Skip to content

Commit ceb8005

Browse files
authored
Create 07-reporting-structure.md
1 parent 4021b3c commit ceb8005

File tree

1 file changed

+29
-0
lines changed

1 file changed

+29
-0
lines changed
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# 07 — Reporting Structure
2+
3+
## Standard DFIR Report Structure
4+
1. Executive Summary
5+
2. Scope & Objectives
6+
3. Methodology
7+
4. Findings
8+
5. Evidence References
9+
6. Impact Assessment
10+
7. Recommendations
11+
8. Appendices
12+
13+
## Writing Clear Findings
14+
- Convert raw data into narrative.
15+
- Explain why a finding matters.
16+
- Link evidence → conclusion → impact.
17+
18+
## Evidence Citation Rules
19+
- Include artifact name, path, timestamp.
20+
- Reference hashes for integrity.
21+
22+
## Confidence Levels
23+
- High: Multiple confirming artifacts
24+
- Medium: Partial confirmation
25+
- Low: Hypothesis with limited support
26+
27+
## Assumption Tracking
28+
- Label assumptions openly.
29+
- Update as investigation evolves.

0 commit comments

Comments
 (0)