Is anyone using a check list for processing a case using FTK or EnCase. If so, would you be willing to share your procedure.
Greetings,
Here is a slightly old workflow document I developed for EnCase. It is *just* a guideline - I always deviate from it to some degree depending on the investigation.
https://
-David
The Official EnCase Certified Examiner Study Guide (ISBN-10 0470901063) from Steve Bunting suggests a decent generic process for EnCase in the final chapter. Clearly this can be easily adapted for FTK as clearly your methodology is king.
Thanks Fab4 and Kovar, I'll check out the link and look into Steve Bunting's article. Since both cover Encase - I would like to see what others have for FTK.