Let's go into the basic requirements and steps of doing a computer forensics audit... against the context of what CyberNinjas has done.
STEP NUMBER ONE: is to KILL all network/wireless access. No Bluetooth, cell, wifi, or wired connections of ANY KIND. Their failure to do that = COMPROMISED evidence.
STEP NUMBER 2: USE IMAGES of the devices.. NEVER use the devices directly. They are using the machines, and modifying them without trying images first. Again, COMPROMISED evidence.
STEP NUMBER THREE: If the devices/machines must be tested, they must be properly disassembled and re-assemble-able to a working state comparable to how you received it (as odd as that sounds, basically if you have to do a chip-off or modify, it better be reversible/recoverable, otherwise... COMPROMISED!
STEP NUMBER 4: DOCUMENT every step, no matter how mundane. In the "Arizona Audit" nobody seems to be taking accurate notes. Ask a COP how a report would hold up in court with statements like "we did some stuff and saw it do something wrong." compared to "we removed the IC chip identified as a 8044XS chip, serial number 232398i2, tested it on an IC test bed to confirm the chip was in a working state, and the test resulted in a failure on pin 3. This means the chip is not functioning correctly." The former is NOT reproducible. The latter identifies the chip, the method used, and the results SO SOMEONE ELSE can verify it. Anything less = INCOMPLETE documentation = not valid evidence.
STEP NUMBER ONE: is to KILL all network/wireless access. No Bluetooth, cell, wifi, or wired connections of ANY KIND. Their failure to do that = COMPROMISED evidence.
STEP NUMBER 2: USE IMAGES of the devices.. NEVER use the devices directly. They are using the machines, and modifying them without trying images first. Again, COMPROMISED evidence.
STEP NUMBER THREE: If the devices/machines must be tested, they must be properly disassembled and re-assemble-able to a working state comparable to how you received it (as odd as that sounds, basically if you have to do a chip-off or modify, it better be reversible/recoverable, otherwise... COMPROMISED!
STEP NUMBER 4: DOCUMENT every step, no matter how mundane. In the "Arizona Audit" nobody seems to be taking accurate notes. Ask a COP how a report would hold up in court with statements like "we did some stuff and saw it do something wrong." compared to "we removed the IC chip identified as a 8044XS chip, serial number 232398i2, tested it on an IC test bed to confirm the chip was in a working state, and the test resulted in a failure on pin 3. This means the chip is not functioning correctly." The former is NOT reproducible. The latter identifies the chip, the method used, and the results SO SOMEONE ELSE can verify it. Anything less = INCOMPLETE documentation = not valid evidence.