Digital-Forensics-Discord-Server / TheHitchhikersGuidetoDFIRExperiencesFromBeginnersandExperts

The official repo for a project involving a crowdsourced DFIR book. The main purpose of this book is to give anyone interested an opportunity to write a chapter of a book to get their name out there, get a publication on their resume with an actual ISBN number, and ideally lower the bar for people to contribute something back to the DFIR Community. Want to write a chapter? Let me know and let's make it happen!
MIT License
191 stars 22 forks source link

Chapter 7: Setting up a Law Enforcement Digital Forensics Lab #20

Closed AndrewRathbun closed 2 years ago

AndrewRathbun commented 2 years ago

Chapter by Jason Wilkins

FirmskyA commented 2 years ago

A nice article and PDF that was published from the ForMobile project regarding validation would sit nicely within this chapter:

Article link https://www.cencenelec.eu/news-and-events/news/2022/eninthespotlight/2022-04-12-for-mobile/

Download link https://www.cencenelec.eu/media/CEN-CENELEC/CWAs/RI/cwa17865_2022.pdf

Br3W7h1S commented 2 years ago

A nice article and PDF that was published from the ForMobile project regarding validation would sit nicely within this chapter:

Article link https://www.cencenelec.eu/news-and-events/news/2022/eninthespotlight/2022-04-12-for-mobile/

Download link https://www.cencenelec.eu/media/CEN-CENELEC/CWAs/RI/cwa17865_2022.pdf

Nice link! Very appropriate, and a good shout :)

jdwilkins75 commented 2 years ago

Outline committed.

awfr commented 2 years ago

I think it is beneficial to include some guidance on the process of having a defense expert at the law enforcement office to conduct an examination where sensitive information or contraband (child porn) is involved. For 10+ years I've performed these examinations at local sheriff's offices, FBI, HSI, etc. I have a process that has worked in most situations. I've also seen some security issues at law enforcement while conducting examinations. I think this chapter would be a good place to insert this information. Let me know if the author is open to collaborating or if you think there is a better place for this.

AndrewRathbun commented 2 years ago

Hey there! I'm tentatively setting 7/31/2022 as a milestone for publishing v1.0 of this book. We'll have the title decided in the next couple weeks which will be the first of multiple administrative tasks we'll complete in July. At this point, please let me know if you intend to have at least a working, editable version of your chapter by 7/31/2022.

If not, please know that's perfectly fine. It doesn't mean your chapter won't get published, it just won't get published in v1.0. It'll simply be added when it's ready to be published and I'll push out a new version of the book, (i.e., V1.3, v1.7, etc) with your new content. I hope we have about 10 ready to go by 7/31/2022 so we can push to publish v1.0 shortly thereafter, but I won't know that until I hear from you! So, please let me know!

jdwilkins75 commented 2 years ago

I will have it completed before then. I am going to be fleshing out the outline over the next several days and will have a final draft ready by next weekend. Thanks for the patience!

jdwilkins75 commented 2 years ago

I think it is beneficial to include some guidance on the process of having a defense expert at the law enforcement office to conduct an examination where sensitive information or contraband (child porn) is involved. For 10+ years I've performed these examinations at local sheriff's offices, FBI, HSI, etc. I have a process that has worked in most situations. I've also seen some security issues at law enforcement while conducting examinations. I think this chapter would be a good place to insert this information. Let me know if the author is open to collaborating or if you think there is a better place for this.

Thank you Aaron! That is a very welcome suggestion. If you wouldn't mind giving me some more information on just what you have done in the past, I will use that to add to my chapter.

My email: jasonwilkins@outlook.com

Thanks again!

AndrewRathbun commented 2 years ago

cc: @awfr

AndrewRathbun commented 2 years ago

@jdwilkins75 nice work on this one. I just finished doing my run through of edits for your chapter.

https://github.com/Digital-Forensics-Discord-Server/TheHitchhikersGuidetoDFIRExperiencesFromBeginnersandExperts/commit/28fe9d3c12569d4d0a14333a5df943c1fbe13fdc for reference