0% found this document useful (0 votes)
2 views16 pages

Module 2 Computer Forensics Investigation Process

The document outlines the digital forensic investigation process, detailing stages such as identification, preservation, analysis, documentation, and reporting. It emphasizes the importance of maintaining evidence integrity and following legal protocols throughout the investigation. Additionally, it discusses the significance of Standard Operating Procedures (SOPs) and provides a checklist for preparing before an investigation.

Uploaded by

abhishekgupta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views16 pages

Module 2 Computer Forensics Investigation Process

The document outlines the digital forensic investigation process, detailing stages such as identification, preservation, analysis, documentation, and reporting. It emphasizes the importance of maintaining evidence integrity and following legal protocols throughout the investigation. Additionally, it discusses the significance of Standard Operating Procedures (SOPs) and provides a checklist for preparing before an investigation.

Uploaded by

abhishekgupta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module 02: Computer Forensics

Investigation Process
Digital forensic process involves the systematic and methodical investigation
of
digital devices, systems, and networks to gather and analyze digital
evidence for
legal purposes. It typically follows a structured approach to ensure the
integrity
and admissibility of evidence in court. The process can be broken down into
several stages:

1. Identification:
The identification phase is the starting point of the digital forensic process. It
helps the person conducting the investigation to get ready and plan the
steps.

Here's what happens in simpler terms:


 Case Intake: This is where the person doing the investigation learns
about the case. They find out who is involved, what happened, what kind
of evidence they need, and what the legal consequences might be.

 Case Assessment: The investigator tries to understand the case fully.


They figure out which digital devices might have important evidence, and
how important that evidence might be. They also decide what skills and
tools they need for the investigation.

 Objective Definition: The investigator decides what they want to find


out from the investigation. These are the specific questions they want to
answer. They make sure these objectives align with what the law requires
and what the investigation is expected to achieve.

 Legal and Ethical Considerations: The investigator makes sure they


follow all the laws and regulations that apply to collecting and analyzing
digital evidence. They also respect the rights of the people involved in the
case.

 Resource Allocation: The investigator figures out what resources they


need for the investigation, like staff, tools, and equipment.

 Risk Assessment: The investigator looks at the things that might go


wrong during the investigation and plans for those problems.

 Scope Definition: The investigator decides what digital devices and data
sources to check, and what specific areas to focus on.

 Initial Documentation: The investigator keeps detailed records of


everything they do and decide during the identification phase. This helps
keep everything transparent and accountable.

2. Preservation:
Preservation is the process of protecting digital evidence from alteration, damage, or deletion
after it has been identified and collected. The objective is to maintain the original state and
integrity of the evidence so that it remains admissible in court and reliable for forensic analysis.

Key Activities in Preservation

 Create a forensic bit-by-bit image of the original storage device.

 Use write-blockers to prevent any modification to the original evidence.

 Calculate and verify hash values (MD5, SHA-1, SHA-256) to confirm integrity.

 Maintain a proper chain of custody documenting every person who handled the evidence.

 Store evidence in secure, access-controlled environments.

 Protect evidence from physical damage, electromagnetic interference, and unauthorized


access.

Goal

 Ensure that digital evidence remains unchanged and legally admissible throughout the
investigation.

Example

If a suspect’s hard drive is seized, investigators create a forensic image, calculate its hash value,
seal the original drive, and perform all analysis on the forensic copy while preserving the original
evidence untouched.
3. Analysis:
The analysis phase involves using collected data to prove or disprove a case
built by the examiners. Here are key questions examiners need to answer for
all relevant data items:

 Who created the data

 Who edited the data

 How the data was created

 When these activities occur

In addition to supplying the above information, examiners also determine


how the information relates to the case.

The analysis phase in the digital forensic process is crucial. Here, the
gathered digital evidence is examined to not only understand what
happened but also how it happened. It involves complex and detailed
techniques to uncover data, including hidden, deleted, or encrypted data.

The steps typically include:

 Data Recovery: Extracting the data from the digital device. This can
involve recovering deleted files or accessing encrypted data.

 Examination: The data is then examined. This often involves looking for
specific files or types of files, examining data in detail, and looking for
evidence of particular activities.

 Analysis: The data is analyzed to draw conclusions about the digital


behavior of the suspect. This could be identifying patterns of behavior,
determining when certain files were created or accessed, or identifying
the source or destination of emails or other communications.

 Reporting: The findings are then written up into a formal report, detailing
the steps taken, the evidence found, and the conclusions drawn. This may
be used in a court of law or for other official purposes.

4. Documentation:
The documentation process in digital forensic investigations is very
important, as it permanently records all relevant information generated
during the investigation.

Forensic investigation professionals dedicate a significant amount of time,


between 50%-75%, to writing administrative and research reports.

Computers are often involved in criminal investigations. For instance,


through a search warrant, the email and internet activities of murder and
rape suspects may be analyzed to gather evidence about motives or hiding
locations.

In the corporate world, computers are investigated when an employee is


suspected of unauthorized actions.

Fraud investigations often involve collecting transaction history evidence


from servers.

5. Presentation/ Reporting:
To present the evidence in a way the court consider it admissible and bring
the guilty to justice, formulating a coherent and comprehensive digital
forensics report is crucial.

At the same time, investigators should keep in mind that other law
enforcement institutions may ask for the report in order to:

 Details of the reporting agency


 Forensic investigator
 Identity of the submitter
 Date of evidence receipt
 Details of the device seized for examination including serial number,
make, and model
 Details of the equipment and tools used in the examination
 Description of steps taken during examination
 Chain of custody documentation
 Details of findings or issues identified
 Evidence recovered during the examination from chat messages, browser
history, and call logs to deleted messages, and so on
 Any images captured during the examination
 Examination and analysis information
 Report conclusion
Chain of Custody
Standard Operating Procedure (SOP)
A Standard Operating Procedure (SOP) is a documented set of step-by-step
instructions that explains how a specific task or process should be performed
consistently and correctly. In digital forensics, SOPs ensure that evidence is
handled in a standardized, repeatable, and legally defensible manner.

Purpose of SOP
 To maintain consistency in forensic investigations.

 To ensure compliance with legal and organizational requirements.


 To preserve the integrity and admissibility of digital evidence.
 To reduce errors and improve the quality of investigations.
 To provide clear guidance to investigators.

Key Components of an SOP


 Objective and scope of the procedure.

 Roles and responsibilities of personnel.

 Required tools and equipment.

 Step-by-step process instructions.

 Documentation and reporting requirements.

 Quality assurance and review procedures.

Example in Digital Forensics


 An SOP for hard disk acquisition may specify:

 Use a hardware write blocker.

 Create a bit-by-bit forensic image.

 Calculate and verify hash values.

 Document chain of custody.

 Store original evidence securely.

Goal
 To ensure that all forensic procedures are performed in a consistent,
reliable, and legally acceptable manner.
WHAT IS CRIME SCENE INVESTIGATION?
Crime scene investigation is the process of identifying, analyzing, and
mitigating computer on crime scene. It involves the use of specialized tools
and techniques to investigate various types of cybercrimes, such as hacking,
phishing, malware, data breaches, and identity theft.
Objectives of Crime Scene Investigation
 Identify all potential sources of evidence.

 Collect and preserve evidence without altering its original state.

 Document the condition of the crime scene.

 Maintain chain of custody.

 Analyze evidence to reconstruct what happened.

 Present findings in a legally admissible manner.

Types of Evidence Collected


 Computers, laptops, and mobile devices.

 Hard drives, SSDs, USB drives, and memory cards.

 Log files, emails, chat messages, and browser history.

 Photographs, CCTV footage, and handwritten notes.

 Network devices such as routers and firewalls.

Steps in Crime Scene Investigation


1. Secure the Scene – Prevent unauthorized access and protect evidence.
2. Document the Scene – Take photographs, videos, and detailed notes.
3. Identify Evidence – Locate all relevant physical and digital items.
4. Collect Evidence – Seize devices and create forensic images.
5. Preserve Evidence – Use write blockers, hash values, and secure
storage.
6. Analyze Evidence – Examine data using forensic tools.
7. Report Findings – Prepare a clear and complete forensic report.

Important Precautions
 Do not power on a device unless necessary.

 Capture volatile data (RAM, running processes, network connections)


when appropriate.

 Always work on forensic copies, not on original evidence.

 Follow Standard Operating Procedures (SOPs).


Raids in Digital Forensics
A raid is a planned law-enforcement operation conducted to search a
location, seize devices, and collect evidence related to a crime. In
cybercrime investigations, raids are carried out at homes, offices, or data
centers to obtain computers, mobile phones, storage devices, documents,
and other relevant evidence.

Incident Response
Incident Response is a structured process used to detect, analyze, contain,
eradicate, and recover from cybersecurity incidents such as malware
infections, ransomware attacks, data breaches, and unauthorized access. Its
purpose is to minimize damage, reduce recovery time, and prevent similar
incidents in the future.
Checklist to Prepare Before the Investigation
A pre-investigation checklist is a list of tasks and materials that investigators
should complete before starting a digital forensic investigation. It helps
ensure that the investigation is organized, legally compliant, and technically
prepared.

Legal Preparation
 Obtain search warrant, court order, or written authorization.

 Define the scope and objectives of the investigation.

 Review applicable laws, policies, and jurisdiction requirements.

 Prepare chain of custody and evidence forms.

Team Preparation
 Assign roles and responsibilities to each team member.

 Conduct a briefing about objectives, risks, and procedures.


Equipment Checklist
 Laptop with forensic software installed.

 Hardware and software write blockers.


 External storage devices for forensic images.

 Cables, adapters, and power supplies.

 Camera or mobile phone for scene documentation.


 Faraday bags, labels, tamper-evident seals, and markers.
 Anti-static bags and gloves.

 An anti-static bag is a specialized packaging material designed to protect sensitive


electronic components from damage caused by electrostatic discharge

Equipment’s and tools software


Disk Imaging and Analysis
 FTK Imager

 EnCase
 Autopsy
 Magnet AXIOM

Memory Forensics
 Volatility

 FTK Imager

 Magnet Memory Capture

Network Forensics
 Wireshark

Mobile Forensics
 Magnet AXIOM

 Oxygen Forensic Detective


Hashing and Verification
 HashCalc

 PowerShell - Get-FileHash

You might also like