forumNew topic

Need to collect evidence from the attack debris (forensics). Who does it? How is it done?

KKader A***Member
Job title
Store Manager
Sector
Cosmetics
Organization type
two-branch business
Joined
Nov 2022
Message
183
#1

I know I shouldn't turn on the computer and check it after an attack. But how is evidence collected from the disk? Do the police or legal counsel do it?

What's in a digital forensics report? Is it hard to understand the findings?

What's the risk of wasting evidence? If I do the wrong thing, is the evidence considered spoiled? Does it retain its legal value?

BBarış K***Expert
Job title
Corporate IT manager
Joined
Jun 2023
Message
172
Most Helpful#2

Digital Forensics: Collection and analysis of cyber attack evidence. Who does it: 1) Penetration testing firm (preliminary), 2) Certified digital forensics expert, 3) Police (Cyber Crimes Branch) — for criminal cases, 4) Private consultants (independent third-party investigation). Process: 1) Scene preservation (don't touch anything after the incident), 2) Device acquisition (disk imaging: read-only copy, hash verification), 3) Analysis (file recovery, timeline reconstruction, malware analysis), 4) Chain of custody (documentation: who held it, when), 5) Report (findings, methodology, conclusion). Report contents: 1) Executive summary (what was found, conclusion), 2) Methodology (how the analysis was performed), 3) Detailed findings (file timeline, malware signatures, user activity logs), 4) Appendix (technical details, hash values, screenshots). Evidence value: Depends on scientific and procedural validity (chain of custody must be intact). Legal acceptance: In criminal cases initiated with the police, the prosecution may request a special report; in compensation lawsuits, insurance/peer reports are accepted. Cost: $2k-10k depending on complexity (number of devices, malware complexity).

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#3

hire a dgital forensics expert also file a complaint with the police... dont touch the disk get a pro to do imaging. find the timeline and malware write a report... like document the chain of custody — evidence needs to be admissible in court...

TTuğçe K***New memberCommunity member
Joined
Sep 2026
Message
310
#4

Digital forensics workflow: 1) Acquisition (dd tool: dd if=/dev/sda of=image.img bs=1M, verify MD5 hash), 2) Analysis (FTK Imager, EnCase, Volatility memory analysis), 3) Timeline (file timestamps: creation, modification, access — MAC times), 4) Artifact recovery (Windows Registry hives, browser cache, email databases), 5) Malware analysis (static + dynamic: sandbox execution, memory dump analysis), 6) Reporting (SANS format: methodology, findings, recommendations). Chain of custody form: device identifier, date/time of handover, signature of the person handling it, storage conditions, access log (who accessed it, when). Admissibility in court (Turkish Code of Criminal Procedure): expert credentials, methodology verification, reproducibility (can another expert reach the same result).

İİlker Ö***Expert
Job title
Store associate
Sector
Furniture manufacturing
Organization type
family business
Joined
Jul 2022
Message
9
#5

dont touch the computer, hire a forensic expert. do disk imaging, document the hash. document the chain of custody — who had it when. btw include timeline and malware analysis in the report but admissibility of evidence in court depends on the accuracy of the methodology...

MMustafa O***MemberCommunity member
Joined
Feb 2024
Message
77
#6

Digital forensics stages: Preservation (immediate evidence capture, no system changes), Acquisition (bit-for-bit copy, cryptographic hash verification), Examination (data parsing, artifact extraction), Analysis (timeline reconstruction, causality linking), Reporting (structured documentation, validation of findings). Quality assurance: independent verification (second analyst review), tool validation (only approved forensic software), expert qualification (certifications: GCFE, CFE, ECCE). Legal admissibility: Daubert standard (US courts) or equivalent (EU/TR courts require the methodology to be peer-reviewed, error rates known, and generally accepted in the field).

HHandeMember
Job title
Communications consultant
Joined
Aug 2024
Message
92
#7

My questions are cleared up, thanks. When we decide without measuring, we always end up in the same place.

I'm also curious if anyone does it differently.

BBarış I***New memberCommunity member
Joined
Sep 2026
Message
2
#8

We experienced almost the exact same thing last year. Your time to detect an issue directly determines its cost.

Just leaving this note, it might be useful.

ZZafer A***MemberCommunity member
Joined
Nov 2025
Message
152
#9

It's rare to find an explanation this clear. Hasty decisions become decisions you have to fix six months later.

NNurMember
Job title
Web Designer
Joined
Aug 2024
Message
96
#10

thnks a lot I'll try it today but i mean when making decisions, write down the worst-case scenario too, not just the best.

taking measures without an inventory laves doors you havent seen open.

ÜÜlkü O***MemberCommunity member
Joined
Mar 2024
Message
14
#11

it's rare to find an explanation this clear.

PPolat E***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
cooperative
Joined
Mar 2024
Message
273
#12

I can't fully agree with this. When making decisions, write down the worst-case scenario too, not just the best.

Taking measures without an inventory leaves doors you haven't seen open. If you have questions, write them; I'll answer as best I can.

NNeslihan T***Expert
Job title
Purchasing manager
Sector
Machinery manufacturing
Organization type
workshop
Joined
Dec 2024
Message
229
#13

I agree with this. If it's your first time, start small; scaling comes later.

If I were you, I'd go this route.

RRamazan K***MemberCommunity member
Joined
Jan 2025
Message
33
#14

Generally correct, but one part is missing. The biggest time-waster for us was not knowing who had the final say.

Hope this helps.

HHüsniye E***MemberCommunity member
Joined
Sep 2024
Message
260
#15

The cheap-looking path usually ends up costing more later. Solutions that work at a small scale collapse when you grow; I learned this late.

Processes without records never improve, because you don't know what to fix. Of course, it varies if your situation is different.

HHasan G***MemberCommunity member
Joined
Jan 2025
Message
144
#16

i agree, and I'd like to emphasize that. when you try to change everything at once nothing settles.

i'm also curious if anyoen does it differently.

ZZerrin K***MemberCommunity member
Joined
May 2025
Message
412
#17

The most overlooked point about digital forensics investigation is this: Don't rely on a single measure; go layer by layer.

When making a decision, first look at what data you have on hand. anyway im also curious if anyone does it differently.

YYasemin I***MemberCommunity member
Joined
Jun 2022
Message
11
#18

Don't miss this: If permission and scope aren't in writing, don't start that test.

An untested backup is not a backup.

YYağmur T***MemberCommunity member
Joined
Jun 2024
Message
283
#19

Good call starting this thread. If you get three different answers on a topic, the question was asked wrong.

That's all, sorry if I went on too long.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#20

Yes, that's exactly how it is with digital forensics investigation. Most time waste accumulates in tasks waiting for approval.

Having backups accessible on the same network and with the same identity makes them part of the target. That's all, sorry if I went on too long.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic