Technical Procedures
Endpoint Forensics Collection
Guide for collecting forensic artifacts from endpoints while maintaining evidence integrity.
Technical Procedures · intermediate · 2-4 hours per system
Procedures for forensic evidence collection from Windows and Linux endpoints.
Steps
5
01
Preparation
Prepare for forensic collection.
- Gather forensic tools and storage media
- Verify chain of custody procedures
- Document initial system state
- Plan collection order of volatility
KAPE · Velociraptor · FTK Imager · Forensic workstation
02
Volatile Data Collection
Collect volatile data first.
- Capture system memory
- Document running processes
- Capture network connections
- Document logged-in users
03
Non-Volatile Collection
Collect persistent artifacts.
- Collect event logs
- Capture registry hives
- Collect browser artifacts
- Capture prefetch/superfetch data
- Collect scheduled tasks
- Capture startup items
04
Full Disk Imaging
Create forensic disk image if needed.
- Use write blocker if collecting from live system
- Create forensic image (E01 or dd)
- Hash original and image
- Verify image integrity
05
Documentation
Document collection activities.
- Complete chain of custody form
- Document all tools and versions used
- Record collection timeline
- Store evidence securely
Checklist
- Collection authorized
- Tools prepared and validated
- Volatile data collected first
- Memory captured
- Event logs collected
- Registry collected
- Browser artifacts collected
- Full disk imaged (if needed)
- Hashes verified
- Chain of custody documented
- Evidence stored securely
Evidence
- Memory dump
- Event logs
- Registry hives
- Browser artifacts
- Disk image (if applicable)
- Hash values
- Chain of custody forms