Module 2 DF
Incidence Response Process : Introduction
People Involved in Incident Response Process:-
Here’s a medium-length point-wise answer suitable for exams on People Involved in Incident
Response Process:
· Incident response (IR) requires a multidisciplinary team; a centralized team should
be formed to handle incidents efficiently.
· All employees must understand and support the IR plan to ensure smooth emergency
procedures.
· Key members of an IR team:
1. Incident Response Manager – Leads the team, prioritizes actions, and
communicates high-severity incidents.
2. Security Analysts – Investigate affected systems; includes Triage
Analysts (initial assessment) and Forensic Analysts (deep analysis).
3. Threat Researchers – Provide threat intelligence and context by
monitoring internal and external sources.
4. Management – Supplies resources, funding, and ensures organizational
support.
5. Human Resources (HR) – Engaged when employees are involved in
incidents.
6. Public Relations (PR) – Communicates incident information accurately
to stakeholders.
7. General Counsel / Attorneys – Ensure evidence is legally admissible and
maintains forensic integrity.
8. Audit and Risk Management Specialists – Help develop threat metrics,
vulnerability assessments, and promote best practices.
· Computer Security Incident Response Team (CSIRT):
o Interdisciplinary team with technical, legal, and other expertise.
o Determines response actions based on incident severity.
1
o Serves as the initial response unit during security incidents.
Incident Response Process:-
The incident response process has six important phases: Initial Response, Investigation,
Remediation, Tracking of Significant Information, and Reporting.
1. Initial Response
This step involves assembling the response team, defining roles and responsibilities, and
gathering early information about the incident. Proper tools, policies, and communication
plans are used to ensure a quick and coordinated response to reduce damage.
2. Investigation
In this phase, the team verifies whether an incident has occurred and determines its root
cause, scope, and impact. Evidence is collected from logs, network traffic, systems, and
security tools. Chain of custody is maintained if legal action may be required.
3. Remediation
Here, the affected systems are repaired and the threat is removed. Communication is
made with impacted parties, and regulatory requirements are considered. A post-mortem
analysis may also be done to learn from the incident.
4. Tracking of Significant Investigative Information
All critical details about the investigation are tracked, such as collected evidence,
2
affected systems, attacker activity, compromised accounts, and indicators of compromise.
A proper incident numbering system is used to organize and share information easily.
5. Reporting
All incident response actions are documented with confidentiality and proper chain of
custody. Incidents are ranked by their impact, and a review is done after the investigation
to evaluate the effectiveness of the response and improve future procedures.
Incident Response Methodology:-
Incident response is a structured way to handle security incidents. The process is divided into
clear phases to avoid confusion and ensure accuracy.
1. Pre-Incident Preparation
· Prepare before incidents occur.
· Organization must set up policies, host/network security, backups, IDS, access
control, and user training.
· A CSIRT (Computer Security Incident Response Team) should be formed with
proper hardware, software, documentation, and trained staff.
3
2. Detection of Incidents
· An incident can be detected by:
o Users reporting suspicious activity,
o System administrators,
o IDS alerts, or other monitoring tools.
· Important details like time, description, and people involved must be recorded.
· Detection leads to initial response activation.
3. Initial Response
· Collect enough information before taking major action.
· CSIRT gathers logs, interviews staff, and reviews intrusion detection reports.
· Avoid panic and document steps.
· Confirm whether it’s truly an incident, identify affected systems, and estimate
business impact.
4. Formulate Response Strategy
· Decide how to respond, considering:
o Technical, legal, and business factors.
o Criticality of systems, sensitivity of data, attacker’s skill, public impact,
financial loss.
· Response options may include:
o Technical fixes (router reconfiguration, monitoring, isolation),
o Administrative action (warnings, termination),
o Legal action (civil, criminal, or law enforcement involvement).
5. Investigate the Incident
Two phases:
4
· Data Collection
o Host-based evidence: logs, backups, volatile data, forensic duplication.
o Network-based evidence: IDS, firewall, router logs, monitoring.
o Other evidence: witness statements, HR records.
· Forensic Analysis
o Review logs, system files, browser history, emails, deleted files.
o Perform keyword searches, recover hidden/encrypted data.
o Aim: figure out who, what, when, where, how, and why.
6. Reporting
· Document everything clearly and on time.
· Use a standard format for reports.
· Reports must be concise, understandable to management/legal teams, and strong
enough for legal scrutiny.
7. Resolution
· Implement security fixes and prevent recurrence.
· Steps include:
o Containment and eradication,
o Restoring systems,
o Applying patches and updates,
o Fixing systemic issues,
o Updating policies and training.
· Validate all corrective actions and record lessons learned.
Forensic Workstation
Definition
5
A Forensic Workstation is a specialized computer system used by digital forensic
investigators to analyze, recover, and preserve digital evidence from electronic devices
without altering the original data.
Purpose
● To safely examine and extract evidence from storage media (hard drives, USBs, mobile
devices).
● To perform data recovery, file analysis, and report generation in a controlled, secure
environment.
Key Features
1. High Processing Power – For analyzing large data sets and running forensic tools.
2. Write Blockers – Prevents any modification to the original evidence drive.
3. Multiple OS Support – Windows, Linux, macOS for analyzing various file systems.
4. Forensic Software Installed – Tools like EnCase, FTK, Autopsy, X-Ways.
5. Large Storage Capacity – For imaging and storing copies of evidence.
6. Secure Environment – Isolated network or offline setup to avoid tampering.
Components
● Hardware: High-speed CPU, large RAM, multiple hard drives, write blockers, external
storage devices.
● Software: Forensic imaging tools, hash calculators, file recovery utilities, report
generators
Example Tools
● EnCase
● FTK (Forensic Toolkit)
● Autopsy / Sleuth Kit
● X-Ways Forensics
● Magnet AXIOM
6
Forensic Kit
Definition
A Forensic Kit is a collection of specialized hardware and software tools used by digital
forensic investigators to collect, preserve, and analyze digital evidence from computers,
mobile devices, and networks.
Purpose
● To help investigators handle digital evidence safely and systematically.
● To ensure data integrity and maintain the chain of custody during investigation.
Types of Forensic Kits
1. Computer Forensic Kit – Used for desktops, laptops, servers.
2. Mobile Forensic Kit – For extracting data from smartphones/tablets.
3. Network Forensic Kit – For capturing and analyzing network traffic.
4. Field Forensic Kit – Portable tools for on-site investigations.
Main Components
Category Examples
Write blockers, data acquisition cables, external storage, adapters,
Hardware Tools
imaging devices, forensic laptops.
EnCase, FTK, Autopsy, X-Ways, Cellebrite (for mobile), Wireshark (for
Software Tools
network).
Accessories Evidence bags, labels, gloves, seals, documentation forms.
Power &
Universal power adapters, USB hubs, connectors.
Connectivity
7
Forensic Software
Definition
Forensic software refers to specialized applications and tools used by digital forensic experts
to collect, analyze, recover, and preserve digital evidence from computers, mobile devices, and
networks without altering the original data.
Purpose
● To acquire and analyze digital evidence safely.
● To recover deleted or hidden files.
● To trace user activity (logs, browsing history, email trails).
● To generate forensic reports for legal use.
Categories of Forensic Software
Category Function Examples
Disk/Drive Create disk images, recover
EnCase, FTK, X-Ways, Autopsy
Forensics deleted data.
Mobile Extract data from smartphones Cellebrite UFED, Oxygen Forensic
Forensics and tablets. Suite, MOBILedit
Network Capture and analyze network
Wireshark, NetworkMiner, Xplico
Forensics packets.
Memory Analyze RAM for running Volatility, Belkasoft Live RAM
Forensics processes, malware. Capturer
Recover and analyze emails and MailXaminer, Paraben Email
Email Forensics
attachments. Examiner
Internet Examine web history, cookies, Browser History Examiner,
Forensics cache, downloads. NetAnalysis
Log Analysis Detect unauthorized access,
Splunk, LogRhythm
Tools analyze system logs.
File and Data Recover and examine hidden or
Autopsy, Bulk Extractor
Analysis modified files.
🔹 Key Features
● Read-only data access (preserves evidence).
● Generate hash values (MD5/SHA) for verification.
● Detailed reporting and documentation.
8
● Support for multiple file systems and devices.
Chain of Custody (CoC)
🔹 Definition
The Chain of Custody is the systematic process of recording and maintaining the
chronological documentation of the handling of digital evidence — from its initial collection to
its final presentation in court.
It ensures that the evidence remains authentic, untampered, and legally admissible
throughout the investigation.
Purpose
The main goal of maintaining a chain of custody is to:
● Preserve the integrity and authenticity of digital evidence.
● Provide a clear trail of who collected, handled, transferred, and stored the evidence.
● Ensure that the evidence presented in court is the same as originally collected, with no
unauthorized alterations.
Steps in Chain of Custody
1. Collection:
o Evidence is identified, photographed, labeled, and recorded.
2. Preservation:
o Evidence is protected using write blockers and stored securely.
3. Transportation:
o Evidence is transferred to the forensic lab, and each movement is documented.
4. Analysis:
o Forensic experts analyze a forensic image (copy), not the original.
5. Presentation:
o Evidence and documentation are presented in court with proof of integrity.
Example
Suppose a forensic investigator seizes a suspect’s laptop during a cybercrime case:
1. Collection:
9
o Officer A collects the laptop, labels it “Evidence ID: LAP123,” notes time/date,
and photographs it.
2. Preservation:
o A write blocker is used to make a forensic image of the hard drive.
o The hash value (e.g., MD5: 5d41402abc4b2a76b9719d911017c592) is calculated.
3. Transfer:
o Officer A hands it to Forensic Analyst B. Both sign and record date/time in the
chain of custody log.
4. Storage:
o The original laptop is sealed and stored in a secure evidence locker.
5. Analysis:
o Analyst B examines the forensic image, finds incriminating emails, and records
all steps.
6. Presentation:
o In court, the analyst proves evidence integrity by showing that the hash of the
original and analyzed copy match exactly.
Dates and Time Zone & Hash Analysis in Digital Forensics
1. Dates and Time Zone Analysis
In digital forensics, date and time information plays a crucial role in reconstructing the
sequence of events.
Every digital file, log, or system record contains timestamps that indicate when a particular
action occurred — such as creation, modification, or access.
Key Components of Timestamps
1. Created Time (CT): When a file was first created.
2. Modified Time (MT): When it was last changed or edited.
3. Accessed Time (AT): When it was last opened or viewed.
Why Time Zone Matters
● Systems across different regions use different time zones.
● Investigators must convert all timestamps to a common reference (usually UTC –
Coordinated Universal Time) to ensure accurate event correlation.
● Daylight Saving Time (DST) adjustments must also be considered.
Example
10
Suppose a cyberattack occurred at 10:00 PM IST (Indian Standard Time) on Oct 30, 2025.
● IST = UTC + 5:30
● In UTC, this time would be 4:30 PM UTC.
If another log from a U.S. server shows suspicious activity at 4:30 PM UTC, the investigator
can link both events accurately, showing coordination between systems.
Hash Analysis
● Definition: Mathematical process to generate unique digital fingerprint
● Common Algorithms: MD5, SHA-1, SHA-256
● Purpose:
o Verify evidence integrity
o Detect tampering or changes
o Identify known files (via hash databases like NSRL)
It ensures data integrity — any change, even a single bit, alters the hash value.
Purpose in Forensics
● To verify evidence integrity.
● To detect file modifications or tampering.
● To identify known files using hash databases (e.g., NSRL).
Steps in Hash Analysis
1. Generate hash value (e.g., MD5/SHA-256) of a file when collected.
2. Recalculate hash after copying or transferring evidence.
3. Compare hashes — if they match, data is unaltered.
4. Use hash sets to identify known malicious or benign files.
Example
File
MD5 Hash Verification
Name
[Link] 5d41402abc4b2a76b9719d911017c5 Same before & after
cx 92 imaging
11
This confirms that no changes were made during evidence collection.
Summary
Aspect Description
Dates & Time
Help reconstruct event timelines and detect inconsistencies.
Zones
Hash Analysis Ensures digital evidence hasn’t been altered.
Maintain accuracy, reliability, and integrity in forensic
Common Goal
investigation.
File Signature Analysis
1. Definition
● File Signature Analysis is a forensic technique used to verify the true type of a file by
checking its binary signature (magic number) rather than just the file extension.
● Helps detect file tampering, renaming, or hidden malicious files.
2. Purpose
● Identify the real format of a file.
● Detect mismatches between file extension and actual content.
● Prevent attackers from disguising files (e.g., changing .exe to .jpg).
● Ensure authenticity and integrity of digital evidence.
3. How It Works
1. Every file starts with a few bytes called a magic number or file header.
2. This header identifies the file type (e.g., JPEG, PDF, DOCX).
3. Forensic tools compare the file’s actual header with its declared extension.
4. If mismatch possible tampering or renaming.
4. Tools Used
● FTK Imager
● Autopsy / Sleuth Kit
● EnCase
● Hex Editors (HxD, WinHex)
12
5. Example
● File name: [Link]
● Header bytes: FF D8 FF E0 actually a JPEG file, not a PDF.
Indicates file tampering or concealment attempt.
Details to Include in a Forensic Report
A forensic report is a structured document that summarizes the entire digital investigation
process — from evidence collection to conclusions. It serves as a legal record and must be
accurate, clear, and unbiased.
🔹 1. Title Page
● Case title and reference number
● Name and designation of investigator
● Date of report submission
🔹 2. Introduction
● Background and purpose of the investigation
● Scope and objectives (e.g., identify data breach, trace malware, etc.)
🔹 3. Authorization
● Details of the person or organization who requested the investigation
● Legal permissions or warrants obtained
🔹 4. Evidence Details
13
● Description of each evidence item (e.g., hard drive, mobile phone)
● Serial numbers and model information
● Collection method and location
● Hash values (MD5/SHA-256) for integrity verification
● Chain of custody details — who handled evidence and when
5. Tools and Techniques Used
● Software and hardware tools (e.g., Autopsy, FTK, EnCase)
● Version numbers and configurations
6. Investigation Procedure
● Step-by-step explanation of how evidence was acquired and analyzed
● Imaging, data recovery, log analysis, and hash verification processes
7. Findings
● Key evidence discovered (emails, logs, deleted files, malicious code)
● Screenshots and extracted data supporting findings 8. Analysis
● Interpretation of evidence
● Correlation between user activities and digital traces
● Explanation of how the evidence supports or disproves allegations
9. Conclusion
● Summary of overall findings
● Final opinion based on evidence (objective, not speculative)
10. Recommendations
● Preventive and corrective actions to avoid similar incidents
11. Appendices
● Supporting documents such as hash reports, logs, and screenshots
14
15