From the course: Incident Response: Evidence Collection in Windows

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Preparing your evidence collection drive

Preparing your evidence collection drive

From the course: Incident Response: Evidence Collection in Windows

Start my 1-month free trial

Preparing your evidence collection drive

- [Instructor] Part of our preparation phase is making sure all of our tools are ready to go. So, one of the things we need to do is make sure that we have hard drives that are for us to collect evidence on. Before we can collect evidence onto a hard drive, though, we have to know the contents of that hard drive. So, I'm going to use a USB thumb stick here and connect it to my Windows 10 machine. Let's take a look at this. It's going to pop up and you're going to see that this D drive, this 64 gigabyte thumb drive, does have some folders on it that has files and stuff like that. Now, this is not a well-prepared thumb drive because there's things on it. Now, you can't just simply take this and delete it and empty the trash because there's still going to be residual on that hard drive or USB thumb stick. So, instead, what we need to do to properly format this, so that it's ready for us to use in a forensic investigation, is…

Contents