FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
FACT EXAM 2025
Forensic Aptitude and Competence Test
Specialization: DIGITAL FORENSICS
Section A: Aptitude in Forensic Science
Comprehensive Study Notes – All Examinable Topics
Prepared for: FACT 2025 Aspirants | Covers: Syllabus Sections A (Digital Forensics Specialization)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 1: Foundations of Forensic Science
1.1 Principles and Scope of Forensic Science
Forensic science is the application of scientific methods and techniques to matters under
investigation by law. The word 'forensic' originates from the Latin 'forensis' meaning 'of the forum'
(public debate/court).
Locard's Exchange Principle
Every contact leaves a trace. When two objects come into contact, material is exchanged between
them. This is the cornerstone of physical evidence.
KEY Locard's Exchange Principle: 'Every contact leaves a trace.' Formulated by Dr.
PRINCIPL Edmond Locard (1877-1966), Director of the first forensic laboratory in Lyon,
E France.
Scope of Forensic Science
• Criminal investigations (homicide, assault, robbery, cybercrime)
• Civil litigation (document disputes, accident reconstruction)
• Counter-terrorism and national security
• Corporate investigations (fraud, IP theft)
• Environmental forensics
• Digital evidence analysis
1.2 Disciplines of Forensic Science
Discipline Function / Scope
Forensic Ballistics Examination of firearms, bullets, cartridge cases, gunshot residue
Forensic Chemistry Analysis of drugs, explosives, fire debris, unknown substances
Digital Forensics Recovery and investigation of digital evidence from computers,
networks, mobile devices
Forensic Document Handwriting analysis, questioned documents, ink dating
Examination
Forensic Biology / DNA Identification via biological evidence (blood, hair, saliva)
Forensic Toxicology Detection of drugs/poisons in biological samples
Forensic Odontology Dental identification; bite mark analysis
Forensic Entomology Estimating time of death using insect evidence
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Forensic Psychology Criminal profiling, competency evaluation
Forensic Accounting Financial fraud investigation
1.3 Developments in Forensic Science – India & Globally
India
• 1878: First Fingerprint Bureau established in Calcutta (Kolkata)
• 1897: Fingerprint identification first used in a criminal case in India
• 1952: CBI Forensic Science Laboratory established
• 2002: DNA profiling legally recognized under Indian Evidence Act
• 2005: National Forensic Sciences University (NFSU) established in Gandhinagar, Gujarat
(formerly GFSL)
• 2020: NFSU Act passed – first national university dedicated to forensic sciences
• Forensic Science Laboratories (FSLs) in all states and Union Territories
Global Milestones
• 1784: First documented use of physical matching evidence (James Marsh, UK)
• 1892: Francis Galton published 'Fingerprints' – classification system
• 1910: Edmond Locard establishes the world's first forensic laboratory
• 1932: FBI Crime Laboratory established (USA)
• 1984: First DNA fingerprinting by Sir Alec Jeffreys (UK)
• 1998: CODIS (Combined DNA Index System) launched in USA
• 2001: Digital Forensics Research Workshop (DFRWS) established
1.4 Role of Forensic Science Laboratories
• Analyze physical, chemical, biological, and digital evidence
• Provide expert opinions/reports for courts
• Conduct research in emerging forensic methodologies
• Train law enforcement personnel
• Maintain reference databases (fingerprint, DNA, narcotics)
• Quality assurance and proficiency testing
Key Institutions in India
Institution Role
NFSU, Gandhinagar Premier forensic education & research university
CFSL, New Delhi / Mumbai / Central Forensic Science Laboratories under MHA
Hyderabad / Kolkata
State FSLs State-level analysis and court reporting
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
CBI FSL Investigations under Central Bureau of Investigation
AIIMS Forensic Division Medico-legal examinations
1.5 Eminent Forensic Scientists
Scientist Contribution
Edmond Locard (France) Locard's Exchange Principle; established first forensic lab
Francis Galton (UK) Fingerprint classification system
Alec Jeffreys (UK) Invented DNA fingerprinting (1984)
Henry Faulds (Scotland) Proposed using fingerprints for identification
Karl Landsteiner (Austria) ABO blood group system
Luke May (USA) Pioneer in tool mark examination
Dr. P. Chandra Sekharan (India) Superimposition technique; forensic odontology
Dr. R.K. Sharma (India) DNA forensics pioneer in India
Edward Henry (UK/India) Henry Classification System for fingerprints (Calcutta)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 2: Crime Scene and Evidence Management
2.1 Types of Crimes and Evidence
Crime Type Key Evidence Materials
Cybercrime / Digital Fraud Digital devices, logs, network traffic, metadata
Homicide Biological evidence, fingerprints, firearms, footprints
Sexual Assault DNA, trace evidence, digital devices, CCTV
Drug Offences Chemical analysis, packaging, digital records
Forgery / Document Fraud Questioned documents, ink analysis, digital files
Financial Fraud Digital records, emails, accounting data
Terrorism Explosives residue, digital communications, surveillance
Theft / Burglary Fingerprints, tool marks, surveillance footage
2.2 Classification of Evidence
By Nature
• Physical Evidence: Tangible objects (weapons, tools, clothing, digital devices)
• Biological Evidence: Blood, hair, saliva, semen, plant material
• Chemical Evidence: Drugs, explosives, poisons, accelerants
• Digital Evidence: Data stored or transmitted in electronic form
• Documentary Evidence: Written/printed documents, photographs
• Trace Evidence: Microscopic materials transferred during crime (fibres, glass, soil)
By Significance
• Direct Evidence: Directly proves a fact (eyewitness, confession)
• Circumstantial Evidence: Implies a fact by inference
• Corroborative Evidence: Supports existing evidence
• Exculpatory Evidence: Proves innocence
By Characteristics
• Class Characteristics: Features shared by group (e.g., same manufacturer's bullet type)
• Individual Characteristics: Unique to one specific source (e.g., rifling marks, fingerprints,
DNA)
EXAM Class vs. Individual characteristics is a high-frequency MCQ topic. DNA, fingerprints,
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
and rifling marks = INDIVIDUAL characteristics. Bullet calibre, shoe sole pattern =
ALERT
CLASS characteristics.
2.3 Crime Scene Management
First Responder Duties
1. Secure and isolate the crime scene
2. Render aid to injured – call medical services
3. Detain and separate witnesses
4. Protect evidence from contamination
5. Log entry/exit of all personnel
6. Brief the lead investigator on arrival
Search Methods
Method Description & Best Use
Strip / Line Search Parallel lanes; outdoor scenes; large areas
Grid Search Double strip at right angles; maximizes coverage
Spiral Search Inward or outward from a central point; compact areas
Zone / Sector Search Area divided into zones; indoor scenes; multiple teams
Wheel / Ray Search Radiates from a central point; vehicle scenes
Crime Scene Documentation
• Notes: Chronological narrative, systematic, factual
• Sketches: Rough sketch (at scene) → Finished scale sketch
• Types of sketches: Overview, Elevation, Cross-projection, Perspective
• Measurements: Triangulation method, Baseline method, Polar coordinate method
• Photography: Overall → Medium → Close-up (with and without scale marker)
• Videography: Continuous walkthrough before touching anything
SEQUEN Documentation Sequence: Photography FIRST → Sketch → Notes → Evidence
CE collection. NEVER collect before photographing.
2.4 Fingerprints, Footprints, and Pattern Evidence
Types of Fingerprints
Type Description
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Latent Prints Invisible; deposited by sweat/oil; require development
Patent Prints Visible; made in soft substances (grease, blood, paint)
Plastic Prints 3D impressions in soft material (wax, putty, fresh paint)
Development of Latent Fingerprints
• Non-porous surfaces: Aluminium powder, Carbon powder, Magnetic powder
• Porous surfaces: Ninhydrin (amino acids), DFO, Physical Developer, Iodine fuming
• Bloody prints: Acid Violet 17, Acid Yellow 7, Leucocrystal Violet
• Cyanoacrylate (Super Glue) fuming: Non-porous, multi-surface
• Small Particle Reagent: Wet non-porous surfaces
• Luminescent techniques: DFO, Rhodamine 6G (requires ALS/laser)
Fingerprint Ridge Characteristics (Minutiae)
• Ridge ending, Bifurcation, Short ridge (island), Dot, Enclosure (lake), Spur, Crossover,
Delta, Core
Henry Classification System
• Three basic patterns: Loop (65%), Whorl (30%), Arch (5%)
• Loops: Radial (toward radius/thumb) or Ulnar (toward little finger)
• Whorls: Plain, Central Pocket Loop, Double Loop, Accidental
• Arches: Plain Arch, Tented Arch
2.5 Evidence: Identification, Collection, Packaging
Stage Key Considerations
Identification Recognize evidentiary value; prioritize volatile/perishable evidence
Collection Minimum handling; use gloves, forceps; collect controls/standards
Preservation Prevent contamination, degradation; biological in paper, not plastic
Packaging Individual packaging; avoid cross-contamination; seal and label
Labelling Case no., date, item no., description, collector's signature, chain of
custody
Transport Tamper-evident seals; maintain temperature for biological samples
Chain of Custody Unbroken documentation of every person handling evidence
Digital Evidence – Special Considerations
• Photograph device in situ before touching
• Note power state (ON/OFF matters critically)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
• Do NOT switch ON a powered-off device
• Isolate from network: Faraday bag/cage to block RF signals
• Use write blockers when imaging
• Create forensic image (bit-for-bit copy); verify with hash (MD5/SHA-256)
• Document IMEI, serial numbers, SIM card details
2.6 Crime Scene Reconstruction
• Bloodstain Pattern Analysis (BPA): Directionality, area of origin, weapon type
• Shooting reconstruction: Trajectory analysis, GSR distribution, cartridge ejection patterns
• Staged crime scenes: Indicators of post-mortem movement, anomalous evidence placement
• Locard's Principle applies: trace evidence tells the story of contact
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 3: Quality Assurance in Forensic Science
3.1 QC and QA in Forensic Evidence Analysis
Quality Control (QC): Technical procedures applied to individual tests/measurements to ensure
accuracy (e.g., running control samples alongside unknowns).
Quality Assurance (QA): Broader system of policies and procedures to ensure the overall quality
of forensic operations.
Quality Management System (QMS): Integrated system encompassing all QA and QC activities in
a laboratory.
Key Elements of QA in Forensic Labs
• Standard Operating Procedures (SOPs)
• Validated analytical methods
• Equipment calibration and maintenance logs
• Chain of custody documentation
• Training and competency records
• Internal audits and management reviews
• Corrective and Preventive Action (CAPA)
3.2 Accreditation Standards
Standard Application
ISO/IEC 17025:2017 General requirements for testing/calibration laboratory competence
– the primary forensic lab standard
ISO 9001:2015 Quality management systems – general organizations
ASCLD (USA) American Society of Crime Laboratory Directors accreditation
NABL (India) National Accreditation Board for Testing and Calibration
Laboratories
BIS Bureau of Indian Standards
3.3 Proficiency Testing
• External Proficiency Tests: Samples from external providers; blind testing
• Internal QC: Duplicate analyses, reagent blanks, positive/negative controls
• Inter-laboratory Comparisons: Same sample analyzed by multiple labs
• Collaborative Exercises: Round-robin tests among partner laboratories
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
ISO/IEC 17025:2017 is the MOST IMPORTANT accreditation standard for forensic
ISO 17025 laboratories. Covers both management requirements (documentation, audits) and
technical requirements (validation, measurement uncertainty).
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 4: Instrumentation and Analytical Techniques
4.1 Electromagnetic Radiation and Matter Interaction
Region (Short → Long Forensic Application
wavelength)
Gamma / X-ray Bone analysis, gunshot residue elemental analysis (XRF)
Ultraviolet (UV) Questioned document examination; drug fluorescence
Visible Light Colour analysis; trace evidence; ALS examinations
Infrared (IR) Drug identification; fibre analysis; paint layer analysis
Microwave / Radio Forensic radar; cell tower data extraction
Alternate Light Source (ALS) Latent fingerprints, body fluids, trace evidence
4.2 Microscopy
Microscope Type Forensic Use
Stereo (Comparison) Toolmarks, bullets, cartridge case comparison
Microscope
Compound Light Microscope Fibres, hair, pollen, biological samples
Scanning Electron Microscope GSR particles (morphology); microstructure
(SEM)
SEM-EDX / SEM-EDS GSR elemental analysis (Pb, Ba, Sb)
Polarizing Light Microscope Fibre ID, crystallography, soil minerals
(PLM)
Transmission Electron Nanoparticle analysis; asbestos fibres
Microscope (TEM)
Fluorescence Microscope DNA staining; latent print development (DFO)
4.3 Spectroscopy and Spectrophotometry
Technique Forensic Application
UV-Vis Spectrophotometry Drug concentration; ink comparison; glass analysis
Infrared Spectroscopy (FTIR) Drug identification; polymer/paint/fibre analysis; unknown
substance ID
Raman Spectroscopy Non-destructive drug/explosive ID; gemstone analysis; ink
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Atomic Absorption Trace metal analysis; GSR; poisoning cases
Spectroscopy (AAS)
ICP-MS / ICP-OES Multi-element trace analysis; soil/glass comparison
X-Ray Fluorescence (XRF) Elemental composition; counterfeit coin analysis; paint layers
Nuclear Magnetic Resonance Structural elucidation of unknown drugs
(NMR)
Mass Spectrometry (MS) Molecular identification; drug analysis; forensic toxicology
4.4 Chromatography
Technique Forensic Application
Thin Layer Chromatography Preliminary drug screening; ink comparison; explosives
(TLC)
Gas Chromatography (GC) Volatile compounds; arson accelerants; drugs; alcohol
GC-MS (Gold Standard) Confirmatory drug identification; toxicology; explosive residues
High-Performance Liquid Non-volatile drugs; explosives (TATP); dye analysis
Chromatography (HPLC)
LC-MS / LC-MS/MS Trace drug metabolites; novel psychoactive substances
Ion Chromatography (IC) Explosive anion/cation analysis; water contamination
4.5 Electrophoresis
Technique Application
Gel Electrophoresis DNA fragment separation (agarose gel)
Capillary Electrophoresis (CE) STR profiling; DNA sequencing; inkjet ink dating
Polyacrylamide Gel (PAGE) Protein separation; blood grouping
SDS-PAGE Protein molecular weight determination
Electrophoresis in BPA Bloodstain enzyme typing (historical)
4.6 Basics of Computer Systems and Digital Evidence
Computer Architecture
• CPU: Central Processing Unit – fetch, decode, execute instructions
• RAM: Volatile memory – lost when power off (critical for live forensics)
• ROM/Storage: Non-volatile (HDD, SSD, Flash, Optical)
• Operating System: Windows, Linux, macOS, Android, iOS
• File System: NTFS (Windows), ext4 (Linux), APFS/HFS+ (macOS), FAT32, exFAT
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
File System Fundamentals
Concept Forensic Relevance
Inode (Linux) Stores file metadata: permissions, timestamps, size, pointers
MFT (Windows NTFS) Master File Table – records metadata for every file
Slack Space Space between end of file data and end of cluster; can contain
residual data
Unallocated Space Space previously used by deleted files; recoverable data
Metadata Created/Modified/Accessed/Changed (MAC) timestamps
File Signature Magic bytes/header identifying true file type (vs. extension)
Journaling File system log of changes – aids in timeline reconstruction
Data Storage Media
• HDD (Hard Disk Drive): Magnetic platters; recoverable after deletion via magnetic force
• SSD (Solid State Drive): NAND flash; TRIM command complicates recovery
• Mobile Storage: NAND flash (eMMC, UFS); challenging due to encryption
• Cloud Storage: Data on remote servers; requires legal process (mutual legal assistance)
• RAM: Volatile; live acquisition mandatory; contains passwords, encryption keys, running
processes
• USB / Flash Drives: FAT32/exFAT; common exfiltration vector
• CD/DVD: Optical media; surface analysis for scratches; recovered with Error Correction
4.7 Imaging and Authentication of Digital Evidence
Forensic Imaging
• Bit-stream copy (forensic image): Exact sector-by-sector duplication of entire storage media
• Logical image: Only active files/folders (faster; less comprehensive)
• Formats: RAW/dd, E01 (EnCase), AFF (Advanced Forensic Format), AFF4
• Write Blockers: Hardware or software devices that prevent any write operations to original
media
Hash Verification
• MD5 (128-bit): Fast; still used for verification but cryptographically weak
• SHA-1 (160-bit): Better than MD5 but deprecated
• SHA-256 (256-bit): Current standard – use for evidential integrity
• SHA-3: Next-generation; quantum-resistant potential
Hash value = 'digital fingerprint' of evidence. If hash of image matches hash of
CRITICAL
original = no modification. ANY change to even 1 bit changes the hash completely.
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Chain of Custody in Digital Forensics
• Documented from seizure to court presentation
• Every copy (image) must be hashed and documented
• Examination only on forensic image; original sealed in evidence bag
• Write-protect sticker + write blocker = dual protection
4.8 Forensic Photography
• Overall/General: Wide angle; establishes scene context
• Medium/Evidence-establishing: Shows relationship between items
• Close-up/Detail: Without scale, then with ABFO No. 2 scale marker
• Macro photography: Minute details (fingerprints, tool marks)
• Alternate Light Source (ALS) photography: Filtered lens; UV/IR
• Aerial photography (drones): Large outdoor crime scenes
• 3D photogrammetry: Crime scene reconstruction
4.9 Statistical Concepts in Forensic Science
Precision vs. Accuracy
• Accuracy: Closeness of measurement to true value
• Precision: Reproducibility; closeness of repeated measurements to each other
• A measurement can be precise but not accurate (systematic error), or accurate but not
precise (random error)
Error Types
• Systematic Error: Consistent bias; affects accuracy; caused by calibration errors, method
bias
• Random Error: Unpredictable variation; affects precision; minimized by replication
Statistical Tests
Test Forensic Application
F-test (Variance Ratio Test) Compare variances of two datasets; check if two populations are
statistically similar
Chi-Square (χ²) Test Test independence or goodness-of-fit; compare observed vs.
expected frequencies
t-test Compare means of two groups
ANOVA Compare means of multiple groups simultaneously
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Measurement Uncertainty
• Every measurement has an associated uncertainty (not error)
• Expressed as: Result ± U (e.g., 25.3 ± 0.2 mg)
• Sources: Instrument resolution, calibration, environmental variation, analyst variability
• Combined Uncertainty: Square root of sum of squares of all component uncertainties
Sampling
Sampling Type Description
Simple Random Sampling Every item has equal chance of selection
Systematic Sampling Every nth item selected
Stratified Sampling Population divided into strata; random sample from each
Cluster Sampling Groups (clusters) randomly selected; all members examined
Purposive/Judgement Analyst selects based on expertise (not statistical)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 5: Legal Framework and Ethics in Forensic Science
5.1 Role of Expert Testimony
• Expert witness: A person with specialized knowledge, skill, experience, or training
• Provides opinion evidence (not just factual testimony)
• Must present findings clearly, objectively, and impartially
• Expert report: Methodology, observations, results, conclusions
• Cross-examination: Expert must defend methodology and conclusions
• Daubert Standard (USA): Scientific testimony must be tested, peer-reviewed, have known
error rate, and be generally accepted
• In India: Governed by Bharatiya Sakshya Adhiniyam (BSA), 2023
5.2 New Indian Criminal Laws (2023)
IMPORTA The three new criminal laws replaced IPC (1860), CrPC (1973), and Indian Evidence
NT Act (1872) from July 1, 2024. FACT exam will test knowledge of these.
New Law Replaced / Covers
Bharatiya Nyaya Sanhita (BNS), Replaces IPC 1860 – defines offences and punishments
2023
Bharatiya Nagarik Suraksha Replaces CrPC 1973 – criminal procedure; investigation, trial, bail
Sanhita (BNSS), 2023
Bharatiya Sakshya Adhiniyam Replaces Indian Evidence Act 1872 – admissibility and evidence
(BSA), 2023 rules
Key Provisions Relevant to Forensic Science
• BNS: Organised crime (Sec. 111); Terrorism (Sec. 113); expanded cybercrimes
• BNSS: Forensic investigation mandatory for offences punishable with 7+ years (Sec. 176);
audio-video recording of crime scene; electronic summons
• BSA: Electronic records as primary evidence (Sec. 57, 58, 63); electronic certificates for
admissibility; expert evidence (Sec. 39)
5.3 Admissibility of Evidence
General Principles
• Evidence must be: Relevant, Reliable, Authentic, and Not excluded by law
• Best Evidence Rule: Original document preferred over copies
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
• Hearsay: Generally inadmissible except statutory exceptions
• Exclusionary Rule: Illegally obtained evidence may be excluded
Electronic Evidence under BSA 2023
• Electronic records are admissible as documentary evidence
• Section 63 (BSA): Electronic records admissible if accompanied by certificate
• Certificate must be signed by responsible official; states hash value, extraction method, and
chain of custody
• WhatsApp chats, emails, CCTV footage, call records – all electronic records
5.4 Digital Evidence Laws and Cyber Forensics Provisions
Law / Act Relevance
Information Technology Act, Cybercrime definitions; Sec. 65, 65B – electronic evidence; Sec. 66
2000 (IT Act) – hacking; Sec. 67 – obscene content
IT (Amendment) Act, 2008 Identity theft (66C), phishing (66D), voyeurism (66E), cyber
terrorism (66F)
BSA 2023 (Sec. 57-63) Electronic records as primary evidence; certificate requirements
BNSS 2023 (Sec. 94) Production of documents/electronic records by court order
POCSO Act, 2012 Child sexual abuse material (CSAM) – digital evidence critical
Prevention of Money Digital transaction records, cryptocurrency trails
Laundering Act (PMLA)
Section 65B – IT Act (Now replaced by BSA)
• Historical context: Sec. 65B IEA required certificate for electronic evidence admissibility
• Anvar P.V. v. P.K. Basheer (2014): SC held Sec. 65B certificate mandatory
• Arjun Panditrao Khotkar v. Kailash Gorantyal (2020): Certificate must be filed at time of
producing evidence
• Under BSA 2023: Similar certificate requirement retained in Sec. 63
5.5 Data Protection and Privacy
Digital Personal Data Protection (DPDP) Act, 2023
• India's comprehensive data privacy legislation
• Data Principal: Individual whose data is processed
• Data Fiduciary: Entity that determines purpose/means of processing
• Data Processor: Processes data on behalf of fiduciary
• Consent-based processing with exceptions for state security, law enforcement
• Data Protection Board: Adjudicatory body for violations
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
• Forensic implication: Government agencies may access data for criminal investigations with
proper legal authority
Privacy Considerations in Digital Forensics
• Search and seizure must be authorized (warrant or lawful authority)
• Scope of examination limited to warrant parameters
• Third-party data discovered incidentally (plain view doctrine considerations)
• Cross-border data: Mutual Legal Assistance Treaties (MLATs)
• Attorney-client privilege and other protected communications
5.6 Ethics in Forensic Science
Core Ethical Principles
• Objectivity: Unbiased analysis; findings follow evidence
• Accuracy: Report only what can be supported by scientific methodology
• Integrity: No fabrication, falsification, or plagiarism
• Impartiality: Expert serves the court, not the party retaining them
• Confidentiality: Protect case information; only disclose as required by law
• Competence: Only perform analyses within area of expertise
• Transparency: Full disclosure of methods, limitations, uncertainties
Common Ethical Violations in Forensic Science
• Confirmation bias: Seeking evidence to confirm existing hypothesis
• Dry-labbing: Reporting results without performing tests
• Over-stating certainty: Claiming definitive match without statistical basis
• Contextual bias: Allowing irrelevant case information to influence analysis
• Cognitive bias: Unconscious influence of prior expectations
Fred Zain (West Virginia) and Annie Dookhan (Massachusetts) cases: Famous
HIGH-
examples of forensic fraud – fabricated results affected hundreds of convictions.
YIELD
Study these for ethics questions.
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 6: Digital Forensics – Specialization (Core Unit)
6.1 Introduction and Scope
Digital forensics involves the identification, preservation, collection, analysis, and presentation of
digital evidence in a manner that is legally admissible in a court of law.
Sub-disciplines of Digital Forensics
Sub-discipline Focus Area
Computer Forensics Desktops, laptops, hard drives, file systems
Mobile Device Forensics Smartphones, tablets, wearables, SIM cards
Network Forensics Packet capture, logs, intrusion detection, traffic analysis
Cloud Forensics Data on cloud platforms; virtual machines; multi-tenancy issues
Memory Forensics RAM acquisition; volatile data; malware analysis
Database Forensics SQL/NoSQL databases; transaction logs; data manipulation
Malware Forensics Reverse engineering; malicious code analysis
IoT Forensics Smart devices; embedded systems; firmware analysis
Email Forensics Header analysis; phishing; email routing
Social Media Forensics Platform data; metadata; open-source intelligence (OSINT)
6.2 Digital Forensics Process Model
DFRWS Model (2001) – Classic Framework
7. Identification: Recognize potential digital evidence; define investigation scope
8. Preservation: Prevent alteration; maintain integrity (write blockers, Faraday bags)
9. Collection: Acquire data (forensic imaging; live acquisition; cloud collection)
10. Examination: Process and filter acquired data; file recovery; artifact extraction
11. Analysis: Interpret examined data; correlate events; build timeline
12. Presentation: Prepare expert report; testify; court-ready documentation
ACPO Principles (UK – Association of Chief Police Officers)
• Principle 1: No action should change data held on digital device that may be relied upon in
court
• Principle 2: If necessary to access original data, the person must be competent and able to
explain relevance and implications
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
• Principle 3: Audit trail must be created and preserved; independent third party must be able
to replicate and achieve same results
• Principle 4: Lead investigator has overall responsibility for ensuring these principles are
adhered to
6.3 Computer Forensics
Windows Artifacts (Key Forensic Locations)
Artifact Location / Forensic Value
Registry HKEY_LOCAL_MACHINE, HKEY_CURRENT_USER – user
activity, program execution, USB devices
Event Logs C:\Windows\System32\winevt\Logs – security, system, application
events
Prefetch Files C:\Windows\Prefetch\ – evidence of program execution (up to 128
entries)
LNK Files / Jump Lists Recent files and applications accessed; timestamps
$MFT Master File Table – complete file system record
Recycle Bin ($I/$R files) Deleted files metadata; original path and deletion time
Browser History Edge/Chrome/Firefox – URLs, downloads, searches, cookies
Shellbags Folder browsing history; even deleted folders
Amcache/Shimcache Program execution evidence; file metadata
[Link] User-specific registry hive – typed URLs, recent documents, run
commands
[Link] Hibernation file – RAM snapshot; volatile data preserved
[Link] / [Link] Virtual memory – may contain fragments of running processes
Volume Shadow Copies (VSS) Previous file versions; may contain deleted data
Linux Artifacts
• /var/log/: System logs ([Link], syslog, [Link])
• .bash_history: Command history per user
• /etc/passwd and /etc/shadow: User accounts and password hashes
• /proc/: Virtual filesystem; running process information
• /tmp/: Temporary files; often used by malware
• Syslog, [Link]: Authentication events, sudo usage
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
6.4 Mobile Device Forensics
Acquisition Levels (Least to Most Data)
Level Method Data Obtained
Manual Browse device interface Limited; only visible data; not forensically
sound
Logical ADB (Android), iTunes backup Files, databases, apps; no deleted data
(iOS)
File System Full file system dump All files including app data; some deleted data
Physical Chip-off, JTAG, memory dump Complete raw image; deleted data; encrypted
data accessible
Cloud iCloud/Google account Backups, synced data; requires credentials or
extraction legal order
Android vs. iOS Forensics
Feature (Android / iOS) Details
File System Android: ext4, F2FS, YAFFS2 | iOS: APFS (newer), HFS+ (older)
Backup Method Android: ADB backup; Google backup | iOS: iTunes/Finder; iCloud
Encryption Android: File-based (FBE) or Full-disk | iOS: Full disk (hardware);
Secure Enclave
Key Artifacts Android: SQLite databases, shared_prefs, APKs | iOS: SQLite DBs,
plists, IPA files
Tools Android: Cellebrite UFED, MSAB XRY, Magnet AXIOM | iOS:
Cellebrite, GrayKey, Elcomsoft iOS Forensic Toolkit
SIM Card Forensics
• IMSI: International Mobile Subscriber Identity (15 digits) – identifies subscriber
• ICCID: Integrated Circuit Card Identifier – unique SIM card identifier
• IMEI: International Mobile Equipment Identity – identifies device (not SIM)
• Last dialled numbers (LDN), SMS, phonebook stored on SIM
• Tool: SIM card reader + forensic software (Forensic SIM Cloner, MOBILedit)
6.5 Network Forensics
Key Concepts
Packet Capture (PCAP): Capturing raw network packets for analysis; tools: Wireshark, tcpdump
NetFlow/IPFIX: Traffic metadata (IP, port, protocol, duration) without payload content
IDS/IPS Logs: Intrusion Detection/Prevention System alerts – evidence of attacks
Firewall Logs: Records of allowed/blocked connections; source/destination IPs
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
DHCP Logs: MAC-to-IP assignment history; identifies devices on network
DNS Logs: Domain name resolutions; C&C communication identification
OSI Model – Forensic Relevance
Layer Protocol Examples Forensic Evidence
7 - Application HTTP, SMTP, FTP, DNS, SSH Payload content; URLs; emails; commands
6 - Presentation SSL/TLS, encryption Encrypted data; certificate analysis
5 - Session NetBIOS, RPC Session establishment; authentication
4 - Transport TCP, UDP Port numbers; connection states; reassembly
3 - Network IP, ICMP, ARP IP addresses; routing; geolocation
2 - Data Link Ethernet, Wi-Fi (802.11) MAC addresses; physical device identification
1 - Physical Cables, fiber, radio Hardware evidence; signal analysis
Common Network Attack Indicators
• Port scanning: Sequential connection attempts (Nmap signature)
• SQL Injection: Unusual SQL strings in HTTP logs
• Brute Force: Multiple failed login attempts in [Link]
• DDoS: Abnormally high traffic from multiple sources
• Exfiltration: Large outbound transfers to unusual IPs/ports
• Malware C&C: Regular beaconing to external IP at fixed intervals
6.6 Memory (RAM) Forensics
Importance
• RAM contains: Running processes, open network connections, clipboard contents,
encryption keys, passwords in plaintext, malware injected into processes
• Volatile: Lost when power is removed – must be acquired during live system
Acquisition Tools
• WinPmem, FTK Imager (live RAM), Magnet RAM Capture, DumpIt
• LiME (Linux Memory Extractor): Kernel module for Linux RAM capture
• Hibernation file ([Link]): Can be analyzed as RAM image
Analysis Framework: Volatility
• Industry-standard open-source memory analysis framework
• Key plugins: pslist, pstree, cmdline, netscan, malfind, dlllist, hivelist, hashdump
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
• Identifies: Processes, open connections, injected DLLs, hidden processes, registry hives in
memory
6.7 Cloud Forensics
Challenges
• Multi-tenancy: Data co-mingled with other users on shared infrastructure
• Jurisdiction: Data stored across multiple countries
• Data volatility: Cloud resources spun up/down rapidly
• Limited access: Investigator cannot directly access physical hardware
• Encryption: Data encrypted at rest and in transit
Evidence Sources in Cloud
• Cloud provider logs (access logs, audit trails, authentication logs)
• Virtual machine disk images (snapshots)
• Object storage data (AWS S3, Azure Blob, Google Cloud Storage)
• Email/collaboration data (Microsoft 365, Google Workspace)
• Legal process: Preservation letters, subpoenas, court orders, MLATs
6.8 Malware Analysis
Types of Malware
Malware Type Description
Virus Self-replicating code attached to legitimate files
Worm Self-replicating; spreads without host file; exploits network
Trojan Disguised as legitimate software; no self-replication
Ransomware Encrypts victim data; demands ransom for key
Spyware Covert surveillance; keyloggers, credential stealers
Rootkit Hides presence in OS; modifies OS components
Botnet/RAT Remote Access Trojan; command and control
Fileless Malware Operates in memory only; no file on disk; hard to detect
Adware Unwanted advertising; may collect data
Backdoor Covert access mechanism; maintained by threat actor
Malware Analysis Approaches
• Static Analysis: Examine malware without executing (strings, file type, hash, disassembly,
YARA rules)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
• Dynamic Analysis: Execute in controlled sandbox environment (Cuckoo Sandbox); observe
behaviour (network connections, registry changes, file drops)
• Hybrid Analysis: Combination of both approaches
6.9 Steganography and Anti-Forensics
Steganography
Definition: Art of hiding information within other data (e.g., hidden data in image, audio, video files)
• LSB (Least Significant Bit) method: Most common; alters least significant bits of pixel values
• Tools: Steghide, OpenStego, S-Tools, SilentEye
• Detection (Steganalysis): Statistical analysis; file size anomalies; hash comparison; noise
patterns
Anti-Forensics Techniques
• Data wiping/secure deletion: Overwrites sectors (DoD 5220.22-M standard, 7-pass)
• Encryption: TrueCrypt, VeraCrypt, BitLocker; makes data unreadable
• Metadata stripping: Removing EXIF data from images; anonymization
• Timestamp manipulation: Changing MAC times to mislead timeline
• Rootkits: Hiding files, processes, registry entries from OS
• Log tampering: Deleting/modifying event logs
• Virtual machines: Evidence isolated in VM; VM may be encrypted or deleted
• TOR / VPN / Proxy: Anonymization of network identity
6.10 Key Digital Forensic Tools
Tool Category / Use
Autopsy / Sleuth Kit Open-source disk imaging & analysis; file system analysis
EnCase (OpenText) Commercial; court-accepted; E01 format; comprehensive analysis
FTK (AccessData) Forensic Toolkit; indexing; email analysis; known file filtering
Cellebrite UFED Mobile device forensics; physical/logical acquisition
Magnet AXIOM Multi-platform; computer + mobile + cloud forensics
Wireshark Network packet capture and analysis
Volatility Memory forensics framework
Cuckoo Sandbox Automated malware analysis
Oxygen Forensics Mobile and cloud forensics
X-Ways Forensics Lightweight; advanced analysis; specialist tool
Bulk Extractor Extract strings, emails, URLs, credit card numbers from images
Hashdeep / md5deep Batch hashing; hash set comparison
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
RegRipper Windows registry analysis
Log2Timeline (Plaso) Super-timeline creation from multiple artifact types
Metasploit (ethical/research) Penetration testing; understanding attacker methods
6.11 Cyber Laws – IT Act 2000 Key Sections
Section Offence / Provision
Sec. 43 Unauthorised access; damage to computer/data – civil remedy
Sec. 65 Tampering with computer source code
Sec. 66 Computer-related offences (hacking)
Sec. 66A (struck down) Offensive online communication – declared unconstitutional
(Shreya Singhal, 2015)
Sec. 66B Dishonestly receiving stolen computer resource
Sec. 66C Identity theft
Sec. 66D Cheating by personation using computer (phishing)
Sec. 66E Violation of privacy (voyeurism)
Sec. 66F Cyber terrorism
Sec. 67 Publishing obscene material in electronic form
Sec. 67A Publishing sexually explicit material
Sec. 67B Child pornography/CSAM
Sec. 69 Power of interception, monitoring, decryption by Government
Sec. 69A Power to block online content
Sec. 72 Breach of confidentiality and privacy
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 7: General Aptitude and Reasoning for FACT
7.1 General Knowledge – Forensic Focus
Important Organisations
Organisation Headquarters / Role
Interpol Lyon, France – International criminal police cooperation
UNODC Vienna – UN Office on Drugs and Crime
FBI Laboratory Quantico, Virginia, USA – Premier forensic lab
BKA (Bundeskriminalamt) Wiesbaden, Germany – German federal forensic agency
NFSU Gandhinagar, Gujarat – India's national forensic university
CFSL New Delhi (HQ) with labs in Mumbai, Hyderabad, Kolkata
INTERPOL Digital Crime Centre Singapore – Cybercrime investigations
(IDCC)
Important Terms and Abbreviations
Abbreviation Full Form
FACT Forensic Aptitude and Competence Test
FSL Forensic Science Laboratory
CFSL Central Forensic Science Laboratory
NFSU National Forensic Sciences University
CODIS Combined DNA Index System (USA)
NDNAD National DNA Database (UK)
NDTL National Dope Testing Laboratory
DFRWS Digital Forensics Research Workshop
ACPO Association of Chief Police Officers (UK)
SWGDE Scientific Working Group for Digital Evidence
NIST National Institute of Standards and Technology (USA)
OSINT Open Source Intelligence
MLAT Mutual Legal Assistance Treaty
ALS Alternate Light Source
GSR Gunshot Residue
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
BPA Bloodstain Pattern Analysis
DPDP Digital Personal Data Protection
BNS Bharatiya Nyaya Sanhita
BNSS Bharatiya Nagarik Suraksha Sanhita
BSA Bharatiya Sakshya Adhiniyam
7.2 Logical Reasoning – Common Question Types
Pattern Recognition
• Number series: Arithmetic, geometric, Fibonacci, prime-based
• Letter series: Positional values (A=1, B=2 …); alternating patterns
• Matrix/Analogy: Identify the relationship; apply to new pair
Coding-Decoding
• Letter substitution codes (Caesar cipher type)
• Number-letter mapping
• Reverse coding; positional coding
Syllogisms
• All A are B / No A is B / Some A are B – use Venn diagram approach
• Definite vs. possible conclusions
Critical Reasoning
• Assumptions: Unstated premises underlying the argument
• Inferences: Conclusions logically drawn from statements
• Strengthen/Weaken: Identify what supports or undermines the argument
7.3 Quantitative Aptitude – Relevant Topics
Core Topics
• Percentage calculations (concentration, purity, yield)
• Ratio and proportion (dilution problems)
• Averages and weighted averages
• Probability (forensic match probability, DNA statistics)
• Simple and compound interest (financial fraud calculations)
• Data interpretation (tables, graphs from forensic reports)
• Basic statistics: Mean, Median, Mode, Standard Deviation, Variance
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Probability in Forensics
• Random Match Probability (RMP): Probability that a random unrelated person matches the
evidence profile
• Likelihood Ratio (LR): Ratio of probability of evidence under prosecution vs. defense
hypothesis
• Bayesian Inference: Updating prior probability with new evidence
• Prosecutor's Fallacy: Confusing RMP with probability of innocence (error to avoid)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 8: Quick Revision – High-Yield MCQ Facts
8.1 Must-Know Facts
• Locard's Principle: Every contact leaves a trace
• NFSU established: 2020 (NFSU Act); formerly GFSL (2003)
• First DNA fingerprinting: Alec Jeffreys, 1984, Leicester, UK
• First Fingerprint Bureau in India: Calcutta, 1897
• Henry Classification: Loop (65%), Whorl (30%), Arch (5%)
• Latent prints on porous: Ninhydrin (reacts with amino acids)
• Latent prints on non-porous: Aluminium powder / Cyanoacrylate
• Best imaging format for court: E01 (EnCase) or RAW/dd with hash
• TRIM command in SSDs: Complicates data recovery
• Hash standard for evidence: SHA-256
• Locard in digital forensics: Metadata, logs, network artifacts are the 'traces'
• Faraday bag: Blocks radio frequency signals (Wi-Fi, Bluetooth, cellular) from mobile devices
• Write blocker: Prevents any write operations to the original evidence drive
• ACPO Principle 1: Do not alter original data
• IT Act Sec. 66: Hacking | 66C: Identity theft | 66F: Cyber terrorism
• BNS replaces: IPC 1860 | BNSS replaces: CrPC 1973 | BSA replaces: IEA 1872
• ISO 17025: Forensic lab accreditation standard
• FTIR: Best technique for identification of unknown substances (drugs, polymers)
• GC-MS: Gold standard for confirmatory drug analysis
• Volatility: Memory forensics framework (open source)
• Autopsy: Open-source disk forensics (based on Sleuth Kit)
• Cellebrite UFED: Leading mobile forensics acquisition tool
• LSB Steganography: Hides data in least significant bits of image pixels
• Prefetch files: Evidence of program execution in Windows
• [Link]: RAM snapshot in hibernation mode – forensic goldmine
• [Link]: Windows virtual memory – may contain plaintext fragments
8.2 Comparison Tables
Evidence Types
Class Characteristic Individual Characteristic
Bullet calibre (.9mm, .45 ACP) Rifling marks (land and groove impressions)
Shoe sole tread pattern Wear patterns unique to one shoe
Hair colour/race characteristics Nuclear DNA profile
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Blood group (ABO, Rh) Full STR DNA profile
Fibre type (polyester) Specific dye lot match
Manufacturer's font/ink type Specific pen's writing characteristics
Volatile vs. Non-Volatile Evidence
Volatile (Collect First) Non-Volatile (Persists)
RAM contents Hard drive / SSD data
Running processes Installed applications
Open network connections Browser history
Clipboard data File system artifacts
Encryption keys in memory Registry hives
Temporary files in RAM Cloud backups
System time / timezone Physical media
Order of Volatility (HIGHEST to LOWEST – RFC 3227)
13. Registers, Cache memory
14. RAM (main memory)
15. Network traffic / connections
16. Running processes
17. Temporary file system / swap
18. Hard disk / non-volatile storage
19. Remote logging / monitoring data
20. Physical configuration / network topology
21. Archival media (backup tapes, optical)
RFC 3227 'Guidelines for Evidence Collection and Archiving' defines the order of
EXAM TIP volatility. Always collect most volatile evidence FIRST in a live investigation. This is
a frequently tested concept.
8.3 Important Case Laws
Case Significance
State of Maharashtra v. Dr. SC allowed video conferencing for recording evidence
Praful B. Desai (2003)
Anvar P.V. v. P.K. Basheer SC: Sec. 65B certificate mandatory for electronic evidence
(2014)
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Arjun Panditrao v. Kailash Certificate must be filed at the time of producing evidence
(2020)
Shreya Singhal v. Union of India Sec. 66A IT Act struck down; free speech protection
(2015)
Selvi v. State of Karnataka Narcoanalysis, brain mapping, polygraph – involuntary
(2010) administration violates Art. 20(3)
Daubert v. Merrell Dow (1993, Standard for admissibility of expert scientific testimony
USA)
R v. Wakeling (UK) Reliability of digital evidence; authentication requirements
8.4 Key Formulas
Statistics
Mean (Average): Sum of all values ÷ Number of values
Variance (σ²): Sum of (xi - mean)² ÷ N
Standard Deviation (σ): Square root of Variance
Coefficient of Variation: (SD / Mean) × 100 %
F-test statistic: F = S₁² / S₂² (larger variance in numerator)
Chi-Square (χ²): Σ [(Observed - Expected)² / Expected]
Likelihood Ratio: Pr(Evidence | Hp) / Pr(Evidence | Hd)
Concentration Calculations
w/v %: (Mass of solute in g / Volume of solution in mL) × 100
ppm (parts per million): mg/L (for solutions) or mg/kg (for solids)
ppb (parts per billion): μg/L or μg/kg
Dilution Formula: C₁V₁ = C₂V₂
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
UNIT 9: Exam Preparation Strategy
9.1 Topic-wise Priority Matrix
Priority Topics
HIGH (Most MCQs) Digital evidence laws (IT Act, BSA); forensic process; hash
functions; Windows artifacts; mobile forensics acquisition levels;
Locard's principle; ISO 17025
HIGH Network forensics (OSI model, PCAP); malware types; anti-
forensics; memory forensics; BNS/BNSS/BSA provisions
MEDIUM Instrumentation (GC-MS, FTIR, SEM-EDX); statistics (F-test, χ²);
fingerprint development; crime scene photography
MEDIUM Cloud forensics challenges; steganography; digital forensic tools;
order of volatility; chain of custody
LOWER (but don't ignore) Eminent scientists; historical milestones; international
organizations; general ethics cases
9.2 Last-Week Revision Checklist
• Revise all key abbreviations and full forms
• Practise Windows artifact locations from memory
• Revise IT Act sections (43, 65, 66, 66A-F, 67, 67A, 67B, 69, 69A, 72)
• Review BNS/BNSS/BSA key provisions
• Revise Henry fingerprint classification percentages
• Memorize forensic tool names and their primary functions
• Revise order of volatility (RFC 3227)
• Practice logical reasoning number series and coding-decoding
• Solve past FACT papers and similar competitive forensic science MCQs
• Review ACPO principles and DFRWS process model
9.3 Common Mistakes to Avoid
• Confusing BSA (Bharatiya Sakshya Adhiniyam) with IT Act provisions – they overlap but are
distinct
• Mixing up class and individual characteristics – memorize examples
• Forgetting that TRIM in SSDs affects data recovery differently than HDDs
• Confusing RAM volatility order – registers > cache > RAM (not HDD first)
• Over-relying on MD5 – SHA-256 is current standard for evidence integrity
• Assuming digital evidence is automatically admissible – certificate requirement is mandatory
• Forgetting that live systems require RAM acquisition BEFORE shutdown
Confidential – Study Material Only Page
FACT EXAM 2025 – Digital Forensics Study Notes | Section A: Aptitude in Forensic Science
Best of Luck for FACT 2025! | Prepared with comprehensive coverage of all syllabus topics
Confidential – Study Material Only Page