0Pricing
Production Debugging & Incident Response Playbook · درس

حفظ الأدلة وسلسلة حيازتها

تعلّم حفظ الأدلة الرقمية بطريقة صحيحة أثناء حادث أمني، بحيث تظل سليمة وقابلة للتحقق ومقبولة للاستخدام في التحقيق أو الإجراءات القانونية.

حفظ الأدلة وسلسلة حيازتها درس مجاني في Production Debugging & Incident Response Playbook على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Production Debugging & Incident Response Playbook، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Production Debugging & Incident Response Playbook 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Why Evidence Handling Matters

During a breach, the instinct is to fix and move on. But if evidence is altered or lost, you cannot prove what happened, and any legal case collapses.

This lesson covers preserving evidence with a defensible chain of custody.

Order of Volatility

Some evidence vanishes faster than others. Collect the most volatile first.

  • CPU registers and cache
  • RAM and running processes
  • Network connections
  • Disk files
  • Backups and logs (most durable)

Don't Contaminate the Scene

Every command you run changes the system. Avoid rebooting a compromised host (RAM is lost) and prefer read-only collection tools. Document every action you take so investigators can separate attacker activity from responder activity.

Creating Forensic Images

Work from a bit-for-bit copy, never the original. Capture the full disk and, where possible, memory, so analysis never touches the source.

dd if=/dev/sda of=/evidence/host01.img bs=4M conv=noerror,sync

Hashing for Integrity

A cryptographic hash proves the image has not changed. Record it at collection time; anyone can re-hash later to verify integrity.

sha256sum /evidence/host01.img > host01.img.sha256

What Chain of Custody Is

Chain of custody is an unbroken, documented record of who handled the evidence, when, why, and how it was stored. A single undocumented gap can render evidence inadmissible.

Recording Custody

Log each transfer with timestamp, person, and purpose. Keep it append-only.

2026-05-31 14:02 | A.Yilmaz | collected disk image from host01
2026-05-31 15:10 | A.Yilmaz -> B.Kaya | handed to analysis, sealed

Secure Storage

Store evidence with restricted access, encryption at rest, and write protection. Limit who can touch it and log every access. The fewer hands, the stronger the chain.

Timestamps and Time Sync

Forensic timelines depend on accurate clocks. Record the timezone, note any clock skew on the affected host, and reference an authoritative time source so events from different systems can be correlated.

Balancing Speed and Preservation

Containment and evidence preservation can conflict: pulling a host offline stops the attacker but loses live state. The compromise is to capture volatile data first (memory, connections) and then isolate.

An Evidence Workflow

Putting it together when you detect a breach:

  • Capture volatile data in order of volatility
  • Image disks read-only and hash them
  • Start a chain-of-custody log immediately
  • Store securely with restricted access
  • Then proceed with containment

Quick Check

Test your understanding of evidence preservation.

Recap

You learned to preserve digital evidence properly.

  • Collect by order of volatility and avoid contamination
  • Image read-only and hash for integrity
  • Maintain an unbroken chain of custody
  • Store securely and balance speed with preservation

الأسئلة الشائعة

هل درس «حفظ الأدلة وسلسلة حيازتها» مجاني؟

نعم — نص درس «حفظ الأدلة وسلسلة حيازتها» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Production Debugging & Incident Response Playbook، انتقل إلى CoddyKit PRO. تتضمن دورة Production Debugging & Incident Response Playbook 4 دروس في المجموع.

ماذا ستتعلم في «حفظ الأدلة وسلسلة حيازتها»؟

تعلّم حفظ الأدلة الرقمية بطريقة صحيحة أثناء حادث أمني، بحيث تظل سليمة وقابلة للتحقق ومقبولة للاستخدام في التحقيق أو الإجراءات القانونية. تتمرن على Production Debugging & Incident Response Playbook مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Production Debugging & Incident Response Playbook؟

لا تُشترط خبرة سابقة. Production Debugging & Incident Response Playbook على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «حفظ الأدلة وسلسلة حيازتها»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Production Debugging & Incident Response Playbook هذا؟

نعم. كل درس في Production Debugging & Incident Response Playbook يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. التعرّف على الاختراقات الأمنية ومؤشراتها
  2. تقنيات التحليل الجنائي الرقمي الأساسية
  3. استراتيجيات الاحتواء والاستئصال
  4. حفظ الأدلة وسلسلة حيازتها
← العودة إلى Production Debugging & Incident Response Playbook