Skip to content

Latest commit

 

History

History
31 lines (20 loc) · 1.27 KB

File metadata and controls

31 lines (20 loc) · 1.27 KB

Activity 7: Incident Evidence Pack

Alignment: LO3 / A3 Objective: Preserve useful evidence and start containment without destroying the incident timeline.

Safety and scope

Use only the simulated data supplied in this folder. Do not test live suspicious links, accounts, phone numbers or payment routes.

Procedure

  1. Start an incident log with date, time, timezone and reporter.
  2. Preserve the original message, sender identifiers, URLs, screenshots and transaction references.
  3. Record actions already taken, including clicks, downloads, credentials entered and transfers.
  4. If compromise is suspected, isolate the affected device without factory-resetting it.
  5. Use a separate trusted device to contact the bank and protect accounts.
  6. Change exposed credentials in priority order and revoke active sessions.
  7. List affected people, systems, data and financial accounts.
  8. Package evidence with neutral filenames and a chain-of-custody note.

Evidence to submit

Incident timeline, evidence register and initial containment record.

Acceptance check

The chronology is complete, evidence remains unaltered, and containment actions are distinguished from eradication.

Reflection

Which observable fact most changed your decision, and which uncertainty remains?