Professional Development
Learning Computer Security Investigation and Response
A practical introduction to computer-security investigation and incident response, including forensic frameworks, evidence handling, incident-scene preservation, evidence collection and recovery, and differences in examining Windows, macOS and Linux systems.
View original PDF ↗
Context
Why I took this course
By the time I completed this course, I had already been doing data-recovery and evidence-sensitive investigative work for years. I took it as a structured refresher—a way to compare practices learned on the job with the investigation and response methods being taught at the time.
Takeaways
What I took away from it
- Incident response and evidence collection have to protect the integrity of the source material, not merely recover useful data.
- A disciplined process matters as much as the tools: preserve, collect, examine, document and report in a way another person can understand.
- The operating system and storage environment affect how evidence is collected and interpreted, so there is no single workflow that fits every case.
Experience
How it connects to my work
My recovery work has included deliberately deleted data, hidden or deleted partitions, failed storage devices and evidence-sensitive engagements where the original media needed to remain untouched whenever possible.
Where practical, I worked from a clone rather than booting the source drive, recovered material to separate media, and documented findings for clients, private investigators or law-enforcement use as appropriate.