CO2 – Digital Forensics Answers
1. Computers, Operating Systems & Nature of Digital Information
• A computer processes data using hardware and software components.
• The operating system manages hardware, memory, and files.
• Examples include Windows, Linux, and macOS.
• Digital data is stored in binary format.
• It can be easily copied or modified.
2. Filesystems Containing Digital Evidence
• A filesystem organizes how data is stored on a disk.
• Common filesystems include FAT32 and NTFS.
• Evidence may exist in active or deleted files.
• Hidden areas may also store evidence.
• Filesystem knowledge helps recovery.
3. Filesystem Category
• Includes disk structure and partitions.
• Shows how files are organized.
• Helps locate deleted data.
• Supports timeline reconstruction.
• Important in forensic analysis.
4. Filename Category
• Includes file names and extensions.
• Shows user naming behavior.
• Extensions indicate file type.
• Renaming can hide evidence.
• Helps detect manipulation.
5. Metadata Category
• Metadata describes file information.
• Includes creation and modification time.
• Stores author and file size.
• Helps build timelines.
• Crucial for investigations.
6. Content Category
• Refers to actual data in files.
• Includes text, images, and videos.
• Often contains direct evidence.
• Shows user intent.
• Key part of analysis.
7. Locating Evidence in File Systems
• Evidence exists in user folders.
• Temporary files may store traces.
• Recycle bin holds deleted files.
• Unallocated space contains remnants.
• Tools help locate data.
8. Password Security
• Passwords restrict unauthorized access.
• Strong passwords increase protection.
• Weak passwords are easy to crack.
• They complicate investigations.
• Legal methods are used to bypass.
9. Encryption
• Encryption protects data confidentiality.
• Data becomes unreadable format.
• Only keys can decrypt it.
• Creates forensic challenges.
• Used for data security.
10. Hidden Files
• Hidden files are concealed by OS.
• Not visible to normal users.
• Used to hide sensitive data.
• Criminals misuse them.
• Forensic tools can detect them.
11. Digital Evidence – Definition & Characteristics
• Digital evidence is electronic data.
• Used in investigations and courts.
• It is fragile in nature.
• Easily altered if mishandled.
• Needs proper preservation.
12. Technical Complexities of Digital Evidence
• Evidence may be encrypted.
• Large data volumes exist.
• Multiple devices involved.
• Deleted data is hard to recover.
• Advanced tools are required.
13. Value of Digital Evidence
• Helps establish facts.
• Identifies users.
• Builds event timelines.
• Supports investigations.
• Strengthens legal cases.
14. Admissibility of Digital Evidence
• Evidence must be relevant.
• Should be authentic.
• Integrity must be preserved.
• Chain of custody maintained.
• Only then accepted in court.
15. Linking Evidence to the User
• Uses login details.
• IP addresses trace activity.
• File ownership links users.
• Logs show timelines.
• Identifies responsible person.
16. Digital Evidence Recovery through Forensic Imaging
• Creates bit-by-bit copy.
• Original data remains safe.
• Hash values ensure integrity.
• Analysis done on copy.
• Accepted in courts.