<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>geschonneck.com &#187; Guidelines</title>
	<atom:link href="http://geschonneck.com/category/forensics/guidelines/feed/" rel="self" type="application/rss+xml" />
	<link>http://geschonneck.com</link>
	<description>This is the private security page of Alexander Geschonneck (Berlin, Germany).</description>
	<lastBuildDate>Tue, 23 Dec 2008 20:32:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Oracle Database Forensics</title>
		<link>http://geschonneck.com/2007/08/14/oracle-database-forensics/</link>
		<comments>http://geschonneck.com/2007/08/14/oracle-database-forensics/#comments</comments>
		<pubDate>Tue, 14 Aug 2007 08:16:28 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Guidelines]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[database forensics]]></category>
		<category><![CDATA[oracle forensics]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/08/14/oracle-database-forensics/</guid>
		<description><![CDATA[David Litchfield from NGSSoftware published some new material about Oracle Database Forensics. You can download his whitepaper and the Black Hat slides here.]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/database_error.png" title="icon" alt="icon" height="16" hspace="3" width="16" />David Litchfield from NGSSoftware published some new material about Oracle Database Forensics. <span id="more-129"></span>You can download his whitepaper and the Black Hat slides <a href="http://www.databasesecurity.com/oracle-forensics.htm" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/08/14/oracle-database-forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Good Practice Guide for Computer-Based Electronic Evidence</title>
		<link>http://geschonneck.com/2007/07/31/good-practice-guide-for-computer-based-electronic-evidence/</link>
		<comments>http://geschonneck.com/2007/07/31/good-practice-guide-for-computer-based-electronic-evidence/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 10:25:56 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Guidelines]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[electronic evidence]]></category>
		<category><![CDATA[evidence seizure]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/07/31/good-practice-guide-for-computer-based-electronic-evidence/</guid>
		<description><![CDATA[The english Association of Chief Police Officers (ACPO) has released a new guide to collecting electronic evidence. The Good Practice Guide for Computer-Based Electronic Evidence has been revised by experts. The guidelines relate to: Personnel attending crime scenes or making initial contact with a victim/witness/suspect Investigators Evidence recovery staff External consulting witnesses The Good Practice [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/acpo_logo.gif" title="ACPO Logo" alt="ACPO Logo" align="right" height="72" width="71" />The english Association of Chief Police Officers (<a href="http://www.acpo.police.uk" target="_blank">ACPO</a>) has released a new guide to collecting electronic evidence.  The Good Practice Guide for Computer-Based Electronic Evidence has been revised by experts.<span id="more-125"></span></p>
<p>The guidelines relate to:</p>
<ul>
<li>Personnel attending crime scenes or making initial contact with a victim/witness/suspect</li>
<li> Investigators</li>
<li>Evidence recovery staff</li>
<li>External consulting witnesses</li>
</ul>
<p>The Good Practice Guide contains the following chapters:</p>
<p>Introduction<br />
The principles of computer-based electronic evidence<br />
Overview of computer-based electronic investigations<br />
Crime scenes<br />
Home networks &amp; wireless technology<br />
Network forensics &amp; volatile data<br />
Investigating personnel<br />
Evidence recovery<br />
Welfare in the workplace<br />
Control of paedophile images<br />
External consulting witnesses &amp; forensic contractors<br />
Disclosure<br />
Retrieval of video &amp; CCTV evidence<br />
Guide for mobile phone seizure &amp; examination<br />
Initial contact with victims: suggested questions<br />
Glossary and explanation of terms<br />
Legislation<br />
Local Hi-Tech Crime Units</p>
<p>You can download the Good Practice Guide for Computer-Based Electronic Evidence <a href="http://www.7safe.com/electronic%5Fevidence/ACPO_guidelines_computer_evidence.pdf" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/07/31/good-practice-guide-for-computer-based-electronic-evidence/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Fundamental Computer Investigation Guide For Windows</title>
		<link>http://geschonneck.com/2007/01/30/fundamental-computer-investigation-guide-for-windows/</link>
		<comments>http://geschonneck.com/2007/01/30/fundamental-computer-investigation-guide-for-windows/#comments</comments>
		<pubDate>Mon, 29 Jan 2007 23:11:34 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Guidelines]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[digital investigations]]></category>
		<category><![CDATA[windows forensics]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/01/30/fundamental-computer-investigation-guide-for-windows/</guid>
		<description><![CDATA[Microsoft published their &#8220;Fundamental Computer Investigation Guide For Windows&#8221;. The paper discusses processes and tools for use in internal computer investigations for windows systems. You can find the guide here. The table of content of the document: Overview.. 1 Computer Investigation Model 1 Initial Decision-Making Process. 2 Chapter Summary. 3 Audience. 3 Caveats and Disclaimers. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/zoom.png" title="icon" alt="icon" align="absmiddle" height="16" hspace="3" width="16" />Microsoft published their &#8220;Fundamental Computer Investigation Guide For Windows&#8221;. The paper discusses processes and tools for use in internal computer investigations for windows systems.</p>
<p><span id="more-108"></span>You can find the guide <a href="http://www.microsoft.com/technet/security/guidance/disasterrecovery/computer_investigation/default.mspx" target="_blank">here</a>.</p>
<p>The table of content of the document:</p>
<p class="MsoToc1"><!--[if supportFields]><span lang=EN-US style='font-weight: normal'></span><span style='mso-element:field-begin'></span><span style='mso-spacerun:yes'> </span>TOC \o &quot;1-3&quot; \h \z <span style='mso-element:field-separator'></span>< ![endif]--><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Overview</span><span style="color: black; display: none; text-decoration: none"></span><span>.. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780488 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">1</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400380038000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Computer Investigation Model</span><span style="color: black; display: none; text-decoration: none"></span><span> </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780489 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">1</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400380039000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Initial Decision-Making Process</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780490 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">2</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390030000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Chapter Summary</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780491 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">3</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390031000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Audience</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780492 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">3</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390032000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Caveats and Disclaimers</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780493 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">3</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390033000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">References and Credits</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780494 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">4</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390034000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Style Conventions</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780495 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">4</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390035000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US"></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Support and Feedback</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780496 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">4</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390036000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Chapter 1: Assess the Situation</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780497 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">5</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390037000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Notify Decision Makers and Acquire Authorization</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780498 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">5</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390038000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Review Policies and Laws</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780499 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">6</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003400390039000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Identify Investigation Team Members</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780500 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">7</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300030000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Conduct a Thorough Assessment</span><span style="color: black; display: none; text-decoration: none"></span><span> </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780501 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">7</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300031000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Prepare for Evidence Acquisition</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780502 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">9</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300032000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Chapter 2: Acquire the Data</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780503 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">11</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300033000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Build a Computer Investigation Toolkit</span><span style="color: black; display: none; text-decoration: none"></span><span> </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780504 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">11</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300034000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Collect the Data</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780505 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">11</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300035000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Store and Archive</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780506 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">13</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300036000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Chapter 3: Analyze the Data</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780507 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">15</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300037000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Analyze Network Data</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780508 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">15</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300038000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Analyze Host Data</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780509 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">16</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500300039000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Analyze Storage Media</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780510 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">16</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310030000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Chapter 4: Report the Investigation</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780511 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">19</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310031000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Gather and Organize Information</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780512 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">19</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310032000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Write the Report</span><span style="color: black; display: none; text-decoration: none"></span><span> </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780513 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">20</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310033000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Chapter 5: Applied Scenario Example</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780514 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">23</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310034000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Scenario</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780515 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">23</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310035000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Assess the Situation</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780516 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">24</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310036000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Acquire Evidence of Confidential Data Access</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780517 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">25</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310037000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Remote Evidence Collection</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780518 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">28</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310038000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Local Evidence Collection</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780519 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">30</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500310039000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Analyze Collected Evidence</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780520 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">33</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320030000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Report the Evidence</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780521 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">36</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320031000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Applied Scenario Lab Configuration</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780522 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">37</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320032000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Deploy Computers and Create Domain</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780523 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">37</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320033000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Create Users and Groups</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780524 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">37</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320034000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Create Folders and Files</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780525 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">38</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320035000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Assign Sharing and Permissions</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780526 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">39</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320036000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Configure Auditing</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780527 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">39</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320037000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--></li>
</ul>
</li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Appendix: Resources</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780528 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">41</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320038000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Preparing Your Organization for a Computer Investigation</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780529 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">41</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500320039000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Worksheets and Samples</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780530 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">42</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330030000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Reporting Computer-Related Crimes</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780531 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">42</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330031000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Local Law Enforcement Agencies</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780532 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">43</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330032000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
</li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Training</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780533 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">45</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330033000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Tools</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780534 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">45</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330034000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span>
<ul>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Windows Sysinternals Tools</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780535 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">46</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330035000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
<li><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Windows Tools</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780536 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">49</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330036000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></li>
</ul>
</li>
</ul>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Acknowledgments</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780537 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">53</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330037000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<p class="MsoToc1"><span class="MsoHyperlink"></span><span style="font-family: Verdana" lang="EN-US">Index</span><span style="color: black; display: none; text-decoration: none"></span><span>. </span><!--[if supportFields]><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-begin'></span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'> PAGEREF _Toc155780538 \h </span><span style='mso-bidi-font-family:Arial;color:black;display:none;mso-hide:screen; text-decoration:none;text-underline:none'></span><span style='mso-element:field-separator'></span>< ![endif]--><span style="color: black; display: none; text-decoration: none">55</span><span style="color: black; display: none; text-decoration: none"><!--[if gte mso 9]><xml>  <w :data>08D0C9EA79F9BACE118C8200AA004BA90B02000000080000000E0000005F0054006F0063003100350035003700380030003500330038000000</w> </xml>< ![endif]--></span><!--[if supportFields]><span style='mso-bidi-font-family: Arial;color:black;display:none;mso-hide:screen;text-decoration:none;text-underline: none'></span><span style='mso-element:field-end'></span>< ![endif]--><span style="font-size: 12pt" lang="EN-US"><o></o></span></p>
<p><!--[if supportFields]><b style='mso-bidi-font-weight:normal'><span lang=EN-US style='font-size:9.0pt;font-family:Verdana;mso-fareast-font-family:"Times New Roman"; mso-bidi-font-family:Arial;mso-font-kerning:12.0pt;mso-ansi-language:EN-US; mso-fareast-language:EN-US;mso-bidi-language:AR-SA'></span><span style='mso-element: field-end'></span></b>< ![endif]--></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/01/30/fundamental-computer-investigation-guide-for-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIST Draft on Cell Phone Forensics</title>
		<link>http://geschonneck.com/2006/09/06/nist-draft-on-cell-phone-forensics/</link>
		<comments>http://geschonneck.com/2006/09/06/nist-draft-on-cell-phone-forensics/#comments</comments>
		<pubDate>Wed, 06 Sep 2006 06:20:14 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Guidelines]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[cell phone forensics]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[NIST]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2006/09/06/nist-draft-on-cell-phone-forensics/</guid>
		<description><![CDATA[NIST recently published a new draft on Cell Phone Forensics for public comment. Download here.]]></description>
			<content:encoded><![CDATA[<p>NIST recently published a new draft on Cell Phone Forensics for public comment.<br />
Download <a href="http://csrc.nist.gov/publications/drafts/Draft-SP800-101.pdf" target="_blank">here</a>.</p>
<p style="text-align: center"><img src="/images/linie.gif" alt="line" /></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2006/09/06/nist-draft-on-cell-phone-forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
