ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Insights / methods and field notes

Technical guidance that shows its work

Practical notes on evidence, admissibility preparation, cloud preservation, attack paths, New York cyber obligations, and operational technology.

Technical map connecting a computer, mobile device, cloud account, verified evidence set, and documented timeline
Source state, documented method, integrity checks, and chronology support a bounded conclusion.
How to use this directory

Start with the technical question, then follow the method and cited primary sources.

These articles are written for professionals who need to decide what to preserve, test, change, or ask next. Primary sources are linked where the topic involves rules, guidance, or standards. The material explains technical practice and does not provide legal advice.

Browse technical field notes

Practical guidance on preservation, expert methods, cyber response, security testing, and operational systems.

01 / Expert evidence

Frye, Daubert, and the technical record behind the opinion

A technical practitioner's guide to preparing reproducible digital evidence work for New York state and federal court scrutiny.

Read field note
02 / eDiscovery

Preserve the collaboration record before ordinary systems change it

A practical technical checklist for preserving Microsoft Teams, Slack, email, cloud files, and identity records under short New York litigation deadlines.

Read field note
03 / New York cybersecurity

Part 500 evidence: connect the policy to the system

How asset, access, testing, vulnerability, log, incident, and recovery records can support a NYDFS cybersecurity program without replacing legal analysis.

Read field note
04 / New York cybersecurity

Give counsel facts that can support the notice analysis

A technical response checklist for establishing access, acquisition, affected systems, data types, identities, safeguards, and chronology after a suspected breach.

Read field note
05 / OT / ICS / SCADA

Passive-first discovery is a coverage discipline

How sensor placement, observation windows, engineering records, owner context, and reconciliation produce a useful OT asset inventory.

Read field note
06 / OT / ICS / SCADA

The diagram is intent. Reachability is evidence.

A practical method for testing OT zones, conduits, firewall rules, routes, identity paths, and remote access under operator authority.

Read field note
07 / Digital evidence

A location artifact is a measurement with conditions

A technical guide to GPS, Wi-Fi, cell, application, photo, health, vehicle, and account records used in mobile location analysis.

Read field note
08 / Incident response

Secure the money path, then reconstruct the mailbox event

A technical first-day plan for business email compromise involving payment fraud, Microsoft 365 or Google Workspace, identity evidence, and mailbox recovery.

Read field note
09 / Digital evidence

Preservation mistakes that can change the answer

Common evidence-handling errors involving live devices, cloud accounts, screenshots, exports, reimaging, forwarding, and undocumented transfers.

Read field note
10 / Digital evidence

Questions to answer before digital evidence work begins

Plain technical answers about preservation, timing, scope, remote collection, deleted data, mobile devices, reports, expert testimony, and cost drivers.

Read field note

Ask a technical question

Describe the work, the deadline, and the people authorized to act. Do not send evidence through the public form.

Contact GDF