Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Forensic Foundations & Evidence Integrity
TheoryBeginner12 minIncident TriageAnalyst Reporting

Foundations Review — The Intake Decision

What is it?

A review of Module 1 assembled into the shape of a real case intake: the forensic question, integrity plan, custody record, acquisition choice and volatility order — decided BEFORE analysis begins.

Why it matters

Cases are won or lost at intake: every later finding inherits the integrity of these first decisions.

Where you see it

The first page of every case file.

What normal looks like

An intake sheet naming the question, the evidence sources, the hashes, the custody holder, and the acquisition order.

What suspicious looks like

Not applicable at review level.

How analysts investigate

By walking the four decisions of this module in order for every new case, before any artifact is opened.

Common beginner mistakes

  • Skipping intake on 'small' cases — the case that ends up in front of legal is never the one that announced itself as big.

Assemble Wadi's intake for the warehouse-laptop case: the question (was an unauthorized remote-access tool executed, when, by whom?), the machine's state (running), the plan (memory → triage → image, hash everything, custody form from minute one).

Quick check

Which intake is professionally sound?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.