CC&CF Module 3
CC&CF Module 3
analyse electronic devices such as computer, smartphones and tablets, in order to find evidence that can
be used in a criminal or civil case.
hacking, identity theft and child pornography, but it can also be used in other types of cases, such as
financial fraud or civil disputes.
• Identification
• Preservation
• Extraction
• Analysis
• Documentation
• Presentation
Identification: The first step in a digital forensic investigation is to identify the devices and data that
may be relevant to the case. This may include computers, smartphones, tablets, servers, and other types
of electronic devices.
Preservation: Once the relevant devices and data have been identified, it is important to preserve them
in order to maintain the integrity of the evidence. This may involve making copies of the data, or taking
steps to prevent any changes from being made to the original data.
Extraction: The next step is to extract the data from the devices and prepare it for analysis. This may
involve using specialized software or hardware tools to access the data and make copies of it.
Presentation: The final step in the process is to present the results of theanalysis in a clear and concise
manner. This may involve creating reports, charts, or other types of documentation to explain the
findings of the investigation.
Computer forensics: This type of digital forensics involves the investigation of computers and other
types of electronic devices in order to identify and analyse evidence. This may include examining hard
drives, analysing network trafÏc, and reconstructing deleted files.
Mobile device forensics: This type of digital forensics involves the investigation of smartphones,
tablets, and other types of portable devices in order to identify and analyse evidence. This may include
examining call logs, text messages, and other types of data stored on the device.
Network forensics: This type of digital forensics involves the investigation of networks and
communication systems in order to identify and analyse evidence. This may include examining network
traffic, analysing log files, and reconstructing packets of data.
Cloud forensics: This type of digital forensics involves the investigation of cloud-based systems and
services in order to identify and analyse evidence. This may include examining logs and other types of
data stored in the cloud.
There are several different types of evidence that can be found during a digital forensic investigation,
including:
➢ Text files: These can include documents, emails, and other types of written communication
that may be relevant to the case.
➢ Audio files: This can include recordings of conversations, lectures, or other types of audio
that may be relevant to the case.
➢ Video files: This can include footage from security cameras, video recordings, or other types
of videos that may be relevant to the case.
➢ Internet history: This can include information about websites that have been visited, as well
as search terms that have been used, and may be relevant to the case.
➢ System files: These can include operating system files, application files, and other types of
data that may be relevant to the case.
There are several different types of electronic devices that may be examined during a digital
forensic investigation, including:
1. Computers: This can include desktop computers, laptops, and servers, and may be used to examine
hard drives, network traffic, and other types of data.
2. Mobile devices: This can include smartphones, tablets, and other types of portable devices, and may
be used to examine call logs, text messages, and other types of data stored on the device.
3. Network devices: This can include routers, switches, and other types of network equipment, and may
be used to examine network traffic and logs.
4. Cloud-based systems: This can include cloud-based storage and other types of cloud-based services,
and may be used to examine data stored in the cloud.
➢ The large amount of storage space into Terabytes that makes this investigation job difficult.
In recent time, commercial organizations have used digital forensics in following a type of cases:
• Industrial espionage
• Employment disputes
• Fraud investigations
• Inappropriate use of the Internet and email in the workplace
• Bankruptcy investigations
Forensic software and hardware are tools that are used to extract and analyse electronic data in a digital
forensic investigation. These tools can include software programs such as EnCase, FTK, and X-Ways, as
well as hardware devices such as write blockers and forensic workstations.
Forensic software and hardware are tools that are used to extract and analyse electronic data in a digital
forensic investigation. These tools can include:
1. Forensic software: This type of software is designed specifically for use in digital forensic
investigations and can include programs such as EnCase, FTK, and X-Ways. These programs can be
used to extract data from electronic devices, analyse the data, and create reports or other
documentation of the findings.
2. Write blockers: A write blocker is a device that is used to prevent any changes from being made to
the data on an electronic device. This is important in order to maintain the integrity of the evidence
and prevent any contamination of the data.
3. Forensic workstations: A forensic workstation is a specialized computer that is used for digital
forensic investigations. These workstations often have multiple hard drives and other specialized
hardware and software tools that are used to extract and analyse data from electronic devices.
In addition to the forensic software and hardware tools that are commonly used in digital forensic
investigations, there are also a number of other tools and techniques that may be employed, depending on
the specific needs of the case. Some of these tools and techniques include:
1. Data carving: Data carving is a technique that is used to extract data from a storage device, even if it has
been deleted or partially
overwritten. This can be useful in cases where the data may have been intentionally or accidentally deleted.
2. Keyword searches: Keyword searches are used to search for specific words or phrases within a large
amount of data. This can be useful in cases where there may be a specific piece of information that is
relevant to the investigation.
3. Hash analysis: Hash analysis is a technique that is used to verify the integrity of the data on an electronic
device. It involves calculating a unique numerical value, or "hash," for each piece of data and comparing
it to a known value in order to ensure that the data has not been altered.
4. Network forensics: Network forensics involves the examination of network traffic and other data in
order to identify patterns of activity or identify specific individuals or devices.
5. Cloud forensics: Cloud forensics involves the examination of data stored in cloud-based systems and
services in order to identify and analyse evidence.
Overall, forensic software and hardware are an important part of the digital forensic process and are used to
extract and analyse electronic data in a reliable and accurate manner.
Computer forensics is often used by law enforcement agencies to investigate and prosecute cybercrimes,
such as hacking, identity theft, and child pornography. In these cases, computer forensics plays a critical role
in identifying and analysing the electronic devices and data that may be relevant to the case.
The process of computer forensics in a law enforcement context typically involves the following steps:
1. Seizure: The first step in a computer forensic investigation is to seize the electronic devices and data that
may be relevant to the case. This may
involve obtaining a search warrant and collecting the devices from the location where the crime was
committed.
2. Preservation: Once the devices and data have been seized, it is important to preserve them in order to
maintain the integrity of the evidence. This may involve making copies of the data , or taking steps to
prevent any changes from being made to the original data.
3. Extraction: The next step is to extract the data from the devices and prepare it for analysis. This may
involve using specialized software or hardware tools to access the data and make copies of it.
4. Analysis: Once the data has been extracted, it must be analyzed in order to identify any relevant
information or evidence. This may involve using specialized software to search for keywords, examine
patterns of activity, or reconstruct deleted files.
5. Presentation: The final step in the process is to present the results of the analysis in a clear and concise
manner. This may involve creating reports, charts, or other types of documentation to explain the
findings of the investigation.
Computer forensics is an important tool for law enforcement agencies in investigating and prosecuting
cybercrimes. It involves the use of specialized techniques and tools to extract, analyse, and present digital
evidence that may be relevant to a criminal case.
➢ Investigate cybercrimes: Computer forensics can be used to identify and track the activities of
individuals or groups who are suspected of committing cybercrimes, such as hacking, identity
theft, or child pornography.
➢ Collect and preserve digital evidence: Computer forensics can be used to collect and preserve
digital evidence that may be relevant to a criminal case, such as emails, text messages, and other
types of electronic communication.
➢ Analyse electronic devices and data: Computer forensics can be used to analyse the data on
electronic devices, such as computers, smartphones,
to present the results of their analysis in court in order to help prosecute cybercrimes and bring perpetrators
to justice.
➢ Identify suspects: Computer forensics can be used to identify the individuals or groups who are
suspected of committing cybercrimes, such as hacking or identity theft. This may involve
analysing electronic devices, such as computers and smartphones, in order to identify patterns of
activity or extract relevant information.
➢ Track cyber-criminal activity: Computer forensics can be used to track the activities of
individuals or groups who are suspected of committing cybercrimes. This may involve
examining log files, analysing network traffic, or reconstructing packets of data in order to
understand how the crimes were committed and identify the perpetrators.
➢ Collect and preserve digital evidence: Computer forensics can be used to collect and preserve
digital evidence that may be relevant to a criminal case, such as emails, text messages, and other
types of electronic communication. This may involve making copies of the data or taking steps to
prevent any changes from being made to the original data.
➢ Present evidence in court: Computer forensics experts may be called upon to present the results
of their analysis in court in order to help prosecute cybercrimes and bring perpetrators to justice.
This may involve creating reports, charts, or other types of documentation to explain the findings
of the investigation.
There are a number of challenges that law enforcement agencies may face when using computer
forensics to investigate and prosecute cybercrimes. Some of these challenges include:
1. Keeping up with technology: The field of computer forensics is constantly evolving as new
technologies are developed and new cyber-crimes are committed. This can make it difficult for
law enforcement agencies to keep up with the latest techniques and tools and to effectively
investigate and prosecute cybercrimes.
2. Maintaining the integrity of the evidence: It is important to maintain the integrity of the evidence
in a computer forensic investigation in order to ensure that it is admissible in court. This can be
challenging, as it is easy to alter or delete digital evidence, and there may be multiple copies of
the data that need to be tracked.
3. Dealing with large amounts of data: Computer forensic investigations often involve analysing
large amounts of data, which can be time- consuming and resource-intensive. This can make it
difficult for law enforcement agencies to efficiently investigate and prosecute cybercrimes.
4. Limited resources: Law enforcement agencies often have limited resources, including staff and
funding, which can make it difficult to effectively investigate and prosecute cybercrimes.
Overall, law enforcement agencies face a number of challenges when using computer forensics to
investigate and prosecute cybercrimes. These challenges can include keeping up with technology,
maintaining the integrity of the evidence, dealing with large amounts of data, and limited resources.
Overall, computer forensics is an important tool for law enforcement agencies in investigating and
prosecuting cyber crimes. It involves the use of specialized techniques and tools to extract, analyze,
and present digital evidence in a reliable and accurate manner.
Indian Cyber Forensic
Indian cyber forensics is the branch of digital forensics that specifically focuses on the investigation of cyber
crimes in India. It involves the use of specialized techniques and tools to extract, analyze, and present digital
evidence that may be relevant to a criminal case in India.
In India, cyber forensics is used by law enforcement agencies and other organizations to investigate and
prosecute cyber crimes, such as hacking, identity theft, and child pornography. It is also used by businesses
and individuals to resolve disputes and protect against cyber threats.
The process of Indian cyber forensics typically involves the following steps:
1. Identification: The first step in a cyber forensic investigation is to identify the devices and data that may
be relevant to the case. This may include computers, servers, and other types of electronic devices.
2. Preservation: Once the relevant devices and data have been identified, it is important to preserve them in
order to maintain the integrity of the evidence. This may involve making copies of the data, or taking
steps to prevent any changes from being made to the original data.
3. Extraction: The next step is to extract the data from the devices and prepare it for analysis. This may
involve using specialized software or hardware tools to access the data and make copies of it.
4. Analysis: Once the data has been extracted, it must be analyzed in order to identify any relevant
information or evidence. This may involve using specialized software to search for keywords, examine
patterns of activity, or reconstruct deleted files.
5. Presentation: The final step in the process is to present the results of the analysis in a clear and concise
manner. This may involve creating reports, charts, or other types of documentation to explain the
findings of the investigation.
Indian cyber forensics is an important tool for law enforcement agencies and other organizations in
India in investigating and prosecuting cyber crimes. It involves the use of specialized techniques and
tools to extract, analyze, and present digital evidence that may be relevant to a criminal case in India.
• Investigate cyber crimes: Indian cyber forensics can be used to identify and track the activities
of individuals or groups who are suspected of committing cyber crimes, such as hacking,
identity theft, or child pornography.
• Collect and preserve digital evidence: Indian cyber forensics can be used to collect and preserve
digital evidence that may be relevant to a criminal case, such as emails, text messages, and other
types of electronic communication.
• Analyze electronic devices and data: Indian cyber forensics can be used to analyze the data on
electronic devices, such as computers, smartphones, and tablets, in order to identify patterns of
activity or extract relevant information.
• Present evidence in court: Indian cyber forensics experts may be called upon to present the
results of their analysis in court in order to help prosecute cyber crimes and bring perpetrators to
justice.
There are a number of challenges that law enforcement agencies and other organizations in India may face
when using cyber forensics to investigate and prosecute cyber crimes. Some of these challenges include:
1. Limited resources: Like many other countries, India faces challenges in terms of limited resources,
including staff and funding, which can make it difficult to effectively investigate and prosecute
cybercrimes.
2. Lack of trained personnel: There is often a shortage of trained personnel in India who are skilled in cyber
forensics and other areas of digital forensics. This can make it difficult for law enforcement agencies and
other
organizations to effectively investigate and prosecute cybercrimes.
3. Technological challenges: Cyber forensic investigations can be complex and time-consuming, and may
involve dealing with a large amount of data and a wide range of technologies. This can present
challenges for law enforcement agencies and other organizations in India.
4. Legal challenges: There may be legal challenges associated with the use of cyber forensics in India,
including issues related to admissibility of digital evidence in court and privacy concerns.
There are a number of best practices that law enforcement agencies and
other organizations in India can follow in order to effectively use cyber forensics to investigate and
prosecute cyber crimes. Some of these best practices include:
➢ Training: It is important for law enforcement agencies and other organizations in India to ensure
that their staff are trained in the latest cyber forensic techniques and tools. This can help them to
effectively extract, analyze, and present digital evidence in a reliable and accurate manner.
➢ Maintaining the chain of custody: It is important to maintain the chain of custody of digital
evidence in order to ensure that it is admissible in court. This involves documenting the handling
of the evidence at every stage of the investigation and keeping track of who has had access to it.
➢ Using forensic-grade tools: It is important to use forensic-grade tools when extracting and
analyzing digital evidence in order to ensure the integrity of the evidence. These tools are
designed specifically for use in forensic investigations and can help to prevent any contamination
of the data.
➢ Documenting the process: It is important to carefully document the process of the investigation
in order to be able to present the results
in court. This may involve creating reports, charts, or other types of documentation to explain the findings of
the investigation.
Forensic technology and practices refer to the tools, techniques, and processes that are used in forensic
science to investigate and analyse evidence in criminal cases. These tools and techniques can be used to
identify, preserve, extract, and analyze physical, chemical, or digital evidence in order to help solve crimes
and bring perpetrators to justice.
1. Forensic ballistics: This involves the use of tools and techniques to analyse the characteristics of bullets
and other types of ballistic evidence in order to determine the type of firearm that was used in a crime.
2. Forensic photography: This involves the use of specialized cameras and techniques to document crime
scenes and other types of evidence in a way that is suitable for presentation in court.
3. Face, iris, and fingerprint recognition: These technologies involve the use of algorithms and specialized
software to identify and analyse facial features, iris patterns, and fingerprints in order to identify
individuals or determine their involvement in a crime.
4. Audio and video analysis: This involves the use of specialized software and techniques to analyse audio
and video evidence, such as recordings of conversations or surveillance footage, in order to extract
relevant information or identify individuals.
5. Forensics of handheld devices: This involves the use of specialized tools and techniques to extract and
analyse data from handheld devices, such as smartphones and tablets, in order to identify relevant
evidence or track patterns of activity.
Forensic ballistics
Forensic ballistics involves the use of tools and techniques to analyse the characteristics of bullets and other
types of ballistic evidence in order to determine the type of firearm that was used in a crime. This may
involve examining the rifling patterns on bullets, analysing the markings on cartridge cases, or comparing
the characteristics of bullets and cartridge cases to those of known firearms.
There are a number of tools and techniques that are used in forensic ballistics,
including:
1. Microscopes: Microscopes are used to examine the rifling patterns on bullets and cartridge cases in order to
determine the type of firearm that was used.
2. Comparison microscopes: Forensic ballistics experts may use comparison microscopes or other specialized
tools to compare the characteristics of bullets and cartridge cases to those of known firearms in order to
determine the type of firearm that was used.
3. Database searches: Forensic ballistics experts may use databases, such as the National Integrated Ballistics
Information Network (NIBIN), to search for matches between bullets and cartridge cases found at crime
scenes and those recovered from known firearms.
There are a number of steps that are typically followed in a forensic ballistics investigation:
• Collection of evidence: The first step in a forensic ballistics investigation is to collect the ballistic
evidence from the crime scene. This may include bullets, cartridge cases, and any other related
evidence, such as bullet fragments or damaged objects.
• Examination and analysis: The next step is to examine and analyse the ballistic evidence in order
to determine the type of firearm that was used. This may involve using microscopes or other
specialized tools to examine the rifling patterns on bullets and cartridge cases, or comparing the
characteristics of the evidence to those of known firearms. Comparison to database: Forensic
ballistics experts may use databases, such as the National Integrated Ballistics Information
Network (NIBIN), to search for matches between bullets and cartridge cases found at crime
scenes and those recovered from known firearms.
• Presentation of findings: The final step in the process is to present the findings of the
investigation in a clear and concise manner. This may involve creating reports, charts, or other
types of documentation to explain the results of the analysis.
Forensic photography
Forensic photography is a specialized field of photography that involves the use of specialized cameras and
techniques to document crime scenes and other types of evidence in a way that is suitable for presentation in
court. It is an important tool in the field of forensic science, as it provides a visual record of the crime scene
and any relevant evidence that may be used to help solve a crime or bring perpetrators to justice.
There are a number of steps that are typically followed in forensic photography:
3. Analysis: Once the images have been captured, they may be analysed in order to identify any relevant
information or evidence. This may involve using specialized software to enhance the images or identify
specific features or patterns.
4. Presentation: The final step in the process is to present the results of the analysis in a clear and concise
manner. This may involve creating reports, charts, or other types of documentation to explain the
findings of the investigation.
There are a number of considerations that forensic photographers must take into account when documenting
crime scenes or other evidence, including:
1. Lighting: Proper lighting is crucial in forensic photography in order to capture clear and detailed
images of evidence. This may involve using specialized lighting equipment, such as floodlights
or lasers, or taking photographs at different times of day in order to capture the best lighting
conditions.
2. Angle and perspective: It is important for forensic photographers to capture images from a
variety of angles and perspectives in order to document the crime scene or other evidence as
accurately as possible. This may involve using tripods, ladders, or other specialized equipment to
capture images from different heights or angles.
3. Camera and lens selection: The choice of camera and lens can have a significant impact on the
quality of the images captured in forensic photography. Forensic photographers often use high-
quality digital cameras and lenses that are specifically designed for capturing detailed images in a
variety of lighting conditions.
4. Image enhancement: Forensic photographers may use specialized software to enhance the images
they have captured in order to make them clearer or to highlight specific features or patterns.
Face, iris, and fingerprint recognition:
Face, iris, and fingerprint recognition are technologies that involve the use of algorithms and specialized
software to identify and analyse facial features, iris patterns, and fingerprints in order to identify individuals
or determine their involvement in a crime. These technologies are often used to help identify suspects or to
confirm the identity of individuals in cases where traditional methods, such as eyewitness testimony, may be
unreliable.
• Face recognition: Face recognition is a technology that involves the use of algorithms and
specialized software to analyse the unique characteristics of an individual's face in order to
identify them. This may involve analyzing the shape, size, and placement of facial features, such
as the eyes, nose, and mouth. Face recognition technology is often used to identify individuals in
security or surveillance applications, such as border control or access control.
• Iris recognition: Iris recognition is a technology that involves the use of algorithms and
specialized software to analyze the unique patterns in an individual's iris, the coloured part of the
eye, in order to identify them. This technology is often used in security applications, such as
border control or access control, as the iris is relatively stable and does not change over time.
There are a number of factors that can impact the accuracy and reliability of face, iris, and
fingerprint recognition technologies, including:
• Quality of the image: The quality of the image is an important factor in the accuracy and
reliability of these technologies. Poor quality images may contain noise, blur, or other
distortions that can make it difficult for the algorithms to accurately analyze the facial features,
iris patterns, or fingerprints.
• Environmental conditions: Environmental conditions, such as lighting and weather, can also
impact the accuracy and reliability of these technologies. For example, low light conditions or
rain may make it difficult to capture clear images of facial features, iris patterns, or fingerprints.
• Age of the image: The age of the image can also impact the accuracy and reliability of these
technologies. As an individual's facial features, iris patterns, or fingerprints may change over
time, older images may be less reliable for identification purposes.
• Diversity of the population: The diversity of the population can also impact the accuracy and
reliability of these technologies. Systems that have been trained on a diverse population may be
more accurate and reliable at identifying individuals from a wide range of backgrounds and
ethnicities.
Audio and video analysis is a field of forensic science that involves the use of specialized software and
techniques to analyze audio and video evidence, such as recordings of conversations or surveillance footage,
in order to extract relevant information or identify individuals. This may involve enhancing the audio or
video to make it clearer, or using software to analyze the content of the recording in order to identify voices
or other relevant information.
Authentication of recordings- In many criminal cases, the authenticity of the recording and the content of
the recording may be called in to question. Forensic audio and video experts can examine a variety of
characteristics of the audio or video recording to determine whether the
evidence has been altered. This includes confirming the integrity (verification) of the recording, as well as
authenticating that the content of the image or audio is what it purports to be.
If the ambient sound present on an audio recording changes abruptly, this could indicate that the
environment where the recording took place suddenly changed.
The volume and tone of a voice on the recording can provide clues as to distance and spatial relationships
within a scene.
Lighting conditions can be examined to estimate the time of day or environmental conditions at the time of
the recording.
Technical details may also confirm information about a recording. For instance, an unnatural waveform
present in the audio or video signal may indicate that an edit has been made.
A physical identifier may be present in the signal on magnetic tape that can identify it as a copy or indicate
that it was recorded on a particular device. Sometimes a perpetrator will try to destroy Audio or video
evidence;
however, using thesemethods, the recording can be analyzed to determine what occurred.
There are a number of tools and techniques that are used in audio and video analysis, including:
1. Audio enhancement: Audio enhancement involves the use of specialized software to improve
the clarity and quality of audio recordings. This may involve removing background noise,
increasing the volume, or enhancing the clarity of the audio in order to make it easier to
understand.
2. Audio enhancement: Audio enhancement involves the use of specialized software to improve
the clarity and quality of audio recordings. This may involve removing background noise,
increasing the volume, or enhancing the clarity of the audio in order to make it easier to understand.
Audio Enhancement Techniques -- For audio recordings. a variety of filters can be applied to enhance the
material, bringing out specific aspects or events contained in the recording.
Frequency Equalization - Highly precise equalizers can be used to boost or cut specific bands of frequencies.
To help make speech more intelligible, the frequency band containing most speech content, 200Hz-5000Hz,
can be amplified or isolated If amplification is applied to a frequency range, other information residing in
this frequency range will be boosted as well. If noise resides in this same range, this noise will also be
increased, limiting the ability to clarify voices.
Loud background noises may be analyzed by a spectrum analyser and the corresponding frequencies
reduced so that these noises are less noticeable.
Compression -Faint sounds in the recording can be boosted by compressing or levelling the signal so that the
dynamic range of the material is reduced, making soft sounds more apparent.
3. Voice identification: Voice identification involves the use of specialized software to analyze
the unique characteristics of an individual's voice in order to identify them. This may involve
analyzing the pitch, tone, and other characteristics of the voice in order to create a unique
voiceprint that can be used for identification purposes.
4. Video enhancement: Video enhancement involves the use of specialized software to improve
the clarity and quality of video footage. This may involve increasing the resolution, removing
noise or blur, or enhancing the contrast in order to make the footage easier to see and analyze.
Sharpening: Makes edges of images in the recording become clearer and more distinct.
Video stabilization: Reduces the amount of movement in the video, producing the smoothest possible
playback.
Masking: Covers the face or areas of the video that may protect a witness, victim or law enforcement ofÏcer.
Interlacing: In an analog system, interlaced scanning is used to record images (a technique of combining
two television fields in order to produce a full frame of video). A process called de- interlacing may be used
to retrieve the information in both fields of video.
Demultiplexing-Allows for isolation of each camera. In CCTV systems, a device called a multiplexer is used
to combine multiple video signals into a single signal or separate a combined signal. These devices are
frequently used in security and law enforcement applications for recording and/or displaying multiple
camera images simultaneously or in succession.
5. Facial recognition: Facial recognition technology may be used in conjunction with video
analysis in order to identify individuals in the footage. This involves the use of algorithms and
specialized software to analyze the unique characteristics of an individual's face in order to
identify them.
There are a number of steps that are typically followed in an audio and video analysis investigation:
1. Collection of evidence: The first step in an audio and video analysis investigation is to collect the
audio or video evidence that is relevant to the case. This may involve collecting audio or video
recordings from a variety of sources, such as surveillance cameras, smartphones, or other
devices.
2. Analysis: The next step is to analyze the audio or video evidence in order to extract relevant
information or identify individuals. This may involve using specialized software to enhance the
audio or video, or using algorithms and software to analyze the content of the recording in order
to identify voices or other relevant information.
3. Comparison to databases: In some cases, audio and video analysis experts may use databases,
such as the National Crime Information Center (NCIC), to search for matches between
individuals identified in the audio or video evidence and known individuals in order to confirm
their identity.
4. Presentation of findings: The final step in the process is to present the findings of the analysis in
a clear and concise manner. This may involve creating reports, charts, or other types of
documentation to explain the results of the analysis.
Forensics of Handheld devices
Forensics of handheld devices involves the use of specialized tools and techniques
to extract, preserve, and analyze digital evidence from handheld devices, such as smartphones, tablets, and
wearable devices. This type of forensic investigation may be used to help solve crimes or to gather evidence
in civil or criminal cases. There are a number of steps that are typically followed in a forensic investigation
of handheld devices:
1. Collection of evidence: The first step in a forensic investigation of handheld devices is to collect
the device and any relevant evidence, such as SIM cards or memory cards. It is important to
handle the device carefully to avoid damaging it or altering any evidence that may be present.
2. Preservation of evidence: The next step is to preserve the evidence on the device in order to
ensure that it is not altered or damaged during the investigation. This may involve making a
copy of the device's memory or creating a forensic image of the device.
3. Analysis: The next step is to analyze the device in order to extract relevant evidence. This may
involve using specialized software to search for specific types of data, such as text messages,
emails, or photos, or analyzing the device's logs or other system data in order to identify any
relevant activity.
findings of the investigation in a clear and concise manner. This may involve creating reports, charts, or
other types of documentation to explain the results of the analysis.
Forensic investigations of handheld devices involve the use of specialized tools and techniques to extract,
preserve, and analyze digital evidence from handheld devices, such as smartphones, tablets, and wearable
devices. This type of forensic investigation may be used to help solve crimes or to gather evidence in
civil or criminal cases
There are a number of considerations that forensic experts must take into account when conducting a
forensic investigation of handheld devices, including:
1. Device type: Different types of handheld devices may have different operating systems and
hardware configurations, which can impact the tools and techniques that are used in the forensic
investigation. It is important for forensic experts to be familiar with the specific characteristics of
the device they are analyzing in order to ensure that they are using the appropriate tools and
techniques.
2. Data types: Handheld devices may contain a wide range of data types, including text
messages, emails, photos, videos, and social media posts. It is important for forensic experts to be
aware of the types of data that may be present on the device and to use the appropriate tools and
techniques to extract and analyze this data.
3. Data storage: Handheld devices may store data in a variety of locations, including internal
memory, removable storage devices, and cloud storage. It is important
for forensic experts to be familiar with the different storage locations and to use the appropriate tools and
techniques to extract and analyze data from each location.
4. Encryption: Some handheld devices may be encrypted, which can make it difficult to extract
and analyze data from the device. Forensic experts must be familiar with the various encryption
technologies that may be used on handheld devices and use the appropriate tools and techniques to
bypass or decrypt the data.
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Introduction
Windows System Forensics is a branch of digital forensics that focuses on collecting, analyzing, and preserving
evidence from computers running the Microsoft Windows operating system. It helps investigators identify
cybercrimes, unauthorized activities, malware infections, data theft, and user actions performed on a Windows
system.
Windows forensics involves examining files, logs, registry entries, user accounts, system configurations, browser
history, deleted files, and other artifacts to reconstruct events and gather digital evidence.
1. Windows Registry
The Windows Registry is a database that stores system and user configuration settings.
Evidence obtained:
3
0
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Installed software
2. Event Logs
Security Logs
Application Logs
System Logs
Evidence obtained:
System errors
Evidence obtained:
3
1
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Deleted files
Hidden files
Investigators examine:
User profiles
Password settings
Group memberships
5. Browser Artifacts
Browsing history
Download history
Cookies
Cached files
Saved passwords
6. Recycle Bin
Even deleted files may remain in the Recycle Bin and can provide valuable evidence.
3
2
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
7. Prefetch Files
Evidence obtained:
Execution timestamps
Evidence obtained:
Device name
Serial number
Connection timestamps
Step 1: Identification
Step 2: Preservation
Step 3: Acquisition
Step 4: Analysis
3
3
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Step 5: Documentation
Step 6: Reporting
Autopsy
FTK Imager
EnCase
Volatility
Registry Explorer
Wireshark
Challenges
3
4
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Introduction
Linux System Forensics is the process of identifying, collecting, preserving, analyzing, and presenting digital
evidence from Linux-based systems. It is widely used in cybercrime investigations, incident response, malware
analysis, and security audits. Linux forensics helps investigators determine what happened on a system, who
performed the activity, and when it occurred.
Linux systems are commonly used in servers, cloud environments, embedded systems, and network devices,
making forensic investigation an important aspect of cybersecurity.
3
5
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
1. Log Files
/var/log/messages
/var/log/syslog
/var/log/[Link]
/var/log/secure
Evidence Obtained:
Security incidents
Important files:
/etc/passwd
/etc/shadow
/etc/group
Evidence Obtained:
Password-related data
3
6
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Group memberships
Ext2
Ext3
Ext4
XFS
Evidence Obtained:
Deleted files
4. Bash History
~/.bash_history
Evidence Obtained:
System modifications
3
7
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
5. Running Processes
Commands used:
ps
top
pstree
Evidence Obtained:
Active processes
Suspicious programs
Malware activities
6. Network Information
Commands used:
netstat
ss
ifconfig
ip addr
Evidence Obtained:
Open ports
3
8
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
7. Scheduled Tasks
Cron Jobs
At Jobs
Files:
/etc/crontab
Evidence Obtained:
Investigators analyze storage devices to recover deleted files and identify attempts to hide evidence.
Step 1: Identification
Step 2: Preservation
Step 3: Collection
3
9
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Step 4: Examination
Step 5: Analysis
Autopsy
Sleuth Kit
Volatility
Wireshark
FTK Imager
dd
4
0
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Challenges
Anti-forensic techniques.
Network Forensics
Introduction
Network Forensics is a branch of digital forensics that involves the monitoring, capture, recording, and analysis of
network traffic to investigate cybercrimes, security incidents, and unauthorized activities. It helps investigators
identify attackers, trace malicious activities, detect security breaches, and collect evidence from network
communications.
Network forensics plays a crucial role in investigating cyber attacks such as hacking, malware infections, denial-of-
service attacks, data theft, and unauthorized access to computer networks.
4
1
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
1. Packet Data
Evidence Obtained:
Protocol information
2. Firewall Logs
Evidence Obtained:
4
2
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Blocked connections
Allowed connections
Suspicious activities
Evidence Obtained:
Connected devices
Traffic patterns
Evidence Obtained:
Attack attempts
Malware activity
Security violations
5. Server Logs
Evidence Obtained:
4
3
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Login attempts
File transfers
Step 1: Identification
Step 2: Collection
Step 3: Preservation
Step 4: Examination
Step 5: Analysis
Step 6: Reporting
Wireshark
tcpdump
4
4
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
NetworkMiner
Snort
Nmap
Autopsy
Encrypted communications.
Privacy concerns.
Cybercrime investigations
4
5
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
Intrusion detection
Malware analysis
Security auditing
QUESTION BANK
2 Marks Questions
4
6
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
5 Marks Questions
10 Marks Questions
4
7
Prepared by,
PROF. SEEMA C K
CYBER CRIME & CYBER FORENSICS NOTES
46. Explain Windows System Forensics and discuss the major sources of evidence available in Windows
operating systems.
47. Describe the Windows Forensic Investigation Process with a neat diagram.
48. Explain Linux System Forensics and discuss various sources of digital evidence in Linux systems.
49. Describe the Linux Forensic Investigation Process and tools used.
50. Explain Network Forensics, its objectives, sources of evidence, and investigation process.
51. Discuss the applications, advantages, and challenges of Network Forensics.
52. Explain Forensic Photography and the steps involved in documenting a crime scene.
53. Discuss Face Recognition, Iris Recognition, and Fingerprint Recognition technologies in forensic
investigations.
54. Explain Audio and Video Analysis in Digital Forensics with suitable enhancement techniques.
55. Describe the process of forensic investigation of handheld devices and discuss the challenges involved.
56. Explain Forensic Ballistics and discuss the tools and techniques used in ballistic investigations.
57. Discuss the steps involved in a Forensic Ballistics Investigation.
58. Explain Audio Authentication and Video Authentication in forensic investigations.
59. Discuss various Audio Enhancement Techniques and their applications.
60. Explain various Video Enhancement Techniques such as Sharpening, Stabilization, Masking, De-
interlacing, and Demultiplexing.
4
8