defencia/knowledge/data collection
Acquisition · Integrity · Documentation

Data Collection

Proper data collection is one of the most important things in an incident. Authorities, third parties and courts all depend on a controlled, well-documented process.

AcquisitionIntegrity

Why proper data securing matters

Data collection is one of the critical things in an attack. Authorities and third parties need to understand what happened from your collection. If the case goes to court and the process was not controlled, the case may fall.

What data do we have?

What data is available if things go wrong? You can often retrieve a computer and secure it — but what about a cloud service? Do you know how to retrieve that data, and how long the export takes? Test this before you get hit.

Questions before collecting

Describe your process — the more careful, the better the collection.

Integrity

Create a process for collecting data, store it on a solution you control, then run a tool like DirHash to calculate hash values of the collected files. Calculation time roughly mirrors copy time — it is bound by disk I/O and CPU.