Guide to Integrating Forensic Techniques into Incident Response
Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang · National Institute of Standards and Technology · August 2006 (final, published 1 September 2006) · 2006
Identifier: NIST SP 800-86
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.
Who it is for, and when
Read it if you are standing up or auditing a corporate or government DFIR capability and need a citable federal reference for policy, staffing and data-source priority. It is also the document to cite when you need to justify a collection order of volatility to a court or a client. Newcomers can use chapters 4-7 as a checklist of where evidence lives on a host or network.
What it does not cover
It has not been revised since 2006, so it predates full-disk encryption as a default, cloud-hosted workloads, smartphones, SSD trim behaviour and modern Windows artefacts; the tool and OS specifics are obsolete even though the process model is not. It gives no legal analysis of admissibility and no US or foreign procedural law.
Go to the source
Open at csrc.nist.gov (opens in a new tab)https://csrc.nist.gov/pubs/sp/800/86/final
Details
- Type
- Standard or guidance
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Author
- Karen Kent, Suzanne Chevalier, Tim Grance, Hung Dang
- Publisher
- National Institute of Standards and Technology
- Version verified
- August 2006 (final, published 1 September 2006)
- Year
- 2006
- Identifier
- NIST SP 800-86
- Topics
- incident-response, evidence-handling, imaging, network, log-analysis, us-federal
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.
An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.
Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.
A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.
How to build and run network security monitoring: where to place sensors, what to collect (full packet capture, session data, alert data), and how to work a case from an alert through the collected evidence to a conclusion about scope.