Skip to content

Add forensics mobile and raw log evidence gates#1137

Open
alan747271363-art wants to merge 1 commit into
UnitOneAI:mainfrom
alan747271363-art:improve/forensics-mobile-raw-log-evidence
Open

Add forensics mobile and raw log evidence gates#1137
alan747271363-art wants to merge 1 commit into
UnitOneAI:mainfrom
alan747271363-art:improve/forensics-mobile-raw-log-evidence

Conversation

@alan747271363-art
Copy link
Copy Markdown

Summary

  • add NIST SP 800-101 Rev. 1 coverage for mobile/BYOD evidence decisions
  • add a mobile scope guard for owner, lock state, network state, MDM enrollment, remote wipe risk, consent/legal authority, and cloud/identity evidence
  • distinguish Windows Event Log triage text queries from preserved .evtx artifacts
  • add raw log preservation output fields with native artifact, triage export, and SHA-256 hash tracking

Scope notes

Addresses the mobile/BYOD and raw event-log preservation portions of #1112. This intentionally avoids duplicating the existing cloud custody PR #1068 and does not change acquisition tooling behavior.

Official references used:

Validation

Bounty

Skill Improvement / Improver candidate. Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant