Common Evidence Collection Mistakes
Common Evidence Collection Mistakes
Avoid these pitfalls during evidence collection:
- Running antivirus on evidence: May delete crucial artifacts
- Booting suspect systems: Alters timestamps and data
- Using original evidence for analysis: Always work on copies
- Poor documentation: Inadequate notes compromise investigations
- Breaking chain of custody: Gaps in documentation
- Improper tool usage: Using unvalidated or inappropriate tools
- Ignoring volatile evidence: Focusing only on disk images