Procedures for forensic evidence collection from Windows and Linux endpoints.
Guide for collecting forensic artifacts from endpoints while maintaining evidence integrity.
Prepare for forensic collection.
Collect volatile data first.
Collect persistent artifacts.
Create forensic disk image if needed.
Document collection activities.