Fraud & Financial Crime¶
212 investigator questions.
Use the list below or search the complete library.
- A live device, account or digital system may be relevant to my investigation — where do I start?
- What is digital first response?
- What is preservation?
- What is the difference between preservation and acquisition?
- What is the difference between acquisition and examination?
- What is volatile digital evidence?
- What should I record before touching anything?
- What should I photograph or capture first?
- What identifiers should be preserved immediately?
- What questions should I ask the person who found or controls the system?
- When should I avoid interacting with the device or account?
- When should immediate intervention take priority over preservation?
- How should I document an urgent first-response decision?
- When should I stop and seek specialist support?
- Why is the original state important?
- What should be recorded about the screen?
- What should be recorded about power and battery state?
- What should be recorded about network connectivity?
- What should be recorded about logged-in accounts?
- What should be recorded about open applications?
- What should be recorded about notifications?
- What should be recorded about date, time and time zone?
- What should be recorded about connected cables and peripherals?
- What should be recorded about removable storage?
- What should be recorded about nearby devices?
- What should be recorded about visible usernames and account IDs?
- Should I take screenshots or photographs?
- What are the limitations of screenshots and photographs?
- Should I switch a digital device off?
- Should I leave a digital device powered on?
- What evidence may be lost when a device is powered off?
- What risks exist if a device remains powered on?
- Could a powered-on device be remotely wiped?
- Could a device lock if the screen turns off?
- Could encryption become harder to access after power loss?
- Could shutting down create new records?
- Is pulling the power cable the same as shutting down?
- What should I consider with a desktop computer?
- What should I consider with a laptop?
- What should I consider with a server?
- What should I consider with a network appliance?
- What should I consider with a smart or embedded device?
- When should a specialist make the power decision?
- What is device isolation?
- Why might a device need to be isolated?
- Could isolation prevent remote deletion?
- Could isolation cause evidence loss?
- Should I enable flight mode?
- Does flight mode disable every connection?
- Could Wi-Fi reconnect automatically?
- Could Bluetooth remain active?
- Could a device communicate through a cable?
- Could removing a SIM alter the evidence?
- What should I consider with an eSIM after removing a physical SIM?
- Should I disconnect a network cable?
- Could disconnecting a server affect other users or evidence?
- What is a Faraday bag and what can it do?
- What are the limitations of a Faraday bag?
- Could isolation affect location, time or synchronisation records?
- How should an isolation decision be documented?
- What should I do first when I encounter an unlocked phone?
- What should I do first when I encounter a locked phone?
- Should I keep an unlocked phone awake?
- Could interacting with the screen change the evidence?
- Could checking the battery level change the evidence?
- Should I connect a phone to a charger?
- Could charging create a data connection?
- Could a phone receive new messages while being preserved?
- Could a phone synchronise deletions or edits?
- Could biometric access be lost?
- Should I ask the user for the passcode?
- What should be recorded if a passcode is supplied?
- Could repeated unlock attempts cause data loss?
- What should I do with a damaged mobile device?
- What should I do with a wet mobile device?
- When should a mobile-device specialist be contacted immediately?
- What should I do first when I encounter an unlocked computer?
- What should I do first when I encounter a locked computer?
- Could moving the mouse or pressing a key alter the evidence?
- What should I record about open windows and applications?
- Could closing an application destroy useful evidence?
- Could logging out destroy useful evidence?
- Could a live computer contain unsaved data?
- What evidence may exist only in memory?
- What is a live-memory capture?
- Should an investigator attempt a live-memory capture?
- Could remote-access software be active?
- Could another user be connected to the computer?
- Could a virtual machine be running?
- Could a container or remote desktop hold the relevant evidence?
- What should be preserved from a live command window or console?
- When should a computer be isolated from the network?
- When should a live-system specialist take over?
- What should I do when I encounter a logged-in online account?
- What should be preserved from the account before interaction?
- Could navigating the account create new records?
- Could opening a page update the account’s activity history?
- Could logging in from another device alter the evidence?
- Could changing a password alert another user?
- Could changing a password terminate useful sessions?
- Could changing recovery details destroy useful context?
- Should I revoke linked devices or sessions?
- What should be recorded before revoking a session?
- Could account security action cause remote deletion?
- Could securing the account protect a victim from further harm?
- How should preservation and safeguarding be balanced?
- Could an administrator access the account without the user?
- What should be preserved from an account-security page?
- When should a provider or platform specialist be contacted?
- Could opening a message alter the evidence?
- Could opening a message create a read receipt?
- Could opening disappearing content consume it?
- Could a message request change when opened?
- Could reconnecting a messaging device trigger synchronisation?
- Could blocking an account alter the evidence?
- Could leaving or removing someone from a group alter the evidence?
- What should be preserved before blocking or removing access?
- Could opening an attachment create a new record?
- Could opening a link expose the device or investigation?
- What should be preserved from a live messaging conversation?
- When should a messaging specialist take over?
- What should I do when I encounter a live cloud session?
- Could cloud data change while I am viewing it?
- Could another user delete cloud evidence remotely?
- Could logging out remove local cloud data?
- Could reconnecting a device trigger cloud synchronisation?
- Could downloading a cloud file alter audit records?
- Could opening a shared document create a viewing record?
- Could changing sharing permissions alert other users?
- What should be preserved from cloud-sharing settings?
- What should be preserved from cloud version history?
- Could a cloud recycle bin or deleted-items folder be volatile?
- What should be preserved from cloud audit or activity records?
- When should the organisation or cloud provider be contacted?
- When should specialist cloud support be sought?
- What should I do when I encounter a router or network appliance?
- Should I restart a router?
- Could restarting a router destroy useful evidence?
- What should be recorded from a router display or interface?
- What should be preserved about connected devices?
- Could disconnecting a network affect several evidential systems?
- What should be preserved from DHCP or connection tables?
- What should be preserved from firewall or security alerts?
- Could logs be lost when network equipment is powered down?
- Could an attacker remain connected to the network?
- When should network isolation be considered?
- When should a network or incident-response specialist take over?
- What should I do when I find a USB storage device?
- Should I plug an unknown USB device into a computer?
- Could connecting removable media alter it?
- Could removable media contain malicious software?
- What should be recorded about removable storage?
- What should I do with a memory card?
- What should I do with an external hard drive?
- What should I do with a hardware security key?
- What should I do with a cryptocurrency hardware wallet?
- What should be recorded about connected printers or scanners?
- Could a peripheral contain its own logs or storage?
- When should removable media be handled only by a specialist?
- What is a provider preservation request?
- What can a preservation request achieve?
- What can a preservation request not achieve?
- When should provider preservation be considered?
- What identifiers should be preserved before contacting a provider?
- Could provider records disappear quickly?
- What should be preserved before an account is deleted?
- What should be preserved before an employee account is disabled?
- Could disabling an organisational account alter other evidence?
- What should an organisation preserve during an incident?
- What is a legal hold or retention hold?
- Does preservation mean the material will automatically be disclosed?
- How should preservation requests and responses be documented?
- When should legal, communications-data or specialist support be sought?
- What should I ask a victim to preserve?
- Should a victim continue using the affected device?
- What should I ask a witness to preserve?
- Should a witness forward messages or files to the investigator?
- Could taking screenshots alter the evidence?
- Should a victim or witness delete harmful content?
- What should be preserved from a victim’s account-security alerts?
- Could account-recovery action destroy useful evidence?
- What should be preserved before a victim changes credentials?
- How should consent and authority be documented?
- Could another household or workplace user control the device?
- When should the original device be retained?
- When may a native export be sufficient?
- When should a specialist acquire the material?
- What should I do during an active cyber incident?
- What evidence may be volatile during an active incident?
- Should compromised systems be disconnected immediately?
- Could immediate disconnection prevent further harm?
- Could immediate disconnection destroy visibility of the attacker?
- What should be recorded before containment?
- What should be preserved about active sessions and processes?
- What should be preserved about current network connections?
- Could containment alert the offender?
- What should be recorded during containment?
- How should containment decisions be justified?
- What should be preserved after containment?
- Could containment create new logs and alerts?
- Could containment affect timestamps and timelines?
- When should recovery begin after containment?
- Could recovery overwrite or destroy evidence?
- How should changes caused by the investigator be recorded?
- How should uncertainty about the original state be reported?
- What is continuity of digital evidence?
- What should be recorded when digital material changes hands?
- What should be recorded about specialist advice?
- How should a decision not to seize or preserve something be documented?
- What are the most common digital first-response mistakes?
- When should a first-response line of enquiry stop?
- What is the overall investigator checklist for first response and preservation?