VI- SEM/III B.E. CSE (CS) Prepared By: P.R.
Ajitha/AP/CSE
DEPARTMENT OF COMPUTER SCIENCE &
ENGINEERING (CYBER SECURITY)
CB3601(Cyber Forensics )
UNIT 2
Prepared By:[Link]/AP/CSE
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
UNIT – 2
EVIDENCE COLLECTION AND FORENSICS TOOLS
Processing Crime and Incident Scenes
Digital evidence can be any information stored or transmitted in digital form. Digital data is a tangible
object. General tasks investigators perform when working with digital evidence :
1. Identify digital information or artifacts that can be used as evidence
2. Collect, preserve and document evidence
3. Analyze, identify and organize evidence
4. Rebuild evidence or repeat a situation to verify that the results can be reproduced reliably
Collecting computers and processing a criminal or incident scene must be done systematically
Crime scene refers to the location where a crime occurred or where evidence of a crime exists. For the
purposes of this set of directives, crime scene will also refer to the scene of an incident that may not be
criminal in nature, but where common crime scene methods are used to gather evidence.
Evidence is any substance or material found or recovered in connection with a criminal investigation.
Evidence processing refers to the specific actions taken at a crime scene or collision scene to identify,
locate, document, preserve and collect evidence and/or known standards.
Software refers to programs that have been or can be installed in a computer. Storage media refers to
digital storage devices include, but may not be limited to, computer disks, flash cards, thumb drives and
magnetic tape used to store computer data and/or images captured via a digital camera.
Digital evidence
Digital evidence is useful in a wide range of criminal investigations such as homicides, sex offences,
missing persons, cheat persons, child abuse, fraud and theft.
Digital evidence helps in tracing how a crime was committed, provide investigative leads, disapprove
or support witness statements and identify likely suspects.
Digital evidence is defined as information stored or transmitted in binary form that may be relied upon
in court.
For considering multiple sources of digital evidence, computer systems can be categorised in to three
groups :
* Open Computer systems
* Communication systems
* Embedded computer systems.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Processing and Handling Digital Evidence
Must maintain the integrity of digital evidence in the lab, when collecting it in the field. The first task
is to preserve the disk data. If you have a suspect computer that hasn’t been copied with an imaging
tool, you must create a copy.
It is necessary to do the suspect drive read-only and document this step. If the disk has been copied
with an imaging tool, you must preserve the image files. With most imaging tools, you can create
smaller, compressed volume sets to make archiving your data easier.
Steps to create image files :
o Copy all image files to a large drive.
o Start forensics tool to analyze the evidence.
o Run an MD5 or SHA-1 hashing algorithm on the image files to get a digital hash.
o When finish copying image files to a larger drive, secure the original media in an evidence
locker. Don’t work with the original media; it should be stored in a locker that has an evidence
custody form. Be sure to fill out the form and date it.
Preparing to Acquire Digital Evidence
The evidence you acquire at the scene depends on the nature of the case and the alleged crime or
violation.
Following questions are asked to supervisor or senior forensics examiner :
o Do you need to take the entire computer and all peripherals and media in the immediate area?
o How are you going to protect the computer and media while transporting them to your lab?
o Is the computer powered on when you arrive?
o Is the suspect you’re investigating in the immediate area of the computer?
o Is it possible the suspect damaged or destroyed the computer, peripherals, or media?
o Will you have to separate the suspect from the computer?
Digital forensics is the discipline that deals with all the process that includes collecting digital materials
from the crime scene, examining, analyzing and reporting them according to certain standards and
methods.
Digital forensics consists of four main steps: preparation, collection, analysis and reporting.
Collection is about accumulating digital evidence related with information technologies from the crime
scene.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Digital devices store the data in internal and external storage devices. The stored data has to be taken
with certain methods. Shadow copying only the criminal part of the stored data or all of it from a
device is named as image acquisition
Direct analysis of digital evidences isn’t considered appropriate because the data storage unit of the
related device can break down and investigator can make a change on the evidence. For the forensics
investigator, in order to assure the integrity of the evidence, a forensic copy must be taken.
Source of Evidence
Understanding rules of evidence
1. Consistent practices help verify your work and enhance your credibility.
2. Comply with your state’s rules of evidence or with the federal rules of evidence.
3. Evidence admitted in a criminal case can be used in a civil suit and vice versa.
4. Keep current on the latest rulings and directives on collecting, processing, storing and admitting
digital evidence.
5. Data you discover from a forensic examination falls under your state’s rules of evidence.
6. Digital evidence is unlike other physical evidence because it can be changed more easily.
7. Most federal courts have interpreted computer records as hearsay evidence.
• Computer records are usually divided into :
Computer-generated records
Computer-stored records
• Computer and digitally stored records must be shown to be authentic and trustworthy. Computer-
generated records are considered authentic if the program that created the output is functioning
correctly. Collecting evidence according to the proper steps of evidence control helps ensure that
the computer evidence is authentic.
Authorization :
• Before gathering digital evidence relating to an investigation, computer security professionals should
obtain instructions and written authorization from their attorneys.
• Usually the employer can search its employee’s computers, e-mail and other data. For accessing
personal and private data a search warrant is needed. In such case it may be permissible to seize the
computer and secure it from alteration until the police arrive.
• A valid search warrant must describe particular property to be seized and probable cause for seizing
it. Warrant should contain each item to be seized and the types of evidence that will be to prevent
mistakes or misuse such as searching the wrong home or seizing items that are outside of the scope
of the warrant.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
• Digital investigators are authorized to collect and examine that is directly pertinent to the
investigation.
• The following shall establish evidentiary-related guidelines and procedures used for collecting
evidence in the field :
1. The first officer to arrive at any incident scene shall be responsible for securing the area and
preserving all observable evidence. Evidence technician work should not begin work until the
entire area has been secured and declared safe.
2. Evidence encountered at a scene shall be handled with care to preserve it for future processing.
Discretion should be used when determining what evidence to process at the scene. Such decisions
shall be based upon the seriousness of the offense, officer expertise and the processing materials
available.
3. The progression of evidentiary-related tasks shall generally be as follows :
a. Secure the scene;
b. Photograph and/or videotape evidence;
c. Develop potential evidence for latent prints;
d. Sketch the scene;
e. Label and collect evidence;
f. Transport and appropriately store evidence;
g. Analyze evidence.
4. Officers seizing evidence shall be responsible for notifying the property team of the need for
laboratory examinations. Evidence technicians and/or other experts should be consulted when
deemed appropriate.
5. Each item of evidence shall be inventoried using the department property documentation system.
The system contains provisions for recording the following : Agency case number; offense;
property invoice number; date seized; owner/suspect identifiers; current location; item
descriptions; disposition recommendation; and chain of custody information. The property
manager or designee should review property cards upon the submission of evidence. Improperly
completed property cards may be returned to the officer completing the card. The officer’s
supervisor may also be notified.
6. As per the ACT, police officers are required to provide receipts to persons from whom they have
seized items of evidence or contraband.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Computer Equipment Seizure
The following shall establish procedures for the seizure of computer equipment :
1. Officers should exercise extreme caution when seizing and/or examining computer equipment so as
not to cause severe damage or the loss of valuable data.
2. Persons possessing specialized knowledge of computers and computer security should be consulted
during the preparation and execution of search warrants when necessary.
3. A person skilled in computer operation should be used to examine such equipment prior to startup.
4. Whenever possible, a copy of the hard drive should be made before examination. The original should
then be placed in secure storage and the copy used for examination purposes.
5. When computer equipment is in operation at the time of seizure, the CPU should be disconnected
from the power source. This procedure will ensure that all contents stored on the hard drive remain
intact. However, data cached in memory will be lost when the computer is powered down.
6. Strong consideration should be given to photographing and/or videotaping on-screen images before
operating computer equipment is disconnected from the power source. This procedure will ensure
that pertinent evidence will be captured when cached memory and/or embedded scripts are involved.
7. Non-operating computers, disks, drives and related peripherals should be considered fragile. Such
equipment should be appropriately packaged, handled, and transported.
8. Special care must be taken to avoid exposing removable media to magnetic fields, static electricity
and physical force.
Forensic analysis function is sometimes broken into two parts :
o Examination
o Analysis
Examination phase involves the use of forensic tools to recover deleted files and retrieve and
characterize operating system artifacts and other relevant material. Analysis phase uses those
materials to answer the questions that gave rise to the investigation. Analysis function is also
responsible for reporting and presenting the investigation’s findings.
Public sector authorization may take the form of a search warrant; seizure of the relevant items
containing the information
Private sector authorization is specified by the organization’s policy; many use affidavit; more
common to authorize the collection of images of digital information.
Private section includes private corporations and government agencies not involved with law
enforcement. They must comply with state public disclosure and federal freedom of information act
and make certain documents available as public records. Law enforcement is called if needed.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Private organization wishing to search an employee’s computer must generally meet the following
conditions :
1. Employee made aware of organizational policy that search may occur
2. Search must be justified at its inception
3. Search must be permissible in its scope
4. Organization has clear ownership over container that material was discovered in
5. Search must be authorized by the responsible manager or administrator
Incident response policy must spell out the procedures for initiating investigative process. Particularly
critical in private sector, as private organizations do not enjoy the broad immunity accorded to law
enforcement investigations
Digital evidence collection follows a four-step methodology :
1. Identify sources of evidentiary material
2. Authenticate the evidentiary material
3. Collect the evidentiary material
4. Maintain a documented chain of custody
2.1.1 Document Evidence
Documentary evidence is any evidence that is, or can be, introduced at a trial in the form of documents,
as distinguished from oral testimony. Documentary evidence is most widely understood to refer to
writings on paper (such as an invoice, a contract or a will), but the term can also apply to any media by
which information can be preserved, such as photographs; a medium that needs a mechanical device to
be viewed, such as a tape recording or film; and a printed form of digital evidence, such as emails,
spreadsheets, etc.
Evidence contained in or on documents can be a form of real evidence. For example, a contract offered
to prove the terms it contains is both documentary and real evidence. When a party offers a document
into evidence, the party must authenticate it the same way as any other real evidence, either by a witness
who can identify the document or by witnesses who can establish a chain of custody for the document.
Ways to Challenge Documenting Evidence
When people deal with documentary evidence, it is a good idea to consider these four potential pitfalls,
which could be used to challenge a document’s admissibility in court : Parol evidence, Authentication, Best
evidence and Hearsay.
The parol evidence rule prohibits the admission of certain evidence concerning the terms of a written
agreement. It operates on the assumption that whatever is included in a signed agreement contains the final
and complete agreement of the parties.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Authentication is essentially showing the court that a piece of evidence is what it claims to be and
documentary evidence can be authenticated similar to other real evidence.
The best evidence rule can be used to deny the admissibility of copies or replications of certain
documents. Under this rule, when the contents of a written document are offered in evidence, the court
will not accept a copy or other proof of the document’s content in place of the original document unless
an adequate explanation is offered for the absence of the original.
Hearsay : Documents can be considered hearsay if they contain statements made out of court (and not
under oath) and where they are being used in court to prove the truth of those statements.
Documenting Evidence in the Lab
After collecting digital evidence at the scene, send it to a forensics lab, which should be a controlled
environment that ensures the security and integrity of digital evidence.
In any investigative work, be sure to record investigator activities and findings as you work. To do so,
investigator can maintain a journal to record the steps as taken as for processing evidence.
Main goal is to be able to reproduce the same results when you or another investigator repeat the steps
you took to collect evidence.
If you get different results when you repeat the steps, the credibility of your evidence becomes
questionable. At best, the evidence’s value is compromised; at worst, the evidence will be dis-qualified.
Because of the nature of electronic components, failures do occur.
For example, you might not be able to repeat a data recovery because of a hardware failure, such as a
disk drive head crash. Be sure to report all facts and events as they occur. Besides verifying your work,
a journal serves as a reference that documents the methods you used to process digital evidence. You
and others can use it for training and guidance on other investigations.
Working with File systems
File System
File systems are abstraction that enables users to read, manipulate and organize data. Typically the data
is stored in units known as files in a hierarchical tree where the nodes are known as directories.
The file system enables a uniform view, independent of the underlying storage devices which can range
between anything from floppy drives to hard drives and flash memory cards. Since file systems evolved
from stand-alone computers the connection between the logical file system and the storage device was
typically a one-to-one mapping.
The DOS and Windows file systems use fixed-size clusters. Even if the actual data being stored requires
less storage than the cluster size, an entire cluster is reserved for the file. This unused space is called
the slack space.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
A cluster, also known as an allocation unit, consists of one or more sectors of storage space and
represents the minimum amount of space that an operating system allocates when saving the contents
of a file to a disk.
File system must be mounted before it can be available to processes on the system. Procedure for
mounting file system is as follows.
1. Mount point is an empty directory at which the mounted file system will be attached.
2. Name of the device and location within the file structure at which to attach the file system is
required.
3. Operating system verifies that the device contains a valid file system.
4. Device driver is used by operating system for these verifications.
5. Finally operating system mounts the file system at a specified mount point.
File Allocation Table
A table that the operating system uses to locate files on a disk. Due to fragmentation, a file may be
divided into many sections that are scattered around the disk. The FAT keeps track of all these pieces.
The FAT system for older versions of Windows 95 is called FAT16 and the one for new versions of
Windows 95 and Windows 98 is called FAT32.
FAT file systems are commonly found on floppy disks, flash memory cards, digital cameras and many
other portable devices because of their relative simplicity.
File and folders are organized on FAT formatted volume which uses directory and file allocation table.
The (C:\ or D:\) is the root folder at a per defined location on the volume. Folder contains a list of file
and subdirectories. Fig. 2.2.1 shows the folder view of the file system.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Folder view contains starting cluster, date, time associated with each file. FAT file system shows only last
accessed date not time. At command line, dir command is used to gate the information about files and
directory.
The FAT shows only a list with one entry for each cluster in a volume. Each entry in the FAT indicates what
the associated cluster is being used for the following Fig. 2.2.1 shows output from norton disk editor on file
allocation table.
Free allocation is marked by zero in the cluster. If it contains some value (i.e. Greater than zero) then
that number is given to the next cluster for a given file or folder. EOF means end of file. Where file end,
FAT marked it as EOF.
Subdirectories are a special type of file. It contains information such as names, attributes, dates, times,
sizes and the first cluster of each file on the system.
When a file is deleted, the file system will perform one of two tasks on the allocation table. The file’s
entry on the file allocation table marked as free space or the file’s entry on the list is erased and then the
space is marked as free.
If a file needs to be placed on the storage unit, the operating system will put the file in the space marked
as empty. After the new file is written to the empty space , the deleted file is now gone forever. When a
deleted file is to be recovered, the user must not manipulate any files because if the empty space is used,
then the file can never be retrieved.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Floppy diskette uses FAT12 file system. Each entry contains 12 bits in the FAT. FAT16 uses 16 bit
fields to identify a cluster. Hard disk uses FAT32 and 28 bits plus 4 bit reserved field used to identify
the cluster.
Registry
• The registry is made up of keys. Each key is like the branch of a tree. Each key has one parent key and zero
or more child keys. Each key can contain zero or more Values , each of which contains a single piece of
data.
• Windows operating systems use the registry to store system configuration information and usage details.
Registry is a database that stores initialization files such as hardware/software configuration, network
connections, user preferences, setup information.
• The registry contains following main keys :
1. HKEY_CLASSES_ROOT : It contains information on file types, including which programs are used to
open a particular file type.
2. HKEY_CURRENT_USER : It contains user-specific settings that are built from information in the
HKEY_USERS key during the logon process.
3. HKEY_LOCAL_MACHINE : It contains computer specific information including installed hardware
and software. This is the one users tend to spend the most time in.
4. HKEY_USERS : It contains information about all of the users who log on to the computer. This includes
settings for programs, desktop configurations and so on. This key contains one sub-key for each user.
5. HKEY_CURRENT_CONFIG : It contains information about the computer’s hardware configuration.
• In some registry file, keys value stored in hexadecimal format but it can be converted to ASCII and saved
to a text file.
• The registry contains the configuration information for the hardware and software and may also contain
information about recently used programs and files.15 proof that a suspect had installed a program or
application may be found in the registry.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Artifacts
Artifacts are digital traces left behind by user activities, system processes, or applications. They are
crucial in forensic investigations because they provide evidence of actions performed on a device. Artifacts
can be found in various locations, such as system logs, file metadata, internet history, and memory dumps.
Types of Digital Artifacts
1. System Artifacts
o Event Logs: Records of system events, including logins, file modifications, and security
incidents.
o Registry Entries: Stores system and user preferences, installed applications, and device
connection history.
o Prefetch Files: Helps track recently executed applications and their execution timestamps.
2. User Activity Artifacts
o Browser History & Cache: Contains records of websites visited, cookies, and saved
passwords.
o Recent Documents: Lists the files recently accessed by a user.
o Clipboard Data: Stores temporarily copied text, images, or files.
3. Application Artifacts
o Email Logs & Attachments: Stores sent, received, and deleted emails.
o Chat & Messaging Logs: Includes records from WhatsApp, Skype, and other
communication platforms.
o Social Media Artifacts: Stores posts, comments, and login timestamps.
4. Memory & Volatile Data Artifacts
o RAM Dumps: Contains live session data, including encryption keys and running processes.
o Page file & Swap file: Stores temporary memory data that may contain sensitive
information.
o Hibernation Files: Captures the system state before shutdown and can store critical forensic
data.
5. File System Artifacts
o Metadata (MAC Times): Tracks file modification, access, and creation timestamps.
o Deleted Files & Recycle Bin Data: Recovers files deleted by users but not yet overwritten.
o Hidden & Encrypted Files: Stores data that users attempt to conceal or protect.
Importance of Artifacts in Forensics
o Helps reconstruct a timeline of activities.
o Assists in identifying unauthorized access or cyberattacks.
o Provides evidence for legal investigations.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Current Computer Forensics Tools : Software/ Hardware Tools
• The field of computer forensic investigation includes the capture and analysis of digital data to either prove a crime
has or has not been committed. The range of crimes can include computer related crime as well as other crimes
that have left evidence in digital formats.
• There are two basic types of data that are collected, persistent data and volatile data. Persistent data is that which
is stored on a hard drive or another medium and is preserved when the computer is turned off. Volatile data is any
data that is stored in memory or exist in transit and will be lost when the computer is turned off. Volatile data might
be key evidence, so it is important that if the computer is on at the scene of the crime it remain on. There are a
variety of tools used to collect data.
• Tools are used to analyze digital data and prove or disprove criminal activity. It is used in 2 of the 3 phases of
computer forensics.
1. Acquisition - Images systems and gathers evidence
2. Analysis - Examines data and recovers deleted content
3. Presentation - Tools not used
Types of Computer Forensics Tools
1. Hardware forensic tools : Range from single-purpose components to complete computer systems and servers
2. Software forensic tools : There are two types of software forensic tools. Command-line applications and GUI
applications are two types. It is commonly used to copy data from a suspect’s disk drive to an image file.
Computer Forensic Tools Capabilities
1. Recover deleted files
2. Find out what external devices have been attached and what users accessed them
3. Determine what programs ran
4. Recover web pages
5. Recover emails and users who read them
6. Recover chat logs
7. Determine file servers used
8. Discover document’s hidden history
9. Recover phone records and SMS text messages from mobile devices
Tasks Performed by Computer Forensics Tools
1. Acquisition
2. Validation and discrimination
3. Extraction
4. Reconstruction
5. Reporting
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Computer forensics procedures can be distilled into three major components :
1) Make a digital copy of the original evidence. Investigator make a copy of the evidence and work with the copy to
reduce the possibility of inadvertently changing the original evidence.
2) Authenticate that the copy of the evidence. Investigators must verify the copy of the evidence is exactly the same
as the original.
3) Analyze the digital copy. The specific procedures performed in an investigation are determined by the specific
circumstances under which the investigation is occurring.
Computer forensics is a very important branch of computer science in relation to computer and Internet related
crimes. Earlier, computers were only used to produce data but now it has expanded to all devices related to digital
data. The goal of computer forensics is to perform crime investigations by using evidence from digital data to find
who was the responsible for that particular crime.
For better research and investigation, developers have created many computer forensics tools. Police departments
and investigation agencies select the tools based on various factors including budget and available experts on the
team.
These computer forensics tools can also be classified into various categories :
1. Disk and data capture tools
2. File viewers
3. File analysis tools
4. Registry analysis tools
5. Internet analysis tools
6. Email analysis tools
7. Mobile devices analysis tools
8. Mac OS analysis tools
9. Network forensics tools
10. Database forensics tools
2.3.1 Tools
1. The Sleuth Kit (TSK)
The Sleuth Kit (TSK) is a library and collection of Unix- and Windows-based tools and utilities to allow for
the forensic analysis of computer systems. It allows examination of DOS, BSD, Mac, Sun, GPT partitions
and disks.
It also includes the autopsy forensic browser as a graphical analysis tool and supports integration with SQLite
database. It can be run on live Windows systems for incident response.
With this kit, the user can examine the computer file systems through a non-intrusive approach that is not
dependent on the investigated machine operating system to process the file system, deleted and hidden from
files DOS, BSD, Mac, Sun and Linux partitions.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
The results generated by Sleuth Kit tools are used by another tool. The autopsy forensic browser which
presents such details as image integrity, keyword searches and other automatized operations about the
investigated partition through a graphical interface.
The Sleuth Kit was written in C and Perl and uses an aspect of the TCT code.
2. The Coroner’s Toolkit (TCT)
• The TCT tools do not recognize NTFS, FAT or EXT3 partitions, making them of little use when performing
forensic investigations in machines with Microsoft Windows and/or Linux operating systems with EXT3 file
systems.
• Investigating Windows (FAT) partitions with TCT is only possible with a conversion to EXT2 format,
demanding alterations on the i-nodes table of the investigated partition. This activity is not always possible
with data analysis.
3. FTK TOOL
• FTK can analyze data from several sources, including image files from other vendors. FTK also produces a
case log file, where you can maintain a detailed log of all activities during the examination such as keyword
searches and data extractions.
• FTK provides two options for searching for keywords. One option is an indexed search, which catalogs all
words on the evidence drive so that FTK can find them quickly. The other option is live search, which can
locate items such as text hidden in unallocated space that might not turn up in an indexed search.
4. Maresware
• Maresware computer forensics software provides an essential set of tools for investigating computer records
and securing private information. It is highly flexible to meet the needs of all types of investigators including :
law enforcement, intelligence agency, private investigator, corporate security officers and human resources
personnel.
• It is used within a forensic paradigm, the software enables discovery of evidence for use in criminal or civil
legal proceedings. Internal investigators can develop documentation to support disciplinary actions, yet do so
non-invasively, to preserve evidence that could end up in court.
Functions of Maresware
1. Discovery of hidden files(such as NTFS Alternate Data Streams)
2. For incident response purposes
3. Evaluation of timelines
4. Key word searching
5. Files verification
6. Drive wiping for information privacy and security
7. File reformatting
8. Documenting all the examiner’s steps and procedures
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
5. Pro-Discover Basic
Pro-Discover basic from technology pathways is a forensics data analysis tool. It can be used to acquire and
analyze data from several different file systems
Forensic Suite
A Forensic Suite is a comprehensive set of digital forensic tools designed to assist investigators in
acquiring, analyzing, and managing digital evidence. These suites provide multiple functionalities, including
disk imaging, file recovery, network forensics, and report generation.
Features of Forensic Suites
Forensic suites typically include:
1. Data Acquisition – Capturing forensic images of storage devices while preserving integrity.
2. Data Analysis – Identifying, recovering, and analyzing files, emails, and hidden data.
3. Memory Forensics – Extracting and examining volatile data such as RAM dumps.
4. Network Forensics – Monitoring and capturing network traffic for analysis.
5. Mobile Device Forensics – Extracting data from smartphones and tablets.
6. Reporting – Generating court-admissible forensic reports.
Popular Forensic Suites
1. Autopsy & The Sleuth Kit
Type: Open-source forensic suite
Functions:
o File system analysis
o Deleted file recovery
o Timeline analysis
o Keyword searching
Usage: Commonly used in law enforcement and academia.
2. FTK (Forensic Toolkit)
Type: Commercial forensic suite (developed by Access Data)
Functions:
o Full-disk imaging
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
o Email and document analysis
o Password cracking
Usage: Popular among law enforcement agencies and cybersecurity professionals.
3. EnCase
Type: Commercial forensic suite (developed by OpenText)
Functions:
o File system analysis
o Mobile and computer forensic analysis
o Advanced reporting tools
Usage: Used in corporate investigations and law enforcement.
4. X-Ways Forensics
Type: Lightweight, commercial forensic tool
Functions:
o Disk imaging and analysis
o Deleted file recovery
o Registry and log file analysis
Usage: Preferred by digital forensics professionals for efficiency and speed.
5. Cellebrite UFED
Type: Mobile forensic suite
Functions:
o Extracting and analyzing data from smartphones
o Bypassing device security and passwords
o Call logs, messages, and GPS data analysis
Usage: Primarily used in mobile device forensics.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Acquisition and Seizure of Evidence from Computers and Mobile Devices
The acquisition and seizure of digital evidence is a critical process in digital forensics. It involves
identifying, collecting, and preserving electronic data from computers and mobile devices while ensuring its
integrity for legal investigations.
1. Principles of Digital Evidence Acquisition
Preservation: Ensure that data is not altered or damaged during collection.
Integrity: Maintain the originality of evidence using cryptographic hashing (e.g., MD5, SHA-256).
Chain of Custody: Properly document handling and storage of evidence.
Admissibility: Follow legal procedures to make evidence acceptable in court.
2. Evidence Seizure Process
A. Seizing Computers
1. Identify the Device
o Locate the suspect’s system (desktop, laptop, external storage).
2. Document the Scene
o Photograph the setup (cables, connected devices, running applications).
o Record serial numbers and system information.
3. Power Considerations
o If the system is ON, capture volatile memory (RAM) using tools like FTK Imager or
Volatility.
o If the system is OFF, do not turn it on. Instead, create a forensic image of the disk.
4. Storage Device Handling
o Use write blockers to prevent tampering.
o Clone the hard drive using forensic tools like EnCase or dd.
5. Package and Transport
o Store devices in anti-static bags.
o Maintain logs of evidence transfer.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
B. Seizing Mobile Devices
1. Secure the Device
o Use Faraday bags to block network signals.
o Document screen activity and running applications.
2. Identify Lock Mechanisms
o Check for PINs, patterns, biometrics (fingerprint, face recognition).
o Use tools like Cellebrite UFED to bypass locks.
3. Extract Data
o Logical Extraction: Extract visible data (contacts, messages, media).
o Physical Extraction: Create a complete bit-by-bit copy of the storage.
4. Preserve SIM and Memory Cards
o Remove and analyze SIM using forensic readers.
o Clone SD cards using write-protected adapters.
5. Transport and Storage
o Keep devices in temperature-controlled environments.
o Maintain logs for the chain of custody.
3. Methods of Evidence Acquisition
A. Live Acquisition
Collects data from a running system (RAM, active processes).
Used when immediate shutdown may erase evidence.
Tools: Volatility, FTK Imager, X-Ways Forensics.
B. Dead Acquisition
Captures forensic images of storage devices when the system is powered off.
Ensures integrity by preventing data changes.
Tools: Autopsy, EnCase, dd command.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
C. Network Acquisition
Captures live network traffic, logs, and communications.
Used in cybercrime and hacking investigations.
Tools: Wireshark, tcp dump, Network Miner.
4. Tools for Evidence Acquisition
Tool Function
FTK Imager Disk imaging, memory forensics
EnCase File recovery, disk analysis
Autopsy Open-source forensic analysis
Cellebrite UFED Mobile device extraction
Volatility RAM analysis
Wireshark Network packet analysis
Chain of Custody
The Chain of Custody refers to a detailed record that tracks the movement, handling, and storage of digital
evidence throughout an investigation. It ensures that evidence is not altered, tampered with, or lost.
Role in Digital Forensics
The Chain of Custody (CoC) is a crucial process in digital forensics that ensures the integrity,
authenticity, and admissibility of digital evidence in court. It documents every stage of evidence handling,
from collection to presentation in legal proceedings.
Importance of Chain of Custody
Legal Admissibility: Ensures that evidence is accepted in court.
Evidence Integrity: Prevents unauthorized access and modifications.
Accountability: Tracks who handled the evidence and when.
Investigation Transparency: Provides a clear record of evidence movement.
Steps in Maintaining the Chain of Custody
Step 1: Evidence Collection
Identify and document all relevant digital evidence (computers, mobile devices, storage media).
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Use forensic tools (FTK Imager, EnCase) to create forensic images.
Photograph the crime scene before handling any device.
Step 2: Documentation
Record evidence details in a Chain of Custody form, including:
o Date & Time of Collection
o Location of Seizure
o Name of Collector
o Description of Evidence (serial number, device type, storage capacity)
o Condition of Evidence (damaged, functional, locked, etc.)
Step 3: Evidence Handling
Use write blockers to prevent data modification.
Store mobile devices in Faraday bags to prevent remote access.
Seal evidence in tamper-proof packaging with labels.
Step 4: Secure Storage
Store evidence in a forensic lab with controlled access.
Maintain proper environmental conditions (temperature, humidity).
Restrict access to authorized personnel only.
Step 5: Evidence Transfer
Document every instance of evidence transfer between investigators.
Record names, signatures, dates, and reasons for transfer.
Ensure evidence is transported securely to forensic labs or courts.
Step 6: Analysis and Reporting
Perform forensic analysis using tools like Autopsy, EnCase, and Volatility.
Maintain logs of all actions performed on the evidence.
Generate reports with findings for legal proceedings.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Step 7: Presentation in Court
Provide evidence with proper documentation.
Ensure that the Chain of Custody form is complete and verified.
The forensic investigator may be called to testify about evidence handling and analysis.
Chain of Custody Form Example
Date & Time Evidence Description Collector Storage Location Remarks
2025-03-02, Dell Laptop, Serial No. Officer A Evidence Room 1 Seized from suspect
10:00 AM XYZ123
2025-03-02, USB Drive (16GB) Officer B Lab for Imaging No visible damage
11:30 AM
2025-03-03, Hard Disk (1TB) Forensic Analyst Forensic Lab Cloning in progress
09:00 AM
Challenges in Maintaining Chain of Custody
Human Error: Missing documentation, improper labelling.
Unauthorized Access: Failure to restrict access can lead to evidence tampering.
Lack of Standard Procedures: Inconsistencies in evidence handling.
Storage Issues: Poor environmental conditions may damage evidence.
Forensic Tools in Digital Investigations
Forensic tools are essential in digital investigations for collecting, analyzing, preserving, and presenting
electronic evidence. These tools help investigators extract information from computers, mobile devices,
networks, and cloud storage while ensuring data integrity and legal admissibility.
1. Types of Forensic Tools
Digital forensic tools can be categorized based on their purpose and functionality:
A. Disk and Data Imaging Tools
Used to create forensic copies (disk images) of hard drives, SSDs, USBs, and other storage media.
Imaging ensures that investigators work on a copy rather than the original evidence.
FTK Imager – Creates forensic disk images and previews files.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
EnCase – Industry-standard for evidence acquisition and analysis.
dd (Linux Command) – Command-line tool for disk cloning and data imaging.
Importance
Preserves original data integrity.
Prevents accidental modifications.
Allows offline forensic analysis.
B. File System Analysis Tools
Used to examine file structures, deleted files, timestamps, and metadata.
Autopsy (Sleuth Kit) – GUI-based forensic suite for file system analysis.
X-Ways Forensics – Advanced file system analysis tool with hex editing.
TSK (The Sleuth Kit) – Command-line tool for investigating file systems.
Key Features:
Recovers deleted files.
Analyzes timestamps (MAC times: Modified, Accessed, Created).
Detects hidden partitions and encrypted files
C. Memory Forensics Tools
Analyze RAM (volatile memory) to extract running processes, encryption keys, passwords, and
malware.
Volatility – Open-source memory analysis framework.
Rekall – Advanced memory forensics and live memory acquisition tool.
DumpIt – Simple tool for creating memory dumps.
Importance
Helps detect malware and rootkits hidden in memory.
Recovers encryption keys and unsaved documents.
Tracks running processes and network connections.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
D. Mobile Forensic Tools
Used to extract contacts, messages, call logs, GPS data, photos, and app data from smartphones.
Cellebrite UFED – Industry-leading tool for mobile data extraction.
Magnet AXIOM – Comprehensive mobile and computer forensic solution.
Oxygen Forensic Suite – Extracts app data, cloud storage, and encrypted files.
MOBILedit Forensic – Supports thousands of mobile devices.
Key Features:
Extracts deleted messages and call logs.
Recovers GPS location history.
Bypasses screen locks and encrypted data.
E. Network Forensics Tools
Analyze network traffic, detect cyber threats, and investigate data breaches.
Wireshark – Packet sniffer for capturing and analyzing network traffic.
NetworkMiner – Passive network traffic analysis tool.
Xplico – Extracts files, emails, and VoIP calls from network captures.
Importance
Detects intrusions, malware, and data exfiltration.
Tracks IP addresses, connections, and session data.
Helps in cyber attack investigations.
F. Cloud Forensics Tools
Investigates data stored in cloud services like Google Drive, Dropbox, and AWS.
Magnet AXIOM Cloud – Extracts data from cloud accounts.
X1 Social Discovery – Collects forensic data from social media.
AWS CloudTrail – Tracks activities and logs in AWS environments.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Importance
Recovers deleted or modified cloud files.
Investigates cybercrimes involving cloud-based services.
Tracks user activities and access logs.
G. Email Forensics Tools
Analyze email headers, attachments, metadata, and phishing attacks.
MailXaminer – Advanced email analysis and search tool.
E3 Forensic Platform – Investigates email fraud and data breaches.
Aid4Mail Investigator – Extracts email data from multiple formats.
Key Features:
Identifies spoofed emails and phishing scams.
Recovers deleted emails from servers.
Extracts metadata (IP, sender, receiver, timestamps).
H. Password Cracking Tools
Used to recover passwords from encrypted files, systems, and databases.
John the Ripper – Open-source password cracking tool.
Hashcat – High-speed GPU-based password recovery tool.
Passware Kit – Recovers passwords from encrypted documents and drives.
Importance
Helps decrypt protected files and systems.
Recovers lost or forgotten passwords.
Bypasses system authentication barriers.
I. Steganography Detection Tools
Used to detect and extract hidden messages in images, audio, and video.
StegExpose – Detects hidden data in images.
OpenStego – Steganography detection and analysis tool.
OutGuess – Extracts hidden messages in digital media.
VI- SEM/III B.E. CSE (CS) Prepared By: [Link]/AP/CSE
Importance
Detects concealed data and cyber espionage.
Uncovers hidden messages used in cybercrimes.
Extracts embedded files from digital images.
Choosing the Right Forensic Tool
When selecting a forensic tool, consider:
Purpose – Is it for disk imaging, mobile analysis, or network forensics?
Compatibility – Supports Windows, Linux, macOS, Android, iOS?
Legal Admissibility – Is the tool accepted in courts?
Ease of Use – Does it have a GUI or require command-line expertise?
Cost – Is it open-source or commercial?
Challenges in Using Forensic Tools
Encryption and Password Protection – Difficult to bypass strong encryption.
Cloud and Remote Storage – Limited access to cloud-based evidence.
Anti-Forensic Techniques – Criminals use obfuscation and wiping tools.
Data Integrity Issues – Improper handling can alter evidence.
Rapid Technological Changes – Tools need frequent updates to stay relevant.
Forensic tools are critical in digital investigations, helping experts extract and analyze evidence
while preserving data integrity. Investigators must choose tools based on case requirements, legal standards,
and technology constraints. A combination of disk imaging, memory analysis, mobile forensics, network
monitoring, and password recovery tools ensures a thorough and legally admissible forensic process.