Conservazione delle prove e catena di custodia
Imparate a conservare correttamente le prove digitali durante un incidente di sicurezza, affinché rimangano integre, verificabili e ammissibili per un’indagine o un’azione legale.
Conservazione delle prove e catena di custodia è una lezione Production Debugging & Incident Response Playbook gratuita su CoddyKit. Questa è la lezione 4 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Production Debugging & Incident Response Playbook, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Production Debugging & Incident Response Playbook include 4 lezioni in totale.
Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.
Why Evidence Handling Matters
During a breach, the instinct is to fix and move on. But if evidence is altered or lost, you cannot prove what happened, and any legal case collapses.
This lesson covers preserving evidence with a defensible chain of custody.
Order of Volatility
Some evidence vanishes faster than others. Collect the most volatile first.
- CPU registers and cache
- RAM and running processes
- Network connections
- Disk files
- Backups and logs (most durable)
Don't Contaminate the Scene
Every command you run changes the system. Avoid rebooting a compromised host (RAM is lost) and prefer read-only collection tools. Document every action you take so investigators can separate attacker activity from responder activity.
Creating Forensic Images
Work from a bit-for-bit copy, never the original. Capture the full disk and, where possible, memory, so analysis never touches the source.
dd if=/dev/sda of=/evidence/host01.img bs=4M conv=noerror,syncHashing for Integrity
A cryptographic hash proves the image has not changed. Record it at collection time; anyone can re-hash later to verify integrity.
sha256sum /evidence/host01.img > host01.img.sha256What Chain of Custody Is
Chain of custody is an unbroken, documented record of who handled the evidence, when, why, and how it was stored. A single undocumented gap can render evidence inadmissible.
Recording Custody
Log each transfer with timestamp, person, and purpose. Keep it append-only.
2026-05-31 14:02 | A.Yilmaz | collected disk image from host01
2026-05-31 15:10 | A.Yilmaz -> B.Kaya | handed to analysis, sealedSecure Storage
Store evidence with restricted access, encryption at rest, and write protection. Limit who can touch it and log every access. The fewer hands, the stronger the chain.
Timestamps and Time Sync
Forensic timelines depend on accurate clocks. Record the timezone, note any clock skew on the affected host, and reference an authoritative time source so events from different systems can be correlated.
Balancing Speed and Preservation
Containment and evidence preservation can conflict: pulling a host offline stops the attacker but loses live state. The compromise is to capture volatile data first (memory, connections) and then isolate.
An Evidence Workflow
Putting it together when you detect a breach:
- Capture volatile data in order of volatility
- Image disks read-only and hash them
- Start a chain-of-custody log immediately
- Store securely with restricted access
- Then proceed with containment
Quick Check
Test your understanding of evidence preservation.
Recap
You learned to preserve digital evidence properly.
- Collect by order of volatility and avoid contamination
- Image read-only and hash for integrity
- Maintain an unbroken chain of custody
- Store securely and balance speed with preservation
Impara Production Debugging & Incident Response Playbook con un tutor IA — gratis
Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.
- Corsi
- 12
- Lezioni
- 48
Domande Frequenti
La lezione «Conservazione delle prove e catena di custodia» è gratuita?
Sì — il testo completo di «Conservazione delle prove e catena di custodia» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Production Debugging & Incident Response Playbook, passa a CoddyKit PRO. Il corso Production Debugging & Incident Response Playbook include 4 lezioni in totale.
Cosa imparerò in «Conservazione delle prove e catena di custodia»?
Imparate a conservare correttamente le prove digitali durante un incidente di sicurezza, affinché rimangano integre, verificabili e ammissibili per un’indagine o un’azione legale. Eserciti Production Debugging & Incident Response Playbook con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.
Ho bisogno di esperienza per iniziare Production Debugging & Incident Response Playbook?
Non è richiesta alcuna esperienza precedente. Production Debugging & Incident Response Playbook su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 4 di 4.
Quanto tempo richiede la lezione «Conservazione delle prove e catena di custodia»?
La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.
Posso scrivere ed eseguire codice in questa lezione Production Debugging & Incident Response Playbook?
Sì. Ogni lezione Production Debugging & Incident Response Playbook include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.
Tutte le lezioni di questo corso
- Riconoscere violazioni della sicurezza e indicatori
- Tecniche fondamentali di digital forensics
- Strategie di contenimento ed eradicazione
- Conservazione delle prove e catena di custodia