Complete all required fields in the Documentation System tab and submit.
4. Document evidence handling procedures
Show Hint
Drag and drop the procedure steps into the correct order.
5. Create write-blocker verification log
Show Hint
Use: verify-write-blocker /dev/sda
6. Transfer evidence and update custody log
Show Hint
Use: transfer-evidence --to "Lab Technician" and update the custody form.
7. Verify evidence integrity after transfer
Show Hint
Use: sha256sum evidence.img and compare with original hash.
8. Prepare evidence summary for legal review
Show Hint
Use: generate-evidence-summary
Evidence Terminal
Documentation System
Digital Forensics Evidence Terminal
Case: IR-2024-0211-BREACH
Evidence Device: /dev/sda (500GB SSD)
Examiner: SOC-Analyst-001
Type 'help' for available commands
forensics@evidence:~$
Chain of Custody Form
Chain of Custody Log
Date/Time
Handler
Action
Location
Hash Verification
-
-
-
-
-
Evidence Handling Procedure Order
Drag and drop the steps below into the correct order, then click "Verify Order"