0% found this document useful (0 votes)
25 views8 pages

Cyber Forensics & Auditing Study Notes

Uploaded by

Souvik Gon
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views8 pages

Cyber Forensics & Auditing Study Notes

Uploaded by

Souvik Gon
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ChatGPT - STUDY NOTES

Below are very detailed, exam-ready notes on Cyber Forensics and Auditing,
written in a clear, structured way with bold headings, emojis, examples, and funny
analogies — just as you requested.

🕵️‍♂️🔍 CYBER FORENSICS & AUDITING – SUPER


DETAILED STUDY NOTES
(With examples + analogies so easy even your sleepy 8AM lecture brain will get it!)

🧪🔐 1. Introduction to Cyber Forensics


💡 Definition
Cyber forensics (also called computer forensics) is the science of identifying,
preserving, analyzing, and presenting digital evidence in a legal context.
Think of it as being a digital Sherlock Holmes investigating crimes committed on
computers or networks.

🎯 Goals of Cyber Forensics


Preserve evidence without altering it
Analyze what happened, how, and by whom
Reconstruct timelines of events
Present evidence in a court-friendly format

📌 Analogy:
Imagine your computer is a chaotic teenage bedroom. Cyber forensics is the parent
trying to figure out:
Who ate the cookies?
When did they sneak in?
Which footprints belong to them?

🖥️💾 2. Computer Equipment and Associated Storage


Media

1/8
🧱 Types of Computer Equipment
1. Desktop Computers – Internal hard drives, RAM, USB ports
2. Laptops – Smaller storage, encryption often enabled
3. Servers – Contain large volumes of sensitive data
4. Mobile Devices – SIM cards, flash memory, app logs
5. IoT Devices – Smart bulbs, cameras, smart speakers

💽 Storage Media Types


Storage Media Description Example

HDD (Hard Disk Magnetic storage, Office PCs


Drive) large capacity

SSD (Solid State Flash storage, New laptops


Drive) faster

USB Flash Drives Portable, easy to Rogue employee


hide or destroy hiding data

Optical Discs CD, DVD Backups, archives

Cloud Storage Remote servers Google Drive, AWS S3

⚠️ Exam Tip: SSDs complicate forensics because of TRIM, which automatically deletes
blocks → making data recovery harder.

🕵️‍♀️🛠️ 3. Role of the Forensics Investigator


👨‍🔬 Primary Responsibilities
Seize devices without damaging evidence
Maintain chain of custody
Image (copy) storage in a forensically sound manner
Analyze logs, files, memory dumps
Prepare reports
Testify in court

🛡️ Required Skills
Technical knowledge (OS, networks, file systems)

2/8
Legal knowledge (privacy, warrants, admissibility of evidence)
Analytical and critical thinking

📌 Analogy:
A forensic investigator must be like a ninja librarian—silent, precise, and able to find
the exact page of a giant book where someone scribbled in the margins.

🔄📝 4. Forensics Investigation Process (The “Golden


6”)
1️⃣ Identification
Recognizing that an incident occurred.
✔ Examples: Data breach, malware outbreak, unauthorized access.
2️⃣ Preservation
Protect the evidence.
✔ Techniques: Write-blockers, isolated storage.
3️⃣ Collection
Gather digital evidence from systems, networks, logs, memory.
✔ Use imaging tools (FTK Imager, EnCase).
4️⃣ Examination
Deep dive into data — recover deleted files, analyze logs.
✔ Look for artifacts: registry keys, browser history.
5️⃣ Analysis
Interpret findings, connect the dots.
✔ Timeline reconstruction: Who logged in? From where? When?
6️⃣ Reporting
Present your findings in a structured manner.
✔ Objective, clear, non-technical when needed.
📌 Funny Analogy:
This process is like investigating who stole your lunch from the office fridge — First

3/8
you identify the missing food, then you preserve the crumbs, check CCTV, interview
suspects, analyze evidence (mustard stains!), and finally report your findings to HR.

🌐📡 5. Collecting Network-Based Evidence


🛰️ What is Network Evidence?
Data generated during communication between devices.
Includes:
Packet captures (PCAP)
Firewall logs
Router logs
Intrusion Detection System (IDS) alerts

🔧 Tools
Wireshark (packet sniffing)
tcpdump
Snort / Suricata
NetFlow analyzers

📘 Examples of Network Evidence


IP addresses used by the attacker
Suspicious outbound traffic to foreign servers
Unusual port activity (e.g., port 4444 for reverse shell)
Large data transfers at 3AM

📌 Analogy:
Collecting network evidence is like listening to hallway gossip—packets reveal who
talked to whom, what they said, and when they said it.

🧾🧑‍⚖️ 6. Writing Computer Forensics Reports


🗂️ Essential Sections
1. Executive Summary – Non-technical overview
2. Description of Items Seized
3. Tools Used (e.g., EnCase, Autopsy)

4/8
4. Methodology
5. Findings (screenshots, logs, reconstruction)
6. Conclusion
7. Chain of Custody Documentation

⚠️ Important Principles
Must be clear, objective, accurate
Avoid jargon
Ensure reproducibility

📌 Analogy:
Your report must be so clear that even someone who thinks “RAM” is a male goat can
understand what happened.

🧮📊 7. Auditing (General Concepts)


📝 What is an Audit?
A systematic evaluation of processes, controls, and compliance.
Used in finance, cybersecurity, operations, etc.

🔍 Types of IT/Cybersecurity Audits


Compliance Audit – meets standards? (e.g., ISO 27001)
Technical Audit – vulnerabilities, configurations
Process Audit – SOPs, risk management
Security Audit – policies, access controls

🎯 Audit Objectives
Verify compliance
Identify risks
Strengthen internal controls

📌 Analogy:
An audit is like a surprise visit from your mom:
She checks if your room is clean, if you're eating properly, and if you're following the
“House Rules Standard 101.”

5/8
🗂️📏 8. How to Plan an Audit Against a Set of Criteria
🧭 Steps
1. Define Scope
What is being audited? (Network? HR systems? Entire ISMS?)
2. Identify Criteria
Standards like ISO 27001, NIST, internal policies.
3. Develop an Audit Plan
Objectives
Resources
Team members
Timelines
4. Identify Evidence Needed
Logs, documents, configurations, access lists.
5. Create Checklists
Based on controls or standards.
6. Communicate with Stakeholders
7. Execute Audit
8. Report Findings

📌 Analogy:
Planning an audit is like preparing for a road trip:
You need a map (criteria), a destination (objective), a checklist (snacks!), and a
timeline (how long till you run out of petrol?).

🔐📘 9. Information Security Management System


(ISMS) Management
🛡️ What is ISMS?
A framework for managing an organization’s information security.
It ensures:
Confidentiality (no one snoops)
Integrity (data isn't modified)
Availability (systems up when needed)

🔄 Key Components
6/8
Security policies
Risk assessment
Risk treatment
Controls implementation
Internal audits
Continual improvement

📌 Analogy:
Think of ISMS as the “diet + gym routine” of an organization — consistent,
disciplined, and meant to prevent disasters (like jeans not fitting).

📜🔐 10. Introduction to ISO 27001:2013


💡 What is ISO 27001?
A globally recognized standard for managing information security.
It outlines controls, requirements, and best practices for securing information
assets.

🧱 Three Major Parts


1. ISMS Requirements (Clauses 4–10)
2. Annex A – 114 Controls in 14 domains
3. Risk Management Framework

🧰 Examples of Annex A Domains


A.5 Information Security Policies
A.7 Human Resource Security
A.9 Access Control
A.12 Operations Security
A.13 Communications Security
A.16 Incident Management

🎯 Purpose of ISO 27001


Build trust with customers
Reduce security risks
Ensure legal compliance
Improve internal processes

7/8
📌 Funny Analogy:
ISO 27001 is like the “How to Adult Properly” manual for organizations—
It tells them how to avoid disasters like leaving passwords on sticky notes or giving
admin access to the intern.

🎉 DONE!
If you want, I can also create:
✅ Flashcards
✅ Mock exam questions
✅ Mind maps
✅ Simplified summaries
Just tell me!

8/8

You might also like