BCSE322L
Digital Forensics
Fall 2025-26
Dr. Aju D
Vellore Institute of Technology, Vellore
Syllabus
Module 1: Understanding Digital Forensics and Legal Aspects: Understanding
computer forensics - Preparing for computer investigation – Maintaining professional
conduct – understanding computer investigations – Taking a systematic approach –
Corporate Hi-Tech investigations – Conducting an investigation.
Module 2: Acquisition and Storage Data: Understanding Storage Formats for
Digital Evidence - Determining the Best Acquisition Method - Contingency Planning
for Image Acquisitions - Using Acquisition Tools - Validating Data Acquisitions -
Performing RAID Data Acquisitions - Using Remote Network Acquisition Tools -
Storing Digital Evidence - Obtaining a Digital Hash - Sample Cases.
Module 3: Working with Windows: Understanding File Systems - Exploring
Microsoft File Structures - Examining NTFS Disks - Understanding Whole Disk
Encryption - Understanding the Windows Registry - Understanding Microsoft Startup
Tasks - Understanding MS-DOS Startup Tasks - Evaluating Computer Forensics Tool
Needs - Computer Forensics Software and Hardware Tools.
© Cengage Learning 2015
Syllabus
Module 4: Working with Linux and Unix System: UNIX and Linux Overview -
Inodes - Boot Process - Drives and Partition Schemes - Examining disk
Structures - Understanding Other Disk Structures - Ownership and Permissions,
File Attributes, Hidden Files, User Accounts - Case studies - Validating Forensic
Data – Addressing Data-Hiding Techniques – Locating and Recovering Graphics
File.
Module 5: Email and Social Media Forensics: Investigating E-mail crimes and
Violations – Applying Digital Forensics Methods to Social Media
Communications - Social Media Forensics on Mobile Devices - Forensics Tools
for Social Media Investigations.
Module 6: Mobile Forensics: Mobile phone basics – Acquisition procedures for
mobile - Android Device –Android Malware – SIM Forensic Analysis – Case
study.
Module 7: Cloud Forensics: Working with the cloud vendor, obtaining
evidence, reviewing logs and APIs.
© Cengage Learning 2015
Module 8: Contemporary Issues
© Cengage Learning 2015
An Overview of Digital Forensics
• Digital forensics
• The application of computer science and an investigative
procedures for a legal purpose
• involving the analysis of digital evidences after proper
search authority, chain of custody, validation with
mathematics, use of validation tools, reporting, and
possible expert presentation.
• In October 2012, an ISO standard for digital forensics was ratified.
© Cengage Learning 2015
Rules of Evidence
• Admissible
• Authentic
• Complete
• Reliable
• Believable
© Cengage Learning 2015
Indian Laws
Law Types
Criminal Law
Civil Law
Statutory Law
Common Law
© Cengage Learning 2015
Cyber Law in India
Cyber Law also called IT Law is the law regarding Information-
technology including computers and internet.
It is related to legal informatics and supervises the digital
circulation of information, software, information security and e-
commerce.
© Cengage Learning 2015
Importance of Cyber Law
It covers all transaction over internet.
It keeps eyes on all activities over internet.
It touches every action and every reaction in
cyberspace.
© Cengage Learning 2015
Digital Forensics and Other
Related Disciplines
Forensics investigators often work as part of a team, known
as the investigation triad.
© Cengage Learning 2015
Digital Forensics and Other
Related Disciplines
Vulnerability/threat assessment and risk management
Tests and verifies the integrity of stand-alone workstations
and network servers.
Network intrusion detection and incident response
Detects intruder attacks by using automated tools and
monitoring network firewall logs.
Digital investigations
Manages investigations and conducts forensics analysis of
systems suspected of containing evidence.
© Cengage Learning 2015
Who are Intruders?
⚫ Masquerader: An individual who is unauthorized to use the
computer and who penetrates a system’s access controls
to exploit a legitimate user’s account.
⚫ Misfeasor: A legitimate user who access data, programs or
resources for which such access is not authorized.
⚫ Clandestine User: An individual who seizes supervisory
control of the system and uses this control to avoid
auditing or access control .
© Cengage Learning 2015
Examples of Intrusion
⚫ Performing a remote root compromise of an email
server.
⚫ Guessing and cracking passwords.
⚫ Copying a database containing credit card numbers.
⚫ Viewing sensitive data, including payroll records and
medical information without authorization.
⚫ Running a packet sniffer on a workstation to capture
usernames and passwords. © Cengage Learning 2015
Examples of Intrusion
Using an anonymous FTP server to distributed software
and music files.
Dialling into an unsecured modem and gaining internal
network access.
Posing as an executive, calling the help desk, resetting
the executive’s email password.
Using and unattended logged-in workstation without
permission.
© Cengage Learning 2015
Understanding Case Laws
Existing laws can’t keep up with the rate of technological
change.
When statutes don’t exist, case law is used
Allows legal counsel to apply previous similar cases to
current one in an effort to address ambiguity in laws.
Examiners must be familiar with recent court rulings on
search and seizure in the electronic environment.
© Cengage Learning 2015
Developing Digital Forensics
Resources
To supplement your knowledge:
Develop and maintain contact with computing, network, and
investigative professionals.
Join computer user groups in both the public and private
sectors
Example: Computer Technology Investigators Network
(CTIN) meets to discuss problems with digital forensics
examiners encounter
Consult outside experts
© Cengage Learning 2015
Preparing for Digital Investigation
Digital investigations fall into two categories:
Public-sector investigations
Involves government agencies responsible for
criminal investigations and prosecution.
Private-sector investigations
Private-sector investigations focus more on
policy violations.
© Cengage Learning 2015
Understanding Law Enforcement
Agency Investigations
When conducting public-sector investigations, you
must understand laws on computer-related crimes
including:
Standard legal processes
Guidelines on search and seizure
How to build a criminal case
The Computer Fraud and Abuse Act was passed in
1986. Later IT Act by 2002.
Specific state laws were generally developed later.
© Cengage Learning 2015
Understanding Law Enforcement
Agency Investigations
[Link]: Official registration of the alleged crime by
police
[Link]: Evidence collection, witness
statements, arrests
[Link] Sheet: Police file formal accusation
and evidence before court
[Link]: Court decides to proceed and
issues summons or warrants
[Link] of Charges: Court outlines specific
charges to accused © Cengage Learning 2015
Understanding Law Enforcement
Agency Investigations
6. Prosecution Evidence: Prosecution presents
evidence and examines witnesses.
[Link] of Accused: Accused responds to
evidence.
[Link] Evidence: Accused can present evidence
and witnesses.
[Link]: Both sides present closing arguments
[Link]: Court decides guilt and passes
sentence if convicted.
[Link]: Opportunity to challenge verdict in higher
courts. © Cengage Learning 2015
Indian Laws
1. Motor Vehicle Act 1988, section -185, 202:- At the time of
driving if your 100ml. blood contains more than 30mg. of
alcohol then the police can arrest you without a warrant.
The Motor Vehicle Act, 2019
2. Criminal Procedure Code 1973, Section 46:- No woman
cannot be arrested before 6 A.M. and after 6 P.M.
3. Indian Sarais Act, 1887:- Even any 5-star hotel can’t
prohibit you from drinking potable water and using its
washrooms.
© Cengage Learning 2015
Indian Laws
5. Police Act, 1861:- A police officer is always on duty whether
he/she wearing a uniform or not. If a person makes a complaint to
the officer, he/she could not say that he can’t help the victim
because he/ she is not on duty.
(The Police Act, 1949)
6. Maternity Benefit Act, 1961:- No company can fire a pregnant
woman. It may be punishable by a maximum of 3 years of
imprisonment.
7. Income Tax Act, 1961:- In the case of tax violations, the tax
collection officer has the power to arrest you but before arresting
you, he/she will have to send a notice to you. Only Tax
Commissioner decides how long you will stay in the custody.
© Cengage Learning 2015
Indian Laws
8. Hindu Marriage Act 1955, Section -13: As per the Hindu
Marriage Act, 1955 (any husband or wife) may apply for divorce in
the court on the basis of Adultery (physical relationship outside of
marriage), physical and mental abuse, impotency, to leave home
without information, to change Hindu religion and adopt other
religion, insanity, incurable disease and no information about
husband or wife for seven-year.
9. As per the Citizen Charter (Indian Oil Corporation website):-
There are very few people who know that if their gas cylinder
blasts during the cooking of food then the gas agency is liable to
pay Rs. 50 lakh to the victim as compensation.
© Cengage Learning 2015
Indian Laws
10. Foreign Contribution Regulation Act (FCRA), 2010:- It would
surprise you to know that if you take a gift from any company on
the occasion of a festival, it falls into the category of bribery. You
can also be sentenced to jail for this crime.
11. Maximum Retail Price Act, 2014:- Any Shop keeper can’t
charge more than the printed price of any commodity, but a
consumer has the right to bargain for less than the printed price
of a commodity.
12. Limitation Act, 1963:- If your office does not pay you then you
have the power to file an FIR against it within 3 years. But if you
report after 3 years, you will not get anything for the due.
© Cengage Learning 2015
Following Legal Processes
© Cengage Learning 2015
Following Legal Processes
Digital Evidence First Responder (DEFR)
Arrives on an incident scene, assesses the situation, and
takes precautions to acquire and preserve evidence.
Digital Evidence Specialist (DES)
Has the skill to analyze the data and determine when
another specialist should be called in to assist.
Affidavit - a sworn statement of support of facts about or
evidence of a crime
Must include exhibits that support the allegation
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Private-sector investigations involve private companies
and lawyers who address company policy violations and
litigation disputes
Example: wrongful termination
Strive to minimize or eliminate litigation
Private-sector crimes can involve:
E-mail harassment, falsification of data, gender and age
discrimination, embezzlement, sabotage, and industrial
espionage © Cengage Learning 2015
Understanding Private-Sector
Investigations
Can reduce the risk of litigation by publishing and
maintaining policies that employees find easy to read and
follow.
Most important policies define rules for using the company’s
computers and networks.
Known as an “Acceptable use policy”
Line of authority - states who has the legal right to initiate
an investigation, who can take possession of evidence, and
who can have access to evidence
© Cengage Learning 2015
BCSE322L
Digital Forensics
Fall 2025-26
Dr. Aju D
Vellore Institute of Technology, Vellore
© Cengage Learning 2015
Understanding Private-Sector
Investigations
During private investigations, you search for evidence to
support allegations of violations of a company’s rules or
an attack on its assets
Three types of situations are common:
Abuse or misuse of computing assets (employee violation
of company rules).
E-mail abuse
Internet abuse
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Abuse / Misuse of Computing Assets
All instances of misuse are detrimental to an organization.
• Improper use of a company vehicle for vacations or other personal
recreation.
• Misuse of company work vehicles or equipment to perform side jobs
on weekends or after hours.
• Renting of company equipment or materials to third parties.
• Using the facility or company materials to create competing goods.
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Abuse / Misuse of Computing Assets
• Running a competing business out of your company.
• Providing family or friends with unsanctioned discounts or free
merchandise (sweet hearting).
• Misusing the company computer system or employee technology
permissions (hosting their own websites, running a side business
using company computers or other devices).
• Theft of office supplies and postage.
© Cengage Learning 2015
Understanding Private-Sector
Investigations
E-Mail abuse
The use of electronic mail to advertise unethically,
harass, annoy, or cause harm to the email recipient.
Bulk email
SPAM / UCE (Unsolicited Commercial Email)
Threatening e-mail (Extortion/ Sextortion)
E-mail sent with the intent to slow productivity
Cause damage to the recipient's computer system
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Internet abuse
Social Exclusion (caste, ethnicity, religion, gender
and disability)
Tagging without Permission
Flaming (derogatory message / Character
Assassination)
Sexting / Reposting
Impersonation / Identity Theft
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Sample text that can be used in internal warning banners:
Use of this system and network is for official business only.
Systems and networks are subject to monitoring at any time by the
owner.
Using this system implies consent to monitoring by the owner
Unauthorized or illegal users of this system or network will be
subject to discipline or prosecution.
© Cengage Learning 2015
Understanding Private-Sector
Investigations
Businesses are advised to specify an authorized requester
who has the power to initiate investigations
Examples of groups with authority
Corporate security investigations
Corporate ethics office
Corporate equal employment opportunity office
Internal auditing
The general counsel or legal department
© Cengage Learning 2015
Understanding Private-Sector
Investigations
The distinction between personal and company computer
property can be difficult with cell phones, smartphones,
personal notebooks, and tablet computers
BYOD environment
Some companies state that if you connect a personal device
to the business network, it falls under the same rules as
company property
© Cengage Learning 2015
Benefits of Professional Forensic
Methodology
Protection of evidence is critical.
o No possible evidence is damaged, destroyed, or otherwise compromised
by the procedures used to investigate the computer.
o No possible computer virus is introduced to a subject computer during the
analysis process.
o Extracted and possibly relevant evidence is properly handled and
protected from later mechanical or electromagnetic damage.
o A continuing chain of custody is established and maintained.
o Any client–attorney information who has inadvertently acquired during a
forensic exploration is ethically and legally respected and not divulged.
© Cengage Learning 2015
Steps taken by Computer
Forensics Specialists
1. Protect the subject computer system during the forensic
examination from any possible alteration, damage, data
corruption, or virus introduction.
2. Discover all files on the subject system. This includes existing
normal files, deleted yet remaining files, hidden files, password-
protected files, and encrypted files.
3. Recover all discovered deleted files.
4. Reveal all the contents of hidden files as well as temporary or
swap files used by both the app. Pgm. and the operating system.
© Cengage Learning 2015
Steps taken by Computer
Forensics Specialists
5. Access all the contents of protected or encrypted
files.
6. Analyze all possibly relevant data found in special
areas of a disk. (Unallocated space, Slack space
in a file).
7. Print out an overall analysis of the subject
computer system, as well as a listing of all possibly
relevant files and discovered file data.
© Cengage Learning 2015
Steps taken by Computer
Forensics Specialists
8. Provide an opinion of the system layout; the file
structures discovered; any discovered data and
authorship information; any attempts to hide,
delete, protect, and encrypt information; and any
other relevant data.
9. Provide expert consultation and/or testimony, as
required.
© Cengage Learning 2015
Digital Forensics Techniques
1. Digital forensics involves creating copies of a
compromised device and then using various
techniques and tools to examine the information.
2. Digital forensics techniques help inspect
unallocated disk space and hidden folders for
copies of encrypted, damaged, or deleted files.
© Cengage Learning 2015
Digital Forensics Techniques:
Reverse Steganography
• Cybercriminals use steganography to hide data
inside digital files, messages, or data streams.
• Reverse steganography involves analysing the
data hashing found in a specific file.
• When inspected in a digital file or image, hidden
information may not look suspicious.
© Cengage Learning 2015
Digital Forensics Techniques:
Cross-Drive Analysis
• Also known as anomaly detection, helps find similarities
to provide context for the investigation.
• These similarities serve as baselines to detect suspicious
events.
• It typically involves correlating and cross-referencing
information across multiple computer drives to find,
analyze, and preserve any information relevant to the
investigation. © Cengage Learning 2015
Digital Forensics Techniques:
Live Analysis
• Occurs in the operating system while the device or
computer is running.
• It involves using system tools that find, analyze, and
extract volatile data, typically stored in RAM or Cache.
• Live analysis typically requires keeping the inspected
computer in a forensic lab to maintain the chain of
evidence properly.
© Cengage Learning 2015
Digital Forensics Techniques:
Deleted File Recovery
• Known as data carving or file carving, is a technique that
helps recover deleted files.
• It involves searching a computer system and memory for
fragments of files that were partially deleted in one
location while leaving traces elsewhere on the inspected
machine.
© Cengage Learning 2015
Interesting Facts
• Sanmay Ved | [Link] | $12 | $6006.13 | Art of
Living
• [Link] | $700 | Amal Augustine |
Maxime Chan
© Cengage Learning 2015
Interesting Facts
© Cengage Learning 2015
Interesting Facts
© Cengage Learning 2015
Computer Crime?
Computer crime is an act performed by a knowledgeable
computer user, sometimes referred to as a hacker that illegally
browses or steals a company’s or individual’s private
information.
© Cengage Learning 2015
Computer Crimes?
Child Pornography Fraud • Human Trafficking
• Intellectual Property
Copyright Violation Software Piracy
Theft
Cracking Spamming
• Salami Slicing
Cyber Terrorism Spoofing • Scam
Cyber bullying Harvesting • Slander
Cyber Squatting Identity Theft • Typo Squatting
• Unauthorized Access
Creating Malwares Illegal Sales
• Wiretapping
Denial of Service IPR Violation
Espionage Phishing © Cengage Learning 2015
Protecting Data being
Compromised
1. Educate your employees
2. Create and update procedures
3. Remote monitoring
4. Data backup and recovery
5. Keep only what you need
6. Destroy before disposal
7. Safeguard physical data
8. Empower employees with best practices
9. Maintain up-to-date security software
10. Encrypt data
11. Protect portable devices
12. Hire an expert
© Cengage Learning 2015
What is Tracking on Internet?
Web tracking is often referred to as user
tracking, since data about user behaviour (across
domains) can be collected.
© Cengage Learning 2015
What data can be tracked?
1. Websites that are visited.
2. Sub-pages of a website that are visited.
3. How long the dwell time on individual sub-pages is.
4. From which website the current website was referred to.
5. Elements (links, buttons, etc.) that were clicked on.
6. Products that were viewed and purchased.
7. Which device and which browser were used.
8. Which files the website visitor downloads/Uploads.
9. What mouse or eye movements were©made on the website.
Cengage Learning 2015
How does Web tracking Work?
Cookies
• Session Cookies
• Persistent Cookies
• First-Party Cookies
• Third-Party Cookies
• Secure Cookies
© Cengage Learning 2015
How does Web tracking Work?
IP
• IPv4 / IPv6
• Public IP / Private IP
• Static IP / Dynamic IP
© Cengage Learning 2015
How does Web tracking Work?
Fingerprinting
1. Browser Fingerprinting
2. Device Fingerprinting
3. Audio and Canvas Fingerprinting
4. IP-based Fingerprinting
5. Behavioural Fingerprinting
© Cengage Learning 2015
How does Web tracking Work?
App Tracking
1. Tracking
2. Data Collection
3. Data Usage
© Cengage Learning 2015
How does Web tracking Work?
Email Tracking
1. Tracking
1. IP address (approximate location)
2. Device type (desktop, mobile, etc.)
3. Email client (e.g., Gmail, Outlook)
2. Link Tracking
3. Read Receipts © Cengage Learning 2015
Crime Investigation
Taking a Systematic Approach
Steps for problem solving
Make an initial assessment about the type of case you are
investigating
Determine a preliminary design or approach to the case
Create a detailed checklist
Determine the resources you need
Obtain and copy an evidence drive
Identify the risks
Mitigate or minimize the risks
Test the design © Cengage Learning 2015
Crime Investigation
Taking a Systematic Approach
Steps for problem solving (cont’d)
Analyze and recover the digital evidence
Investigate the data you recover
Complete the case report
Critique the case
© Cengage Learning 2015
Assessing the Case
Systematically outline the case details
Situation
Nature of the case
Specifics of the case
Type of evidence
Known disk format
Location of evidence
Based on these details, you can determine the case
requirements
Planning your Investigation
A basic investigation plan should include the following
activities:
Acquire the evidence
Complete an evidence form and establish a chain of custody
Secure evidence in an approved secure container
Transport the evidence to a computer forensics lab
Planning your Investigation
A basic investigation plan (cont’d):
Prepare your forensics workstation
Retrieve the evidence from the secure container
Make a forensic copy of the evidence
Return the evidence to the secure container
Process the copied evidence with computer forensics tools
Planning your Investigation
An evidence custody form helps you document what has
been done with the original evidence and its forensics
copies
Also called a chain-of-evidence form
Two types
Single-evidence form
Lists each piece of evidence on a separate page
Multi-evidence form
Single Evidence Form
Multiple Evidence Form
A sample multi-evidence from used on a private-sector environment
Securing your Device
Use evidence bags to secure and catalog the evidence
Use computer safe products when collecting computer
evidence
Antistatic bags
Antistatic pads
Use well-padded containers
Use evidence tape to seal all openings
CD drive bays
Insertion slots for power supply electrical cords and
USB cables
Securing your Device
Write your initials on tape to prove that evidence has not
been tampered with
Consider computer specific temperature and humidity
ranges
Make sure you have a safe environment for transporting
and storing it until a secure evidence container is available
Procedure
For
Private-Secor High-Tech Investigations
As an investigator, you need to develop formal procedures
and informal checklists.
To cover all issues important to high-tech investigations
Ensures that correct techniques are used in an investigation
© Cengage Learning 2015
Procedure
For
Private-Secor High-Tech Investigations
The majority of investigative work for termination cases involves
employee abuse of corporate assets
Incidents that create a hostile work environment are the predominant
types of cases investigated
Viewing pornography in the workplace
Sending inappropriate e-mails
Organizations must have appropriate policies in place
© Cengage Learning 2015
Internet Abuse Investigation
To conduct an investigation you need:
Organization’s Internet proxy server logs
Suspect computer’s IP address
Suspect computer’s disk drive
Your preferred computer forensics analysis tool
© Cengage Learning 2015
Internet Abuse Investigation
Recommended steps
Use standard forensic analysis techniques and procedures
Use appropriate tools to extract all Web page URL
information
Contact the network firewall administrator and request a
proxy server log
Compare the data recovered from forensic analysis to the
proxy server log
Continue analyzing the computer’s disk drive data
© Cengage Learning 2015
Email Abuse Investigation
To conduct an investigation you need:
An electronic copy of the offending e-mail that contains
message header data
If available, e-mail server log records
For e-mail systems that store users’ messages on a central
server, access to the server
Access to the computer so that you can perform a forensic
analysis on it
Your preferred computer forensics analysis tool
© Cengage Learning 2015
Email Abuse Investigation
Recommended steps
Use the standard forensic analysis techniques
Obtain an electronic copy of the suspect’s and victim’s e-
mail folder or data
For Web-based e-mail investigations, use tools such as
FTK’s Internet Keyword Search option to extract all related
e-mail address information
Examine header data of all messages of interest to the
investigation
© Cengage Learning 2015
Conducting an Investigation
Gather resources identified in investigation plan
Items needed
Original storage media
Evidence custody form
Evidence container for the storage media
Bit-stream imaging tool
Forensic workstation to copy and examine your
evidence
Securable evidence locker, cabinet, or safe
© Cengage Learning 2015
Understanding Bit-Stream Copies
Bit-stream copy
Bit-by-bit copy of the original storage medium
Exact copy of the original disk
Different from a simple backup copy
Backup software only copy known files
Backup software cannot copy deleted files, e-mail
messages or recover file fragments
Bit-stream image
File containing the bit-stream copy of all data on a disk
or partition
Also known as “image” or “image file”
© Cengage Learning 2015
Understanding Bit-Stream Copies
Copy image file to a target disk that matches the original
disk’s manufacturer, size and model
© Cengage Learning 2015
Acquiring an Image of Evidence Media
First rule of computer forensics
Preserve the original evidence
Conduct your analysis only on a copy of the data
Several vendors provide MS-DOS, Linux, and
Windows acquisition tools
Windows tools require a write-blocking device when
acquiring data from FAT or NTFS file systems
© Cengage Learning 2015
Analysing your Digital Evidence
Your job is to recover data from:
Deleted files
File fragments
Complete files
Deleted files linger on the disk until new data is saved on
the same physical location
Tools can be used to retrieve deleted files
ProDiscover Basic
© Cengage Learning 2015
Completing the Case
You need to produce a final report
State what you did and what you found
Include Autopsy / ProDiscover report to document your work
Repeatable findings
Repeat the steps and produce the same result
If required, use a report template
Report should show conclusive evidence
Suspect did or did not commit a crime or violate a company
policy
© Cengage Learning 2015
Completing the Case
Keep a written journal of everything you do
Your notes can be used in court
Answer the six Ws:
Who, What, When, Where, Why, and hoW
You must also explain computer and network
processes
© Cengage Learning 2015
Critiquing the Case
Ask yourself the following questions:
How could you improve your performance in the case?
Did you expect the results you found? Did the case develop in
ways you did not expect?
Was the documentation as thorough as it could have been?
What feedback has been received from the requesting source?
Did you discover any new problems? If so, what are they?
Did you use new techniques during the case or during
research?
© Cengage Learning 2015
© Cengage Learning 2015