CHAPTER 01 25 MIN READ BEGINNER

Digital Forensics Foundations: Legal Process, Order of Volatility & Chain of Custody

Digital forensics is the discipline of turning a compromised system into legally defensible evidence: collected, handled, and documented in a way that survives scrutiny later. This chapter lays the foundation, the branches of the field, the legal basis for collecting evidence, and the custody discipline, that every other chapter in this module (disk, Windows artifacts, memory, timeline, network, mobile and cloud, anti-forensics) builds on directly.

digital forensics process chain of custody order of volatility forensic branches

The Branches of Digital Forensics

Digital forensics is not one skill, it is a set of related disciplines, each recovering a different kind of evidence from a different kind of source. This module covers five of them in depth, one chapter or more at a time.

BranchWhat It RecoversTypical Trigger
Disk / Media ForensicsDeleted files, file system metadata, partition artifacts, slack spaceInsider misuse, data theft, ransomware post-mortem
Memory ForensicsRunning processes, injected code, encryption keys, network connections in memoryLive malware, fileless attacks, credential theft
Network ForensicsPacket captures, flow records, DNS and proxy logs, lateral movement tracesActive intrusion, exfiltration, C2 investigation
Mobile ForensicsApp data, call and message history, location history, device backupsBYOD incidents, HR investigations, device seizure
Cloud ForensicsControl-plane logs, object storage history, identity and access logs, snapshot imagesCloud account compromise, misconfigured storage, SaaS abuse
Note: this module is not the same scope as SOC Operations or Incident Response. SOC Operations covers alert triage, deciding whether something needs escalation. Incident Response owns the full incident lifecycle end to end. Digital Forensics is the deep, evidence-grade collection and analysis skillset that IR investigators draw on once an incident needs proof, not just a verdict. See SOC Operations and Incident Response for those companion modules.

Order of Volatility

Not all evidence decays at the same rate. Some data disappears the moment power is lost, other data can sit untouched on a disk for years. Collection has to move from the most volatile sources to the least, or the fast-decaying evidence is gone before anyone gets to it.

1
CPU Registers & Cache
Exists only while the CPU is executing, gone in nanoseconds.
2
Routing Tables, ARP Cache, Process Table, Kernel Stats
Live operational state, overwritten continuously by normal system activity.
3
System Memory (RAM)
Holds running processes, injected code, and keys, lost on power-off.
4
Temporary Filesystem / Swap Space
Paged-out memory contents, still tied to the running session.
5
Disk
Persistent, but still changes as the system keeps running.
6
Remote Logging & Monitoring Data
Retained on a schedule set by whoever owns that logging system.
7
Physical Configuration & Network Topology
Stable, but can change if hardware is reconfigured or replaced.
8
Archival Media & Backups
The most durable copies, but often the oldest and least current.

This ordering comes from RFC 3227, Guidelines for Evidence Collection and Archiving (February 2002), which tells collectors to work from the volatile to the less volatile in this sequence: registers and cache; routing table, ARP cache, process table, kernel statistics and memory; temporary file systems; disk; remote logging and monitoring data relevant to the system; physical configuration and network topology; archival media. The flow above splits system memory and swap out as their own steps, since in practice they are captured by separate tools, but the ranking is the RFC's.

Why order matters: imaging the disk first on a live, running system can mean the RAM gets overwritten before anyone captures it, and evidence that only ever existed in memory (an injected payload, a decryption key, a C2 connection) is lost for good.

Chain of Custody

Chain of custody is a continuous, documented record of who possessed a piece of evidence, when, and what they did with it. A gap in that record is often enough for opposing counsel or an auditor to question whether the evidence was tampered with, even if it wasn't.

FieldPurpose
Item description / identifierUniquely identifies the exact piece of evidence (serial number, case ID, label)
Collected by (name)Ties the initial acquisition to an accountable individual
Date / time of each transferEstablishes a timeline with no unexplained gaps
From / to (custodian)Shows exactly who held the evidence at every point
Purpose of transferExplains why possession changed hands (analysis, storage, court)
Location storedConfirms the evidence was kept somewhere secure and access-controlled
Hash value at each stepProves the evidence itself was never altered
Integrity verification: compute a cryptographic hash (SHA-256 is standard) at the moment of acquisition, then re-verify it at every subsequent access. For physical media, pair that with tamper-evident bags and write blockers so the original can be examined without ever being altered.

The Forensic Investigation Process

Most forensic work follows the same high-level lifecycle, regardless of which branch is involved. Each stage exists to protect the integrity of the stage before it.

1
Identification
Determine what potential evidence exists and where it lives.
2
Preservation
Protect evidence from change before it is collected.
3
Collection
Acquire the evidence using sound, repeatable methods.
4
Examination
Process the acquired evidence to surface relevant artifacts.
5
Analysis
Interpret the artifacts to answer the investigation's questions.
6
Presentation
Report findings clearly enough to support a decision or a case.

The rest of this module walks through each branch this process is applied to:

  • Disk and File System Forensics: recovering deleted files, parsing file system metadata, and reading slack space.
  • Windows Artifact Forensics: registry hives, event logs, prefetch, and other OS-level evidence.
  • Memory Forensics: capturing and analyzing RAM for processes, injected code, and live network state.
  • Timeline Analysis: correlating timestamps across sources into a single sequence of events.
  • Network Forensics: packet captures, flow data, and log-based reconstruction of network activity.
  • Mobile and Cloud Forensics: device backups, app data, and cloud control-plane evidence.
  • Anti-Forensics and Reporting: recognizing evidence tampering and writing findings up for presentation.

Key Takeaways

  • Digital forensics splits into distinct branches, disk, memory, network, mobile, and cloud, each recovering different evidence and triggered by different scenarios.
  • Evidence only remains usable later if it was collected under proper legal authority, with unbroken custody, sound methodology, and reproducible results.
  • Collection must follow order of volatility, most volatile sources (registers, memory) first, most durable (backups) last, or fast-decaying evidence is lost.
  • Chain of custody is a continuous documented record of who held evidence, when, and what they did with it, verified at each step by hashing.
  • The forensic process runs through six stages: identification, preservation, collection, examination, analysis, and presentation.
  • This module is the technical evidence-handling skillset that Incident Response investigations draw on once proof, not just triage, is required.

Knowledge Check

Click an answer to reveal the explanation.

Following order of volatility, which of these should generally be captured first on a live, running system?

Correct answer: B. RAM is far more volatile than disk or archival media, it is lost the moment power is cut, so it needs to be captured before slower-decaying sources like disk.

A chain of custody log is missing the hash value recorded at the point of collection. What does this gap put at risk?

Correct answer: B. The hash at acquisition is the baseline used to prove integrity at every later access. Without it, there is no way to demonstrate the evidence was never changed.

Which stage of the forensic investigation process comes immediately after preservation?

Correct answer: C. The six-step process runs identification, preservation, collection, examination, analysis, presentation, so collection follows directly after preservation.