Pelestarian Bukti dan Rantai Penguasaan
Pelajari cara melestarikan bukti digital dengan benar selama insiden keamanan agar tetap utuh, dapat diverifikasi, dan dapat diterima untuk penyelidikan atau tindakan hukum.
Pelestarian Bukti dan Rantai Penguasaan adalah pelajaran Production Debugging & Incident Response Playbook gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Production Debugging & Incident Response Playbook, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Production Debugging & Incident Response Playbook mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Why Evidence Handling Matters
During a breach, the instinct is to fix and move on. But if evidence is altered or lost, you cannot prove what happened, and any legal case collapses.
This lesson covers preserving evidence with a defensible chain of custody.
Order of Volatility
Some evidence vanishes faster than others. Collect the most volatile first.
- CPU registers and cache
- RAM and running processes
- Network connections
- Disk files
- Backups and logs (most durable)
Don't Contaminate the Scene
Every command you run changes the system. Avoid rebooting a compromised host (RAM is lost) and prefer read-only collection tools. Document every action you take so investigators can separate attacker activity from responder activity.
Creating Forensic Images
Work from a bit-for-bit copy, never the original. Capture the full disk and, where possible, memory, so analysis never touches the source.
dd if=/dev/sda of=/evidence/host01.img bs=4M conv=noerror,syncHashing for Integrity
A cryptographic hash proves the image has not changed. Record it at collection time; anyone can re-hash later to verify integrity.
sha256sum /evidence/host01.img > host01.img.sha256What Chain of Custody Is
Chain of custody is an unbroken, documented record of who handled the evidence, when, why, and how it was stored. A single undocumented gap can render evidence inadmissible.
Recording Custody
Log each transfer with timestamp, person, and purpose. Keep it append-only.
2026-05-31 14:02 | A.Yilmaz | collected disk image from host01
2026-05-31 15:10 | A.Yilmaz -> B.Kaya | handed to analysis, sealedSecure Storage
Store evidence with restricted access, encryption at rest, and write protection. Limit who can touch it and log every access. The fewer hands, the stronger the chain.
Timestamps and Time Sync
Forensic timelines depend on accurate clocks. Record the timezone, note any clock skew on the affected host, and reference an authoritative time source so events from different systems can be correlated.
Balancing Speed and Preservation
Containment and evidence preservation can conflict: pulling a host offline stops the attacker but loses live state. The compromise is to capture volatile data first (memory, connections) and then isolate.
An Evidence Workflow
Putting it together when you detect a breach:
- Capture volatile data in order of volatility
- Image disks read-only and hash them
- Start a chain-of-custody log immediately
- Store securely with restricted access
- Then proceed with containment
Quick Check
Test your understanding of evidence preservation.
Recap
You learned to preserve digital evidence properly.
- Collect by order of volatility and avoid contamination
- Image read-only and hash for integrity
- Maintain an unbroken chain of custody
- Store securely and balance speed with preservation
Belajar Production Debugging & Incident Response Playbook dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “Pelestarian Bukti dan Rantai Penguasaan” gratis?
Ya — teks lengkap “Pelestarian Bukti dan Rantai Penguasaan” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Production Debugging & Incident Response Playbook, upgrade ke CoddyKit PRO. Kursus Production Debugging & Incident Response Playbook mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “Pelestarian Bukti dan Rantai Penguasaan”?
Pelajari cara melestarikan bukti digital dengan benar selama insiden keamanan agar tetap utuh, dapat diverifikasi, dan dapat diterima untuk penyelidikan atau tindakan hukum. Kamu berlatih Production Debugging & Incident Response Playbook dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai Production Debugging & Incident Response Playbook?
Tidak diperlukan pengalaman sebelumnya. Production Debugging & Incident Response Playbook di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.
Berapa lama pelajaran “Pelestarian Bukti dan Rantai Penguasaan” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran Production Debugging & Incident Response Playbook ini?
Ya. Setiap pelajaran Production Debugging & Incident Response Playbook menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- Mengenali Pelanggaran Keamanan dan Indikatornya
- Teknik Dasar Forensik Digital
- Strategi Penahanan dan Pemberantasan
- Pelestarian Bukti dan Rantai Penguasaan