likely to remain.

Live acquisition may capture valuable volatile information but also changes some system state.

Offline acquisition avoids many live-system changes but loses volatile information.

The decision depends on investigative objectives, authority, evidence value, operational risk and the environment.

There is therefore no universal rule that every suspicious computer should immediately be powered off.

Investigative techniques can include timeline analysis, log correlation, metadata analysis, keyword searching, deleted-data recovery, file carving, memory analysis and network analysis.

Timeline analysis puts relevant events into chronological order.

Correlation combines multiple evidence sources to establish context and strengthen understanding of events.

Accurate time interpretation is essential for correlation.

Time zones, clock drift and differing timestamp formats can make events appear to occur at different times.

Before trusting the timeline, understand the clocks.

Digital artifacts are traces created or stored by digital activity.

Artifact sources include files, metadata, operating-system information, memory, application logs, network records, mobile devices and cloud services.

An artifact is not automatically evidence of malicious behaviour.

Investigators should understand how an artifact was generated before assigning meaning to it.

Artifact โ‰  entire story.

Computer artifacts can include filesystem information, operating-system logs, browser records, memory, user profiles and persistence mechanisms.

Network artifacts can include packets, flow records, DNS, DHCP, firewall, proxy, VPN and detection-system information.

Packet captures and flow records provide different levels of network evidence.

Packet = detailed communication. Flow = communication summary.

Mobile forensic evidence can include messages, call information, application data, photographs, browser history, location information and device logs.

Mobile devices require careful preservation because connectivity, encryption, remote-management functions and normal device operation can alter evidence.

Cloud forensics introduces additional challenges because evidence may be distributed across services and controlled partly by external providers.

Cloud evidence may include identity logs, API activity, control-plane events, service logs, snapshots and object versions.

Ephemeral cloud resources can disappear quickly, making forensic readiness particularly important.

Cloud does not eliminate forensics. It changes where evidence exists and who controls it.

Forensic readiness means preparing systems, logging, retention, procedures, skills and provider arrangements before an investigation is required.

Logging alone is not enough.

Logs must also be available, protected, appropriately retained, time-aligned and accessible to authorised investigators.

The worst time to discover that evidence was never collected is after the incident.

Digital-forensics tools should be understood and appropriately validated.

Investigators should know what a tool does, its version, configuration, supported evidence types and known limitations.

Tool output still requires knowledgeable interpretation.

Modern operating systems and applications change over time, and the meaning of forensic artifacts may change with them.

Investigators should distinguish directly observed facts from interpretations and inferences.

Authentication logs demonstrating use of an account do not automatically prove which human physically performed the action.

Similarly, a source IP address does not automatically identify the human responsible for activity.

Evidence should support attribution rather than attribution being assumed from one technical indicator.

Investigation reports should record scope, authority, evidence, custody, methodology, tools, integrity information, findings, timelines, limitations and conclusions as appropriate.

Contemporaneous notes help create a reliable record of investigative actions.

Reports should distinguish facts from inference and clearly state limitations.

Digital investigations cannot always answer every question.

Missing logs, encryption, overwritten information, unavailable devices and tool limitations may prevent definitive conclusions.

"Unable to determine" is better than an unsupported conclusion.

Applicable preservation requirements may require information to be protected from routine deletion.

Investigations may expose unrelated sensitive information, so privacy, authorisation and appropriate data handling remain important.

Forensic evidence should itself be treated as a sensitive organisational asset and protected from unauthorised access, alteration or loss.

Incident response and digital forensics have related but different objectives.

Incident response focuses on stopping damage, containing incidents and restoring operations.

Digital forensics focuses on preserving evidence and understanding what occurred.

Those objectives sometimes compete, especially when volatile evidence exists on a system that also needs urgent containment.

The central CISSP principle is: obtain appropriate authority, preserve evidence before it disappears or changes, document its handling, use reliable investigative techniques, distinguish evidence from assumptions and report only conclusions that the evidence can support.

๐Ÿ“š Sources & Further Reading Current and foundational digital-forensics references