Acquisition and chain of custody of digital evidence
This course provides a comprehensive and practical guide to the technical and regulatory procedures required for the acquisition, preservation, and forensic validation of digital evidence. Throughout its chapters, it covers key concepts in computer forensics, hash functions, national and international regulations, specialized tools, disk cloning and forensic imaging procedures, and essential aspects of the chain of custody. The content is enriched with practical examples using tools such as FTK Imager, Autopsy, OSForensics, dd, and dc3dd, and includes evidence extracted from hard drives, USB sticks, mobile devices, and computers. It is an essential resource for those aiming to produce legally valid forensic expert reports.
The main objectives of this course include the following:
- Understand the role of computer forensics in the acquisition and analysis of digital evidence.
- Apply proper disk cloning and forensic imaging procedures in accordance with accepted standards.
- Become familiar with applicable regulations such as RFC 3227, UNE 71506, and UNE-ISO/IEC 27037:2016.
- Ensure the authenticity and integrity of evidence using hash functions and a proper chain of custody.
- Use specialized forensic tools to obtain evidence in a professional and legally valid manner.