0Pricing
Production Debugging & Incident Response Playbook · Lesson

Evidence Preservation and Chain of Custody

Learn to preserve digital evidence correctly during a security incident so it remains intact, verifiable, and admissible for investigation or legal action.

Evidence Preservation and Chain of Custody is a free Production Debugging & Incident Response Playbook lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Production Debugging & Incident Response Playbook learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Why Evidence Handling Matters

During a breach, the instinct is to fix and move on. But if evidence is altered or lost, you cannot prove what happened, and any legal case collapses.

This lesson covers preserving evidence with a defensible chain of custody.

Order of Volatility

Some evidence vanishes faster than others. Collect the most volatile first.

  • CPU registers and cache
  • RAM and running processes
  • Network connections
  • Disk files
  • Backups and logs (most durable)

Don't Contaminate the Scene

Every command you run changes the system. Avoid rebooting a compromised host (RAM is lost) and prefer read-only collection tools. Document every action you take so investigators can separate attacker activity from responder activity.

Creating Forensic Images

Work from a bit-for-bit copy, never the original. Capture the full disk and, where possible, memory, so analysis never touches the source.

dd if=/dev/sda of=/evidence/host01.img bs=4M conv=noerror,sync

Hashing for Integrity

A cryptographic hash proves the image has not changed. Record it at collection time; anyone can re-hash later to verify integrity.

sha256sum /evidence/host01.img > host01.img.sha256

What Chain of Custody Is

Chain of custody is an unbroken, documented record of who handled the evidence, when, why, and how it was stored. A single undocumented gap can render evidence inadmissible.

Recording Custody

Log each transfer with timestamp, person, and purpose. Keep it append-only.

2026-05-31 14:02 | A.Yilmaz | collected disk image from host01
2026-05-31 15:10 | A.Yilmaz -> B.Kaya | handed to analysis, sealed

Secure Storage

Store evidence with restricted access, encryption at rest, and write protection. Limit who can touch it and log every access. The fewer hands, the stronger the chain.

Timestamps and Time Sync

Forensic timelines depend on accurate clocks. Record the timezone, note any clock skew on the affected host, and reference an authoritative time source so events from different systems can be correlated.

Balancing Speed and Preservation

Containment and evidence preservation can conflict: pulling a host offline stops the attacker but loses live state. The compromise is to capture volatile data first (memory, connections) and then isolate.

An Evidence Workflow

Putting it together when you detect a breach:

  • Capture volatile data in order of volatility
  • Image disks read-only and hash them
  • Start a chain-of-custody log immediately
  • Store securely with restricted access
  • Then proceed with containment

Quick Check

Test your understanding of evidence preservation.

Recap

You learned to preserve digital evidence properly.

  • Collect by order of volatility and avoid contamination
  • Image read-only and hash for integrity
  • Maintain an unbroken chain of custody
  • Store securely and balance speed with preservation

Frequently asked questions

Is the “Evidence Preservation and Chain of Custody” lesson free?

Yes — the full text of “Evidence Preservation and Chain of Custody” is free to read here on the web, and the Production Debugging & Incident Response Playbook course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Production Debugging & Incident Response Playbook course, upgrade to CoddyKit PRO.

What will I learn in “Evidence Preservation and Chain of Custody”?

Learn to preserve digital evidence correctly during a security incident so it remains intact, verifiable, and admissible for investigation or legal action. You practise Production Debugging & Incident Response Playbook with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Production Debugging & Incident Response Playbook?

No prior experience is required. Production Debugging & Incident Response Playbook on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Evidence Preservation and Chain of Custody” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Production Debugging & Incident Response Playbook lesson?

Yes. Every Production Debugging & Incident Response Playbook lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Recognizing Security Breaches and Indicators
  2. Basic Digital Forensic Techniques
  3. Containment and Eradication Strategies
  4. Evidence Preservation and Chain of Custody
← Back to Production Debugging & Incident Response Playbook