0% found this document useful (0 votes)
1 views49 pages

GuideCompFor 7e Mod05

The document outlines the objectives and procedures for processing crime and incident scenes in computer forensics, including identifying and collecting digital evidence. It emphasizes the importance of understanding rules of evidence, securing crime scenes, and the steps necessary for preparing and conducting evidence searches. Additionally, it discusses the legal considerations and best practices for seizing and handling digital evidence in both law enforcement and private-sector investigations.

Uploaded by

Saad AlRaheem
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
1 views49 pages

GuideCompFor 7e Mod05

The document outlines the objectives and procedures for processing crime and incident scenes in computer forensics, including identifying and collecting digital evidence. It emphasizes the importance of understanding rules of evidence, securing crime scenes, and the steps necessary for preparing and conducting evidence searches. Additionally, it discusses the legal considerations and best practices for seizing and handling digital evidence in both law enforcement and private-sector investigations.

Uploaded by

Saad AlRaheem
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Guide to Computer

Forensics and
Investigations, 7e
Module 5: Processing Crime and
Incident Scenes

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 1
Module Objectives (1 of 2)

By the end of this module, you should be able to:


• Explain how to identify digital evidence
• Describe how to collect evidence at private-sector incident scenes
• Explain guidelines for processing law enforcement crime scenes
• List the steps in preparing for an evidence search
• Describe how to secure a computer incident or crime scene

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 2
Module Objectives (2 of 2)

By the end of this module, you should be able to (continued):


• Explain guidelines for seizing digital evidence at the scene
• List procedures for transporting and storing digital evidence
• Explain how to obtain a digital hash
• Understand employee compliance investigations

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 3
Identifying Digital Evidence (1 of 2)

• Digital evidence can be any information stored or transmitted in digital form


• U.S. courts accept digital evidence as physical evidence
− Digital data is treated as a tangible object
• Groups such as the Scientific Working Group on Digital Evidence (SWGDE)
set standards for recovering, preserving, and examining digital evidence

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 4
Identifying Digital Evidence (2 of 2)

• The following are general tasks investigators perform when working with digital
evidence:
− Identify digital information or artifacts that can be used as evidence
− Collect, preserve, and document evidence
− Analyze, identify, and organize evidence
− Rebuild evidence or repeat a situation to verify that the results can be
reproduced reliably

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 5
Understanding Rules of Evidence (1 of 4)

• Consistent practices help verify your work and enhance your credibility
• Evidence admitted in a criminal case can be used in a civil suit, and vice versa
• Keep current on the latest rulings and directives on collecting, processing,
storing, and admitting digital evidence
• Data you discover from a forensic examination falls under your state’s rules of
evidence or the Federal Rules of Evidence (FRE)

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 6
Understanding Rules of Evidence (2 of 4)

• Business-record exception allows “records of regularly conducted activity,” such


as business memos, reports, records, or data compilations
• Business records are authenticated by verifying that they were created “at or
near the time by, or from information transmitted by, a person with knowledge”
• Business records are admissible “if the record was kept in the course of a
regularly conducted business activity, and it was the regular practice of that
business activity to make the record”

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 7
Understanding Rules of Evidence (3 of 4)

• Computer-generated records are data the system maintains such as system


log files and proxy server logs
• Computer-stored records are data that a person creates and saves on a
digital device
• Computer-generated records are considered authentic if the program that
created the output is functioning correctly
• One test to prove that computer-stored records are authentic is to demonstrate
that a specific person created the records
− The author of a Microsoft Word document can be identified by using file metadata

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 8
Understanding Rules of Evidence (4 of 4)

• The process of establishing digital evidence’s trustworthiness originated with


written documents and the “best evidence rule”
− This rule states that to prove the content of a written document, recording, or
photograph, ordinarily the original file is required
• The FRE allows a duplicate instead of originals when it is produced by the same
impression as the original
• As long as bit-stream copies of data are created and maintained properly, the
copies can be admitted in court
− Although they aren’t considered best evidence

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 9
Collecting Evidence at Private-Sector
Incident Scenes (1 of 3)
• Private-sector organizations include small to medium businesses, large
corporations, and non-government organizations (NGOs)
• Non-government organizations (NGO) must comply with state public disclosure
and federal Freedom of Information Act (FOIA) laws
• Internet service providers (ISPs) can investigate computer abuse committed by
their employees, but not by customers
− Except for activities that are deemed to create an emergency situation

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 10
Collecting Evidence at Private-Sector
Incident Scenes (2 of 3)
• Investigating and controlling computer incident scenes in the corporate
environment is much easier than in crime scenes
• A corporate policy statement about misuse of digital assets allows corporate
investigators to conduct covert surveillance with little or no cause
• Companies should display a warning banner and publish a policy stating that
they reserve the right to inspect computing assets at will
• Every organization must have a well-defined process describing when an
investigation can be initiated

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 11
Collecting Evidence at Private-Sector
Incident Scenes (3 of 3)
• If you discover evidence of a crime during a company policy investigation, take
the following steps:
− Determine whether the incident meets the elements of criminal law
− Inform management of the incident
− Stop your investigation to make sure you don’t violate Fourth Amendment
restrictions on obtaining evidence
− Work with the corporate attorney on how to respond to a police request for
more information

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 12
Processing Law Enforcement Crime Scenes

• You must be familiar with criminal rules of search and seizure


• You should also understand how a search warrant works and what to do when
you process one
• Probable cause is the standard specifying whether a police officer has the right
to make an arrest, conduct a personal or property search, or obtain a warrant for
arrest
• The Fourth Amendment states that only warrants “particularly describing the
place to be searched, and the persons or things to be seized” can be issued

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 13
Understanding Concepts and Terms Used in
Warrants (1 of 2)
• Innocent information is unrelated information often included with the evidence
you’re trying to recover
• Judges often issue a limiting phrase to the warrant which allows the police to
separate innocent information from evidence
• Plain view doctrine states that objects falling in plain view of an officer who has
the right to be in position to have that view are subject to seizure without a
warrant and may be introduced into evidence

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 14
Understanding Concepts and Terms Used in
Warrants (2 of 2)
• To apply the plain view doctrine, the following criteria must be met:
− The officer must be lawfully present at the place where the evidence can be
plainly viewed
− The officer must have a lawful right to access the object
− The incriminating character of the object must be “immediately apparent”
• These three conditions are referred to as the Horton test

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 15
Preparing for a Search (1 of 3)

• The following are tasks you should perform before you search for evidence:
− Identify the nature of the case
− Identify the type of OS or digital device
− Determine whether you can seize computers and digital devices
− Get a detailed description of the location
− Determine who is in charge
− Use additional technical expertise

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 16
Preparing for a Search (2 of 3)

• The following are tasks you should perform before you search for evidence
(continued):
− Determine the tools you need
 Your initial-response field kit should be lightweight and easy to
transport
− Prepare the investigation team

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 17
Preparing for a Search (3 of 3)

Figure 5-4 Items in an initial-


response field kit

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 18
Knowledge Check Activity 5-1

Which of the following file types are considered computer-generated records?


(Choose all that apply.)
a. A database file that contains customer addresses
b. System user login data
c. Files created using Microsoft Office
d. Internet proxy logs

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 19
Knowledge Check Activity 5-1: Answer

Which of the following file types are considered computer-generated records?


(Choose all that apply.)
Answer: b. System user login data; d. Internet proxy logs
Any data file (such as a system log file or a proxy server log) produced and
maintained by the computer’s operating system is a computer-generated record.
These types of files are output generated from a computer process or algorithm,
not usually data a person creates.

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 20
Securing a Digital Incident or Crime Scene (1
of 2)
• Investigators secure an incident or crime scene to preserve the evidence and
keep information confidential
• Define a secure perimeter using barrier tape
• For incidents involving mostly computers, the evidence is in the computer, but
the courts consider it physical evidence
− Digital devices could contain actual physical evidence, such as DNA
evidence or fingerprints on keyboards
• Professional curiosity can destroy evidence

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 21
Securing a Digital Incident or Crime Scene (2
of 2)
• Automated Fingerprint Identification System (AFIS) is a computerized
system for identifying fingerprints that is connected to a central database
− Used to identify criminal suspects and review thousands of fingerprint
samples at high speed
• Police can take elimination prints of everyone who had access to the crime
scene

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 22
Seizing Digital Evidence at the Scene

• Law enforcement can seize evidence with a proper warrant


• Corporate investigators might have the authority only to make an image of the
suspect’s drive
• When seizing digital evidence in criminal investigations, follow U.S. DOJ
standards for seizing digital data
• Civil investigations follow the same rules
• Consult with your attorney for extra guidelines

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 23
Preparing to Acquire Digital Evidence

• Ask your supervisor or senior forensics examiner in your organization the


following questions:
− Do you need to take the entire computer and all peripherals and media in the
immediate area?
− How will you protect the computer and media while transporting them to your lab?
− Is the computer powered on when you arrive?
− Is the suspect you’re investigating in the immediate area of the computer?
− Is it possible the suspect damaged or destroyed the computer, peripherals, or
media?

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 24
Processing Incident or Crime Scenes (1 of 4)

• The following guidelines offer suggestions on how to process a scene:


− Keep a journal to document your activities
− Secure the scene
 Remove people who are not part of the investigation
− Take video and still recordings of the area around the computer
− Sketch the incident or crime scene
− Check the state of computers as soon as possible

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 25
Processing Incident or Crime Scenes (2 of 4)

• The following guidelines offer suggestions on how to process a scene


(continued):
− Save data from current applications as safely as possible
− Record all active windows or shell sessions
− Make notes of everything you do when copying data from a live suspect
computer
− Close applications and shut down the computer

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 26
Processing Incident or Crime Scenes (3 of 4)

• Complete processing the scene, following these steps:


− Assign one person to collect and log all evidence
− Tag all evidence you collect with the current date and time, serial numbers or
unique features, make and model, and the name of the person who collected it
− Maintain two separate logs of collected evidence
− Maintain constant control of the collected evidence and the crime or incident scene

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 27
Processing Incident or Crime Scenes (4 of 4)

• Look for information related to the investigation


− Passwords, passphrases, PINs, bank accounts
• Collect as much personal information as possible about the suspect or victim
• Collect documentation and media related to the investigation
− Hardware, software, backup media, documentation, manuals

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 28
Processing Data Centers with RAID Systems

• Sparse acquisition is a technique for extracting evidence from large systems


− This technique extracts only data related to evidence for your case from
allocated files
− It minimizes how much data you need to analyze
• A drawback of this technique is that it doesn’t recover data in free or slack
space

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 29
Using a Technical Advisor

• Responsibilities of a technical advisor include the following:


− Know all aspects of the seized system
− Direct investigator handling sensitive material
− Help secure the scene
− Help document the planning strategy
− Conduct ad hoc trainings
− Document activities
− Help conduct the search and seizure

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 30
Documenting Evidence in a Lab

• Record your activities and findings as you work


− Maintain a journal to record the steps you take as you process evidence
• Your goal is to be able to reproduce the same results when you or another
investigator repeat the steps you took to collect evidence
• A journal serves as a reference that documents the methods you used to
process digital evidence

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 31
Processing and Handling Digital Evidence

• Use the following steps to create image files:


− Copy all image files to a large drive or a SAN
− Start your forensics tool to analyze the evidence
− Run an MD5 or SHA-1 hashing algorithm on the image files to get a digital
hash
− Secure the original media in an evidence locker

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 32
Special Situation Needs

• When seizing digital evidence from a crime or incident scene it may be


necessary to keep a suspect’s computer powered on before processing it and
shutting it down
• There is a special device that will allow you to disconnect power and allow a
computer to continue running
− The device is WiebeTech HotPlug Field Kit
• WiebeTech also sells the Mouse Jiggler MJ-3, which will prevent the screen
saver that might be password protected from starting

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 33
Archiving of Digital Evidence (1 of 2)

• The media you use to store digital evidence usually depends on how long you
need to keep it
• CDs, DVDs have a shelf-life of 5 to 10 years
− Lifespan: 2 to 5 years
• For large quantities of digital evidence, use magnetic tapes
− 4-mm DAT, DLT, and Super DLT tape cartridges
− The typical life span of a DLT is over 50 years
− A disadvantage of tape is slow read and write speeds

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 34
Archiving of Digital Evidence (2 of 2)

• M-Disc optical media is an option for digital evidence that needs to be stored for
a very long time
− Storage capacity ranges from 4.7 to 100 GB
− Manufacturer states that it has a shelf-life of over 1,000 years
• For all data preservation needs, be sure to make two copies of every image to
prevent data loss
• If practical, use different tools to create the two images

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 35
Evidence Retention and Media Storage Needs

• You might need to retain evidence indefinitely


− Check with your local prosecuting attorney’s office or state laws to make
sure you’re in compliance
• For the private sector, check with the organization’s legal department, which is
responsible for setting standards for evidence retention
• For cases that involve child pornography, evidence must be examined by law
enforcement
− The material is contraband and must not be stored by any person or
organization other than a law enforcement agency

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 36
Documenting Evidence (1 of 2)

• Create or use an evidence custody form


• An evidence custody form serves the following functions:
− Identifies the evidence
− Identifies who has handled the evidence
− Lists dates and times the evidence was handled
• You can add more information to your form
− Such as a section listing MD5 and SHA-1 hash values

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 37
Documenting Evidence (2 of 2)

• Include any detailed information you might need to reference


• Evidence bags also include labels or evidence forms you can use to document
your evidence
− Use antistatic bags for electronic components and be sure to write the
evidence information on the bag before placing evidence in it

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 38
Managing Digital Evidence Forms

• The purpose of an evidence form is to maintain the chain of custody of the


evidence
− Information about who transported and secured it in an evidence locker must
be recorded on the form
− The form must be updated every time someone examines evidence
• Another purpose of the evidence form is to provide a description of the evidence
− A thorough description will be helpful if there are multiple evidence items that
are identical

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 39
Transporting Digital Evidence

• You should have the following packing items to ensure safe transport:
− Antistatic bags of various sizes
− Sufficient quantities of bubble wrap
− Boxes or ruggedized containers of various sizes
− Packing tape and evidence tape
− Labels and permanent marking pens to list the contents of each evidence
container
• Evidence must be under surveillance at all times during transport

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 40
Obtaining a Digital Hash (1 of 3)

• One of the first methods of data verification was the cyclic redundancy check
(CRC)
− Which is a mathematical algorithm that determines whether a file’s contents have
changed
− It is not considered a forensic hashing algorithm
• First algorithm used for digital forensics was Message Digest 5 (MD5)
− Which is a mathematical formula that translates a file into a hexadecimal code
value, or a hash value
− If a bit or byte in the file changes, it alters the hash value, which can be used to
verify a file or drive has not been tampered with

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 41
Obtaining a Digital Hash (2 of 3)

• The following are three rules for forensic hashes:


− You cannot predict the hash value of a file or device
− No two hash values can be the same
− If anything changes in the file or device, the hash value must change
• Another hashing algorithm is the Secure Hash Algorithm version 1 (SHA-1)
− It was developed by the National Institute of Standards and Technology
(NIST)

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 42
Obtaining a Digital Hash (3 of 3)

• In both MD5 and SHA-1, collisions have occurred


• Most digital forensics hashing needs can be satisfied with a nonkeyed hash set
− Which is a unique hash number generated by a software tool, such as the
Linux md5sum command
• A keyed hash set is created by an encryption utility’s secret key
− You can use the secret key to create a unique hash value for a file

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 43
Employee Compliance Investigations

• Justification for compliance investigations should be based on ensuring


employees are performing their duties correctly
• For covert surveillance, employees are monitored for potential abuse of an
organization’s resources that typically include the computing and network
privileges
• Real-time surveillance may require sniffing data transmissions between a
suspect’s computer and a network server
− Network sniffer tools, such as Wireshark, are used to determine what data is
being transmitted over the network

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 44
Knowledge Check Activity 5-2

For cases that might require retention of digital evidence longer than 10 years,
which of the following media types should you consider using?
a. Optical media such as CDs or DVDs
b. Secondary memory media such as hard disk drives
c. Flash-based media such as solid-state drives
d. Magnetic tape media such as DLT

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 45
Knowledge Check Activity 5-2: Answer

For cases that might require retention of digital evidence longer than 10 years,
which of the following media types should you consider using?
Answer: d. Magnetic tape media such as DLT
Of all data storage media, magnetic tapes, such as DLT, can maintain data integrity the
longest. The typical lifespan of a DLT tape is over 50 years, which makes this media ideal
for saving important case data. Optical media, such as CDs and DVDs, can deteriorate
after 5 to 10 years. Most manufacturers will warranty solid-state drives for 10 years;
however, the manufacturers will only replace the drive, not the data, if the drive fails

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 46
Self Assessment

As a digital forensics examiner assigned to secure a crime or incident scene,


what should be your first consideration?

As a private business digital forensics examiner, what is the first step you should
take to avoid becoming an agent of the police?

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 47
Summary (1 of 2)

Now that the lesson has ended, you should be able to:
• Explain how to identify digital evidence
• Describe how to collect evidence at private-sector incident scenes
• Explain guidelines for processing law enforcement crime scenes
• List the steps in preparing for an evidence search
• Describe how to secure a computer incident or crime scene

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 48
Summary (2 of 2)

Now that the lesson has ended, you should be able to (continued):
• Explain guidelines for seizing digital evidence at the scene
• List procedures for transporting and storing digital evidence
• Explain how to obtain a digital hash
• Understand employee compliance investigations

Nelson/Phillips/Steuart/Wilson, Guide to Computer Forensics and Investigations, 7th Edition. ©2025 Cengage Learning, Inc. All Rights
Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part. 49

You might also like