File tree Expand file tree Collapse file tree 1 file changed +29
-0
lines changed
Expand file tree Collapse file tree 1 file changed +29
-0
lines changed Original file line number Diff line number Diff line change 1+ # 07 — Reporting Structure
2+
3+ ## Standard DFIR Report Structure
4+ 1 . Executive Summary
5+ 2 . Scope & Objectives
6+ 3 . Methodology
7+ 4 . Findings
8+ 5 . Evidence References
9+ 6 . Impact Assessment
10+ 7 . Recommendations
11+ 8 . Appendices
12+
13+ ## Writing Clear Findings
14+ - Convert raw data into narrative.
15+ - Explain why a finding matters.
16+ - Link evidence → conclusion → impact.
17+
18+ ## Evidence Citation Rules
19+ - Include artifact name, path, timestamp.
20+ - Reference hashes for integrity.
21+
22+ ## Confidence Levels
23+ - High: Multiple confirming artifacts
24+ - Medium: Partial confirmation
25+ - Low: Hypothesis with limited support
26+
27+ ## Assumption Tracking
28+ - Label assumptions openly.
29+ - Update as investigation evolves.
You can’t perform that action at this time.
0 commit comments