0% found this document useful (0 votes)
7 views84 pages

Module 01

The document outlines the syllabus for a Digital Forensics course at Vellore Institute of Technology, covering various modules including legal aspects, data acquisition, and investigations involving Windows, Linux, email, social media, mobile devices, and cloud forensics. It emphasizes the importance of understanding digital evidence, legal processes, and the roles of forensic specialists in both public and private sector investigations. Additionally, it discusses the significance of cyber law in India and the challenges faced in keeping up with technological advancements in legal contexts.

Uploaded by

Dileesha A
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views84 pages

Module 01

The document outlines the syllabus for a Digital Forensics course at Vellore Institute of Technology, covering various modules including legal aspects, data acquisition, and investigations involving Windows, Linux, email, social media, mobile devices, and cloud forensics. It emphasizes the importance of understanding digital evidence, legal processes, and the roles of forensic specialists in both public and private sector investigations. Additionally, it discusses the significance of cyber law in India and the challenges faced in keeping up with technological advancements in legal contexts.

Uploaded by

Dileesha A
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

BCSE322L

Digital Forensics
Fall 2025-26

Dr. Aju D

Vellore Institute of Technology, Vellore


Syllabus
Module 1: Understanding Digital Forensics and Legal Aspects: Understanding
computer forensics - Preparing for computer investigation – Maintaining professional
conduct – understanding computer investigations – Taking a systematic approach –
Corporate Hi-Tech investigations – Conducting an investigation.

Module 2: Acquisition and Storage Data: Understanding Storage Formats for


Digital Evidence - Determining the Best Acquisition Method - Contingency Planning
for Image Acquisitions - Using Acquisition Tools - Validating Data Acquisitions -
Performing RAID Data Acquisitions - Using Remote Network Acquisition Tools -
Storing Digital Evidence - Obtaining a Digital Hash - Sample Cases.

Module 3: Working with Windows: Understanding File Systems - Exploring


Microsoft File Structures - Examining NTFS Disks - Understanding Whole Disk
Encryption - Understanding the Windows Registry - Understanding Microsoft Startup
Tasks - Understanding MS-DOS Startup Tasks - Evaluating Computer Forensics Tool
Needs - Computer Forensics Software and Hardware Tools.

© Cengage Learning 2015


Syllabus
Module 4: Working with Linux and Unix System: UNIX and Linux Overview -
Inodes - Boot Process - Drives and Partition Schemes - Examining disk
Structures - Understanding Other Disk Structures - Ownership and Permissions,
File Attributes, Hidden Files, User Accounts - Case studies - Validating Forensic
Data – Addressing Data-Hiding Techniques – Locating and Recovering Graphics
File.

Module 5: Email and Social Media Forensics: Investigating E-mail crimes and
Violations – Applying Digital Forensics Methods to Social Media
Communications - Social Media Forensics on Mobile Devices - Forensics Tools
for Social Media Investigations.

Module 6: Mobile Forensics: Mobile phone basics – Acquisition procedures for


mobile - Android Device –Android Malware – SIM Forensic Analysis – Case
study.

Module 7: Cloud Forensics: Working with the cloud vendor, obtaining


evidence, reviewing logs and APIs.

© Cengage Learning 2015


Module 8: Contemporary Issues
© Cengage Learning 2015
An Overview of Digital Forensics

• Digital forensics

• The application of computer science and an investigative


procedures for a legal purpose

• involving the analysis of digital evidences after proper


search authority, chain of custody, validation with
mathematics, use of validation tools, reporting, and
possible expert presentation.

• In October 2012, an ISO standard for digital forensics was ratified.


© Cengage Learning 2015
Rules of Evidence

• Admissible
• Authentic
• Complete
• Reliable
• Believable

© Cengage Learning 2015


Indian Laws

Law Types

Criminal Law

Civil Law

Statutory Law

Common Law

© Cengage Learning 2015


Cyber Law in India

Cyber Law also called IT Law is the law regarding Information-


technology including computers and internet.

It is related to legal informatics and supervises the digital


circulation of information, software, information security and e-
commerce.

© Cengage Learning 2015


Importance of Cyber Law

It covers all transaction over internet.

It keeps eyes on all activities over internet.

It touches every action and every reaction in


cyberspace.

© Cengage Learning 2015


Digital Forensics and Other
Related Disciplines

Forensics investigators often work as part of a team, known


as the investigation triad.

© Cengage Learning 2015


Digital Forensics and Other
Related Disciplines

Vulnerability/threat assessment and risk management


Tests and verifies the integrity of stand-alone workstations
and network servers.

Network intrusion detection and incident response


Detects intruder attacks by using automated tools and
monitoring network firewall logs.

Digital investigations
Manages investigations and conducts forensics analysis of
systems suspected of containing evidence.
© Cengage Learning 2015
Who are Intruders?

⚫ Masquerader: An individual who is unauthorized to use the


computer and who penetrates a system’s access controls
to exploit a legitimate user’s account.

⚫ Misfeasor: A legitimate user who access data, programs or


resources for which such access is not authorized.

⚫ Clandestine User: An individual who seizes supervisory


control of the system and uses this control to avoid
auditing or access control .
© Cengage Learning 2015
Examples of Intrusion

⚫ Performing a remote root compromise of an email


server.

⚫ Guessing and cracking passwords.

⚫ Copying a database containing credit card numbers.

⚫ Viewing sensitive data, including payroll records and


medical information without authorization.

⚫ Running a packet sniffer on a workstation to capture


usernames and passwords. © Cengage Learning 2015
Examples of Intrusion

Using an anonymous FTP server to distributed software


and music files.

Dialling into an unsecured modem and gaining internal


network access.

Posing as an executive, calling the help desk, resetting


the executive’s email password.

Using and unattended logged-in workstation without


permission.
© Cengage Learning 2015
Understanding Case Laws

Existing laws can’t keep up with the rate of technological


change.

When statutes don’t exist, case law is used


Allows legal counsel to apply previous similar cases to
current one in an effort to address ambiguity in laws.

Examiners must be familiar with recent court rulings on


search and seizure in the electronic environment.
© Cengage Learning 2015
Developing Digital Forensics
Resources

To supplement your knowledge:


Develop and maintain contact with computing, network, and
investigative professionals.

Join computer user groups in both the public and private


sectors
Example: Computer Technology Investigators Network
(CTIN) meets to discuss problems with digital forensics
examiners encounter

Consult outside experts

© Cengage Learning 2015


Preparing for Digital Investigation

Digital investigations fall into two categories:

Public-sector investigations
Involves government agencies responsible for
criminal investigations and prosecution.

Private-sector investigations
Private-sector investigations focus more on
policy violations.

© Cengage Learning 2015


Understanding Law Enforcement
Agency Investigations
When conducting public-sector investigations, you
must understand laws on computer-related crimes
including:
Standard legal processes
Guidelines on search and seizure
How to build a criminal case

The Computer Fraud and Abuse Act was passed in


1986. Later IT Act by 2002.
Specific state laws were generally developed later.
© Cengage Learning 2015
Understanding Law Enforcement
Agency Investigations

[Link]: Official registration of the alleged crime by


police
[Link]: Evidence collection, witness
statements, arrests
[Link] Sheet: Police file formal accusation
and evidence before court
[Link]: Court decides to proceed and
issues summons or warrants
[Link] of Charges: Court outlines specific
charges to accused © Cengage Learning 2015
Understanding Law Enforcement
Agency Investigations
6. Prosecution Evidence: Prosecution presents
evidence and examines witnesses.
[Link] of Accused: Accused responds to
evidence.
[Link] Evidence: Accused can present evidence
and witnesses.
[Link]: Both sides present closing arguments
[Link]: Court decides guilt and passes
sentence if convicted.
[Link]: Opportunity to challenge verdict in higher
courts. © Cengage Learning 2015
Indian Laws

1. Motor Vehicle Act 1988, section -185, 202:- At the time of


driving if your 100ml. blood contains more than 30mg. of
alcohol then the police can arrest you without a warrant.
The Motor Vehicle Act, 2019

2. Criminal Procedure Code 1973, Section 46:- No woman


cannot be arrested before 6 A.M. and after 6 P.M.

3. Indian Sarais Act, 1887:- Even any 5-star hotel can’t


prohibit you from drinking potable water and using its
washrooms.
© Cengage Learning 2015
Indian Laws

5. Police Act, 1861:- A police officer is always on duty whether


he/she wearing a uniform or not. If a person makes a complaint to
the officer, he/she could not say that he can’t help the victim
because he/ she is not on duty.
(The Police Act, 1949)

6. Maternity Benefit Act, 1961:- No company can fire a pregnant


woman. It may be punishable by a maximum of 3 years of
imprisonment.

7. Income Tax Act, 1961:- In the case of tax violations, the tax
collection officer has the power to arrest you but before arresting
you, he/she will have to send a notice to you. Only Tax
Commissioner decides how long you will stay in the custody.
© Cengage Learning 2015
Indian Laws

8. Hindu Marriage Act 1955, Section -13: As per the Hindu


Marriage Act, 1955 (any husband or wife) may apply for divorce in
the court on the basis of Adultery (physical relationship outside of
marriage), physical and mental abuse, impotency, to leave home
without information, to change Hindu religion and adopt other
religion, insanity, incurable disease and no information about
husband or wife for seven-year.

9. As per the Citizen Charter (Indian Oil Corporation website):-


There are very few people who know that if their gas cylinder
blasts during the cooking of food then the gas agency is liable to
pay Rs. 50 lakh to the victim as compensation.

© Cengage Learning 2015


Indian Laws

10. Foreign Contribution Regulation Act (FCRA), 2010:- It would


surprise you to know that if you take a gift from any company on
the occasion of a festival, it falls into the category of bribery. You
can also be sentenced to jail for this crime.

11. Maximum Retail Price Act, 2014:- Any Shop keeper can’t
charge more than the printed price of any commodity, but a
consumer has the right to bargain for less than the printed price
of a commodity.

12. Limitation Act, 1963:- If your office does not pay you then you
have the power to file an FIR against it within 3 years. But if you
report after 3 years, you will not get anything for the due.

© Cengage Learning 2015


Following Legal Processes

© Cengage Learning 2015


Following Legal Processes

Digital Evidence First Responder (DEFR)


Arrives on an incident scene, assesses the situation, and
takes precautions to acquire and preserve evidence.

Digital Evidence Specialist (DES)


Has the skill to analyze the data and determine when
another specialist should be called in to assist.

Affidavit - a sworn statement of support of facts about or


evidence of a crime
Must include exhibits that support the allegation
© Cengage Learning 2015
Understanding Private-Sector
Investigations

Private-sector investigations involve private companies


and lawyers who address company policy violations and
litigation disputes
Example: wrongful termination

Strive to minimize or eliminate litigation

Private-sector crimes can involve:


E-mail harassment, falsification of data, gender and age
discrimination, embezzlement, sabotage, and industrial
espionage © Cengage Learning 2015
Understanding Private-Sector
Investigations

Can reduce the risk of litigation by publishing and


maintaining policies that employees find easy to read and
follow.

Most important policies define rules for using the company’s


computers and networks.
Known as an “Acceptable use policy”

Line of authority - states who has the legal right to initiate


an investigation, who can take possession of evidence, and
who can have access to evidence
© Cengage Learning 2015
BCSE322L

Digital Forensics
Fall 2025-26

Dr. Aju D

Vellore Institute of Technology, Vellore

© Cengage Learning 2015


Understanding Private-Sector
Investigations

During private investigations, you search for evidence to


support allegations of violations of a company’s rules or
an attack on its assets

Three types of situations are common:


Abuse or misuse of computing assets (employee violation
of company rules).
E-mail abuse
Internet abuse

© Cengage Learning 2015


Understanding Private-Sector
Investigations

Abuse / Misuse of Computing Assets


All instances of misuse are detrimental to an organization.
• Improper use of a company vehicle for vacations or other personal
recreation.

• Misuse of company work vehicles or equipment to perform side jobs


on weekends or after hours.

• Renting of company equipment or materials to third parties.

• Using the facility or company materials to create competing goods.


© Cengage Learning 2015
Understanding Private-Sector
Investigations

Abuse / Misuse of Computing Assets


• Running a competing business out of your company.

• Providing family or friends with unsanctioned discounts or free


merchandise (sweet hearting).

• Misusing the company computer system or employee technology


permissions (hosting their own websites, running a side business
using company computers or other devices).

• Theft of office supplies and postage.

© Cengage Learning 2015


Understanding Private-Sector
Investigations

E-Mail abuse
The use of electronic mail to advertise unethically,
harass, annoy, or cause harm to the email recipient.
Bulk email
SPAM / UCE (Unsolicited Commercial Email)
Threatening e-mail (Extortion/ Sextortion)
E-mail sent with the intent to slow productivity
Cause damage to the recipient's computer system
© Cengage Learning 2015
Understanding Private-Sector
Investigations

Internet abuse
Social Exclusion (caste, ethnicity, religion, gender
and disability)
Tagging without Permission
Flaming (derogatory message / Character
Assassination)
Sexting / Reposting
Impersonation / Identity Theft
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Sample text that can be used in internal warning banners:
Use of this system and network is for official business only.

Systems and networks are subject to monitoring at any time by the


owner.

Using this system implies consent to monitoring by the owner

Unauthorized or illegal users of this system or network will be


subject to discipline or prosecution.

© Cengage Learning 2015


Understanding Private-Sector
Investigations

Businesses are advised to specify an authorized requester


who has the power to initiate investigations

Examples of groups with authority


Corporate security investigations

Corporate ethics office

Corporate equal employment opportunity office

Internal auditing

The general counsel or legal department


© Cengage Learning 2015
Understanding Private-Sector
Investigations

The distinction between personal and company computer


property can be difficult with cell phones, smartphones,
personal notebooks, and tablet computers

BYOD environment
Some companies state that if you connect a personal device
to the business network, it falls under the same rules as
company property

© Cengage Learning 2015


Benefits of Professional Forensic
Methodology
Protection of evidence is critical.

o No possible evidence is damaged, destroyed, or otherwise compromised


by the procedures used to investigate the computer.
o No possible computer virus is introduced to a subject computer during the
analysis process.

o Extracted and possibly relevant evidence is properly handled and


protected from later mechanical or electromagnetic damage.

o A continuing chain of custody is established and maintained.

o Any client–attorney information who has inadvertently acquired during a


forensic exploration is ethically and legally respected and not divulged.
© Cengage Learning 2015
Steps taken by Computer
Forensics Specialists

1. Protect the subject computer system during the forensic


examination from any possible alteration, damage, data
corruption, or virus introduction.
2. Discover all files on the subject system. This includes existing
normal files, deleted yet remaining files, hidden files, password-
protected files, and encrypted files.
3. Recover all discovered deleted files.
4. Reveal all the contents of hidden files as well as temporary or
swap files used by both the app. Pgm. and the operating system.
© Cengage Learning 2015
Steps taken by Computer
Forensics Specialists

5. Access all the contents of protected or encrypted


files.
6. Analyze all possibly relevant data found in special
areas of a disk. (Unallocated space, Slack space
in a file).
7. Print out an overall analysis of the subject
computer system, as well as a listing of all possibly
relevant files and discovered file data.
© Cengage Learning 2015
Steps taken by Computer
Forensics Specialists

8. Provide an opinion of the system layout; the file


structures discovered; any discovered data and
authorship information; any attempts to hide,
delete, protect, and encrypt information; and any
other relevant data.
9. Provide expert consultation and/or testimony, as
required.
© Cengage Learning 2015
Digital Forensics Techniques

1. Digital forensics involves creating copies of a


compromised device and then using various
techniques and tools to examine the information.

2. Digital forensics techniques help inspect


unallocated disk space and hidden folders for
copies of encrypted, damaged, or deleted files.

© Cengage Learning 2015


Digital Forensics Techniques:
Reverse Steganography

• Cybercriminals use steganography to hide data


inside digital files, messages, or data streams.
• Reverse steganography involves analysing the
data hashing found in a specific file.
• When inspected in a digital file or image, hidden
information may not look suspicious.
© Cengage Learning 2015
Digital Forensics Techniques:
Cross-Drive Analysis

• Also known as anomaly detection, helps find similarities


to provide context for the investigation.
• These similarities serve as baselines to detect suspicious
events.
• It typically involves correlating and cross-referencing
information across multiple computer drives to find,
analyze, and preserve any information relevant to the
investigation. © Cengage Learning 2015
Digital Forensics Techniques:
Live Analysis

• Occurs in the operating system while the device or


computer is running.
• It involves using system tools that find, analyze, and
extract volatile data, typically stored in RAM or Cache.
• Live analysis typically requires keeping the inspected
computer in a forensic lab to maintain the chain of
evidence properly.
© Cengage Learning 2015
Digital Forensics Techniques:
Deleted File Recovery

• Known as data carving or file carving, is a technique that


helps recover deleted files.
• It involves searching a computer system and memory for
fragments of files that were partially deleted in one
location while leaving traces elsewhere on the inspected
machine.

© Cengage Learning 2015


Interesting Facts

• Sanmay Ved | [Link] | $12 | $6006.13 | Art of


Living

• [Link] | $700 | Amal Augustine |


Maxime Chan

© Cengage Learning 2015


Interesting Facts

© Cengage Learning 2015


Interesting Facts

© Cengage Learning 2015


Computer Crime?

Computer crime is an act performed by a knowledgeable

computer user, sometimes referred to as a hacker that illegally

browses or steals a company’s or individual’s private

information.

© Cengage Learning 2015


Computer Crimes?

Child Pornography Fraud • Human Trafficking


• Intellectual Property
Copyright Violation Software Piracy
Theft
Cracking Spamming
• Salami Slicing
Cyber Terrorism Spoofing • Scam
Cyber bullying Harvesting • Slander
Cyber Squatting Identity Theft • Typo Squatting
• Unauthorized Access
Creating Malwares Illegal Sales
• Wiretapping
Denial of Service IPR Violation
Espionage Phishing © Cengage Learning 2015
Protecting Data being
Compromised

1. Educate your employees


2. Create and update procedures
3. Remote monitoring
4. Data backup and recovery
5. Keep only what you need
6. Destroy before disposal
7. Safeguard physical data
8. Empower employees with best practices
9. Maintain up-to-date security software
10. Encrypt data
11. Protect portable devices
12. Hire an expert
© Cengage Learning 2015
What is Tracking on Internet?

Web tracking is often referred to as user


tracking, since data about user behaviour (across
domains) can be collected.

© Cengage Learning 2015


What data can be tracked?

1. Websites that are visited.

2. Sub-pages of a website that are visited.

3. How long the dwell time on individual sub-pages is.

4. From which website the current website was referred to.


5. Elements (links, buttons, etc.) that were clicked on.

6. Products that were viewed and purchased.


7. Which device and which browser were used.

8. Which files the website visitor downloads/Uploads.


9. What mouse or eye movements were©made on the website.
Cengage Learning 2015
How does Web tracking Work?
Cookies

• Session Cookies

• Persistent Cookies

• First-Party Cookies

• Third-Party Cookies

• Secure Cookies
© Cengage Learning 2015
How does Web tracking Work?
IP

• IPv4 / IPv6

• Public IP / Private IP

• Static IP / Dynamic IP

© Cengage Learning 2015


How does Web tracking Work?
Fingerprinting

1. Browser Fingerprinting

2. Device Fingerprinting

3. Audio and Canvas Fingerprinting

4. IP-based Fingerprinting

5. Behavioural Fingerprinting

© Cengage Learning 2015


How does Web tracking Work?
App Tracking

1. Tracking

2. Data Collection

3. Data Usage

© Cengage Learning 2015


How does Web tracking Work?
Email Tracking

1. Tracking

1. IP address (approximate location)

2. Device type (desktop, mobile, etc.)

3. Email client (e.g., Gmail, Outlook)

2. Link Tracking

3. Read Receipts © Cengage Learning 2015


Crime Investigation
Taking a Systematic Approach
Steps for problem solving
Make an initial assessment about the type of case you are
investigating
Determine a preliminary design or approach to the case
Create a detailed checklist

Determine the resources you need

Obtain and copy an evidence drive

Identify the risks

Mitigate or minimize the risks

Test the design © Cengage Learning 2015


Crime Investigation
Taking a Systematic Approach
Steps for problem solving (cont’d)

Analyze and recover the digital evidence

Investigate the data you recover

Complete the case report

Critique the case

© Cengage Learning 2015


Assessing the Case

Systematically outline the case details


Situation

Nature of the case

Specifics of the case

Type of evidence

Known disk format

Location of evidence

Based on these details, you can determine the case


requirements
Planning your Investigation

A basic investigation plan should include the following


activities:
Acquire the evidence

Complete an evidence form and establish a chain of custody

Secure evidence in an approved secure container

Transport the evidence to a computer forensics lab


Planning your Investigation

A basic investigation plan (cont’d):


Prepare your forensics workstation

Retrieve the evidence from the secure container

Make a forensic copy of the evidence

Return the evidence to the secure container

Process the copied evidence with computer forensics tools


Planning your Investigation

An evidence custody form helps you document what has


been done with the original evidence and its forensics
copies
Also called a chain-of-evidence form

Two types
Single-evidence form
Lists each piece of evidence on a separate page
Multi-evidence form
Single Evidence Form
Multiple Evidence Form
A sample multi-evidence from used on a private-sector environment
Securing your Device

Use evidence bags to secure and catalog the evidence

Use computer safe products when collecting computer


evidence
Antistatic bags
Antistatic pads

Use well-padded containers

Use evidence tape to seal all openings


CD drive bays
Insertion slots for power supply electrical cords and
USB cables
Securing your Device

Write your initials on tape to prove that evidence has not


been tampered with

Consider computer specific temperature and humidity


ranges
Make sure you have a safe environment for transporting
and storing it until a secure evidence container is available
Procedure
For
Private-Secor High-Tech Investigations

As an investigator, you need to develop formal procedures


and informal checklists.
To cover all issues important to high-tech investigations

Ensures that correct techniques are used in an investigation

© Cengage Learning 2015


Procedure
For
Private-Secor High-Tech Investigations

The majority of investigative work for termination cases involves


employee abuse of corporate assets

Incidents that create a hostile work environment are the predominant


types of cases investigated

Viewing pornography in the workplace


Sending inappropriate e-mails

Organizations must have appropriate policies in place

© Cengage Learning 2015


Internet Abuse Investigation

To conduct an investigation you need:


Organization’s Internet proxy server logs
Suspect computer’s IP address
Suspect computer’s disk drive
Your preferred computer forensics analysis tool

© Cengage Learning 2015


Internet Abuse Investigation

Recommended steps
Use standard forensic analysis techniques and procedures
Use appropriate tools to extract all Web page URL
information
Contact the network firewall administrator and request a
proxy server log
Compare the data recovered from forensic analysis to the
proxy server log
Continue analyzing the computer’s disk drive data

© Cengage Learning 2015


Email Abuse Investigation

To conduct an investigation you need:


An electronic copy of the offending e-mail that contains
message header data
If available, e-mail server log records
For e-mail systems that store users’ messages on a central
server, access to the server
Access to the computer so that you can perform a forensic
analysis on it
Your preferred computer forensics analysis tool

© Cengage Learning 2015


Email Abuse Investigation

Recommended steps
Use the standard forensic analysis techniques
Obtain an electronic copy of the suspect’s and victim’s e-
mail folder or data
For Web-based e-mail investigations, use tools such as
FTK’s Internet Keyword Search option to extract all related
e-mail address information
Examine header data of all messages of interest to the
investigation

© Cengage Learning 2015


Conducting an Investigation

Gather resources identified in investigation plan

Items needed
Original storage media
Evidence custody form
Evidence container for the storage media
Bit-stream imaging tool
Forensic workstation to copy and examine your
evidence
Securable evidence locker, cabinet, or safe

© Cengage Learning 2015


Understanding Bit-Stream Copies

Bit-stream copy
Bit-by-bit copy of the original storage medium
Exact copy of the original disk
Different from a simple backup copy
Backup software only copy known files
Backup software cannot copy deleted files, e-mail
messages or recover file fragments

Bit-stream image
File containing the bit-stream copy of all data on a disk
or partition
Also known as “image” or “image file”
© Cengage Learning 2015
Understanding Bit-Stream Copies

Copy image file to a target disk that matches the original


disk’s manufacturer, size and model

© Cengage Learning 2015


Acquiring an Image of Evidence Media

First rule of computer forensics


Preserve the original evidence

Conduct your analysis only on a copy of the data

Several vendors provide MS-DOS, Linux, and


Windows acquisition tools
Windows tools require a write-blocking device when
acquiring data from FAT or NTFS file systems

© Cengage Learning 2015


Analysing your Digital Evidence

Your job is to recover data from:


Deleted files
File fragments
Complete files

Deleted files linger on the disk until new data is saved on


the same physical location
Tools can be used to retrieve deleted files
ProDiscover Basic

© Cengage Learning 2015


Completing the Case

You need to produce a final report


State what you did and what you found

Include Autopsy / ProDiscover report to document your work

Repeatable findings
Repeat the steps and produce the same result

If required, use a report template

Report should show conclusive evidence


Suspect did or did not commit a crime or violate a company
policy
© Cengage Learning 2015
Completing the Case

Keep a written journal of everything you do


Your notes can be used in court

Answer the six Ws:


Who, What, When, Where, Why, and hoW

You must also explain computer and network


processes

© Cengage Learning 2015


Critiquing the Case

Ask yourself the following questions:


How could you improve your performance in the case?

Did you expect the results you found? Did the case develop in
ways you did not expect?

Was the documentation as thorough as it could have been?

What feedback has been received from the requesting source?

Did you discover any new problems? If so, what are they?

Did you use new techniques during the case or during


research?
© Cengage Learning 2015
© Cengage Learning 2015

You might also like