Day 6: Incident Response, Digital Forensics & The Chain of Custody!
HELLO FRIENDS!!
WELCOME TO MY CYPHER LOG
Guys in this blog I am going to share about what I have learned today and the blog is full of how we need to react before and after an attack and also the golden rule of cybersecurity. So can we stop this introduction and start learning about this.
Incident response
When an attack happens we would call it a cyber incident.
Incident response life cycle
The national industry standard has six phases for handling a cyber attack
Preparation
Preparation is when a natural disaster occurs and the government organised a preventive measures and also made preparation to reduce the damage before it happens so that's how this preparation works in organisations they will hire a trained staff and have tools and policies before an attack happens.
Identification
Identification is finding an attack already happened by some incidents like an alert from intrusion detection alarm and if a user reports as they receive a strange email.
Containment
Containment is stopping the damage to spread like if someone had fever that could spread to others too so doctors prefer them to stay isolated that's how we must isolate the infected system from the network without turning it off because if we switched off the system it could lead to loss of data basically it's to preserve RAM data by doing this an attacker can't destroy the evidence.
Eradication
It is removing threat, if there's any small bugs or destroyed leaves in plants we tend to remove that so we can save the plant that's how this eradication works by detecting malware or patching the vulnerability to prevent an attack.
Recovery
If an attack happened we need to totally clean the system and restore the data from the backup so that again the attack can't happen.
Lessons learned
It's like logging things we have already seen in our blog, here we need to write a report to be alert and prevent these things before it happens.
Next we come to the final part which is the golden rule,
The golden rule of cybersecurity - chain of custody
Actually it will be used for those who try to become investigating officers like me ,
This chain of custody is a documented unbroken trial that shows exactly who handled the evidence, when, where, and why from the moment it was collected until it is presented in court.
If this chain is broken then they won't consider this as evidence.
Let's see how they maintain this chain of custody
Officers arrive at the scene and take the photo of the laptop in the exact state then writes down the serial number, make and model of those systems then keep the evidence in evidence bag seal it and signs across the seal then kept it in the evidence room and note down date and time and about the officer who bring that.
This is how it actually happens.
So that's it guys let's see in other topics I hope you guys found it helpful.
If you want study guide to learn more about this you can get through this site

Comments
Post a Comment