Data Forensics
DSE3241
[Link] Joshi
Email Id: [Link]@[Link]
Department of Data Science and Engineering, SCSE
Manipal University Jaipur
[Link] Joshi (WS-50 (AB2,FB3)) DF 1 / 69
Course Outcome, Syllabus and Books
Table of Content
1 Course Outcome, Syllabus and Books
2 Module 1
[Link] Joshi (WS-50 (AB2,FB3)) DF 2 / 69
Course Outcome, Syllabus and Books
Course Outcome
CO1: List the core phases and lifecycle models of digital forensics
investigations.
CO2: Explain techniques for acquiring and analyzing data from a
variety of digital devices.
CO3: Demonstrate the use of forensic tools for imaging, data recovery
and analysis.
CO4: Examine procedures, chain of custody and legal considerations
across operating systems and networks to ensure evidence admissibility.
[Link] Joshi (WS-50 (AB2,FB3)) DF 3 / 69
Course Outcome, Syllabus and Books
Syllabus
Module 1 Introduction to Digital Forensics: Overview and
History of Digital Forensics, Types of Digital Forensics - Computer,
Network, Mobile, Database, Digital Evidence - Definition, Types, and
Characteristics, Digital Crime Investigation Lifecycle, Chain of
Custody and Evidence Handling. .
Module 2 Data Acquisition and Preservation: Forensic
Duplication - Imaging and Cloning, Write Mockers and Data Integrity,
Live vs. Static Acquisition, Bitstream Imaging Techniques, Data
Acquisition tools - FTK Imager, dd, EnCase.
[Link] Joshi (WS-50 (AB2,FB3)) DF 4 / 69
Course Outcome, Syllabus and Books
Syllabus Continued
Module 3 Forensic Analysis and Recovery: File Systems - FAT,
NTFS, EXT, Recovering Deleted, Hidden, and Encrypted Files,
Hashing and Checksums, Email and Browser Forensics, Steganography
and Anti-Forensic Techniques
Module 4 OS and Network Forensics: Windows and Linux
Forensics - Registry, Log Analysis, System Artifacts, Network Forensics
- Packet Analysis, Intrusion, Election, Analyzing Traffic using
Wireshark, Cloud Forensics Basics.
Module 5 Legal, Ethical, and Professional Issues: IT Act 2000
and Amendments relevant to Forensics, Legal Admissibility of Digital
Evidence, International Standards and Certifications (ISO, NIST),
Ethical Considerations in Forensic Investigations.
[Link] Joshi (WS-50 (AB2,FB3)) DF 5 / 69
Course Outcome, Syllabus and Books
Books
1. B. Nelson, A. Phillips, and C. Steuart, Guide to Computer Forensics
and Investigations, 6th Ed., Cengage Learninv, 2020.
2. L. Volonino, R. Anzaldua, and J. Godwin, Computer Forensics:
Principles and Practices, 1st Ed., Pearson Education, 2009.
3. C. Altheide and H. Carvey, Digital Forensics with Open Source
Tools, 1st Ed., Syngress Media, 2011.
4. E. Casey, Handbook of Digital Forensics and Investigation, 1st Ed”
Academic Press, 2009
[Link] Joshi (WS-50 (AB2,FB3)) DF 6 / 69
Module 1
Table of Content
1 Course Outcome, Syllabus and Books
2 Module 1
[Link] Joshi (WS-50 (AB2,FB3)) DF 7 / 69
Module 1
Module 1
Introduction to Digital Forensics: Overview and History of Digital
Forensics, Types of Digital Forensics - Computer, Network, Mobile,
Database, Digital Evidence - Definition, Types, and Characteristics,
Digital Crime Investigation Lifecycle, Chain of Custody and Evidence
Handling.
[Link] Joshi (WS-50 (AB2,FB3)) DF 8 / 69
Module 1
Introduction to Digital Forensics
Digital forensics, the art of recovering and analysing the contents found
on digital devices such as desktops, notebooks/netbooks, tablets,
smartphones, etc., was little-known a few years ago. However, with the
growing incidence of cyber crime, and the increased adoption of digital
devices, this branch of forensics has gained significant importance in
the recent past, augmenting what was conventionally limited to the
recovery and analysis of biological and chemical evidence during
criminal investigations.
[Link] Joshi (WS-50 (AB2,FB3)) DF 9 / 69
Module 1
Definition of Computer Forensics
Computer forensics is the practice of collecting, analysing and reporting
on digital data in a way that is legally admissible. It can be used in the
detection and prevention of crime and in any dispute where evidence is
stored digitally. It is the use of specialized techniques for recovery,
authentication and analysis of electronic data when a case involves
issues relating to reconstruction of computer usage, examination of
residual data, and authentication of data by technical analysis or
explanation of technical features of data and computer usage.
[Link] Joshi (WS-50 (AB2,FB3)) DF 10 / 69
Module 1
Cyber crime
Computer crime, or cybercrime, is any crime that involves a computer
and a network. The computer may have been used in the commission
of a crime, or it may be the target. [Link] Halder and Dr. K.
Jaishankar define Cybercrimes as: ”Offences that are committed
against individuals or groups of individuals with a criminal motive to
intentionally harm the reputation of the victim or cause physical or
mental harm, or loss, to the victim directly or indirectly, using modern
telecommunication networks such as Internet (Chat rooms, emails,
notice boards and groups) and mobile phones (SMS/MMS)”. Such
crimes may threaten a nation‘s security and financial health.
[Link] Joshi (WS-50 (AB2,FB3)) DF 11 / 69
Module 1
Evolution of Computer Forensics
It is difficult to pinpoint the first —computer forensic examination or
the beginning of the field for that matter6. But most experts agree
that the field of computer forensics began to evolve more than 30 years
ago. The field began in the United States, in large part, when law
enforcement and military investigators started seeing criminals get
technical.
[Link] Joshi (WS-50 (AB2,FB3)) DF 12 / 69
Module 1
Origins: The Dawn of Digital Evidence
The late 1970s marked the beginning of digital evidence as mainframe
and minicomputer systems became prevalent in business and
government. When the first computer-related crimes emerged,
investigators faced unprecedented challenges—how do you secure,
preserve, and analyze evidence that exists only as magnetic charges on
storage media?
The 1980s witnessed explosive growth in personal computing, bringing
computers into homes and small businesses. This democratization of
technology also democratized cybercrime. Law enforcement agencies
worldwide scrambled to develop capabilities to handle this new
evidence type, often learning through trial and error
[Link] Joshi (WS-50 (AB2,FB3)) DF 13 / 69
Module 1
Origins: The Dawn of Digital Evidence
Figure 1: History of Digital Evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 14 / 69
Module 1
The Birth of Computer Forensics (1980s-1990s)
The need for specialized expertise became undeniable as computer
crimes proliferated. The FBI’s formation of the Computer Analysis
and Response Team (CART) represented a watershed
moment—centralizing knowledge and creating a dedicated unit of
forensic specialists who could handle increasingly complex digital
investigations.
[Link] Joshi (WS-50 (AB2,FB3)) DF 15 / 69
Module 1
The Birth of Computer Forensics (1980s-1990s)
Figure 2: The Birth of Computer Forensics (1980s-1990s)
By the mid-1990s, commercial forensic software tools emerged, making
sophisticated analysis techniques available beyond government
agencies. This commercialization accelerated the field’s growth and
professionalization, establishing forensic protocols that would influence
practice for decades.
[Link] Joshi (WS-50 (AB2,FB3)) DF 16 / 69
Module 1
Where Digital Forensics Took Its First Steps
The 2000s brought much-needed structure to digital forensics.
Professional organizations emerged to establish standards,
certifications, and best practices that transformed digital forensics from
an ad-hoc specialty into a recognized profession with rigorous
methodologies.
Figure 3: Digital Forensics Initial Days
[Link] Joshi (WS-50 (AB2,FB3)) DF 17 / 69
Module 1
Where Digital Forensics Took Its First Steps
The establishment of professional standards transformed digital
forensics from an investigative art into a rigorous science, ensuring
evidence integrity and expert credibility in legal proceedings.
[Link] Joshi (WS-50 (AB2,FB3)) DF 18 / 69
Module 1
The Mobile and Cloud Era (Mid 2000s - 2010s)
Mobile Forensics Revolution : The smartphone revolution
fundamentally changed digital forensics. Suddenly, investigators
needed to extract evidence from devices containing text messages, GPS
data, photos, app data, and internet history—all from a device that fits
in a pocket.
[Link] Joshi (WS-50 (AB2,FB3)) DF 19 / 69
Module 1
The Mobile and Cloud Era (Mid 2000s - 2010s)
Figure 4: Mobile Era
[Link] Joshi (WS-50 (AB2,FB3)) DF 20 / 69
Module 1
The Mobile and Cloud Era (Mid 2000s - 2010s)
Cloud computing introduced paradigm-shifting challenges. Evidence
was no longer stored on a single machine but distributed across
multiple servers in various jurisdictions. Investigators had to navigate
virtualized environments, remote storage systems, and complex data
architectures.
[Link] Joshi (WS-50 (AB2,FB3)) DF 21 / 69
Module 1
The Mobile and Cloud Era (Mid 2000s - 2010s)
Figure 5: Cloud Era
[Link] Joshi (WS-50 (AB2,FB3)) DF 22 / 69
Module 1
Advanced Technologies and Big Data (2010s - Present)
Figure 6: Advanced Technologies
[Link] Joshi (WS-50 (AB2,FB3)) DF 23 / 69
Module 1
Key Milestones and Real-World Impact
Figure 7: Key Milestones and Real-World Impact
[Link] Joshi (WS-50 (AB2,FB3)) DF 24 / 69
Module 1
Timeline
Figure 8: Timeline
[Link] Joshi (WS-50 (AB2,FB3)) DF 25 / 69
Module 1
ROLE OF FORENSICS INVESTIGATOR
Confirms or dispels whether a resource/network is compromised.
Determine extent of damage due to intrusion.
Answer the questions: Who, What, When, Where, How and Why.
Gathering data in a forensically sound manner.
Handle and analyze evidence.
Prepare the report.
Present admissible evidence in court.
[Link] Joshi (WS-50 (AB2,FB3)) DF 26 / 69
Module 1
Why Study Data Forensics? Career Relevance and
Impact
Studying Data Forensics is essential in today’s technology-driven world
because organizations increasingly rely on digital systems for
operations, communication, and decision-making. As a result,
cybercrimes such as data breaches, financial fraud, identity theft,
insider attacks, and cyber espionage are growing both in frequency and
sophistication. Data forensics equips students with the ability to
investigate such incidents methodically and responsibly.
[Link] Joshi (WS-50 (AB2,FB3)) DF 27 / 69
Module 1
Why Study Data Forensics? Career Relevance and
Impact
From a career perspective, this subject opens pathways in multiple
domains including cyber forensics, incident response, cybersecurity
operations, law enforcement agencies, corporate compliance teams,
digital risk management, and legal consulting. Roles such as Digital
Forensic Analyst, Incident Response Specialist, Cybercrime
Investigator, Security Auditor, and Compliance Officer require a strong
understanding of forensic processes, evidence handling, and legal
admissibility—skills that are directly addressed in this course.
[Link] Joshi (WS-50 (AB2,FB3)) DF 28 / 69
Module 1
Type of Cyber Crime
Figure 9: Type of Cyber Crime
[Link] Joshi (WS-50 (AB2,FB3)) DF 29 / 69
Module 1
Example of Cyber Crime
Figure 10: Example of Cyber Crime
[Link] Joshi (WS-50 (AB2,FB3)) DF 30 / 69
Module 1
Introduction to Digital Evidence
Figure 11: Digital Evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 31 / 69
Module 1
Digital Evidence
Digital evidence is any information of probative value that is stored or
transmitted in digital form and can be used in legal proceedings.
Intangible and tool-dependent
Easily altered or destroyed
Found in computers, mobiles, networks, and cloud systems
Example: An email containing threats used as evidence in a
cybercrime case.
[Link] Joshi (WS-50 (AB2,FB3)) DF 32 / 69
Module 1
Type of Digital Evidence
Figure 12: Type of Digital Evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 33 / 69
Module 1
Types of Digital Evidence
Digital evidence can be categorized based on persistence and visibility.
Volatile Data: RAM contents, active connections
Non-Volatile Data: Files, databases, backups
Active Data: Visible user files
Latent Data: Deleted or hidden data
Example: RAM data lost immediately after system shutdown.
[Link] Joshi (WS-50 (AB2,FB3)) DF 34 / 69
Module 1
Role of Digital Evidence
Figure 13: Role of Digital Evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 35 / 69
Module 1
Source of Digital Evidence
Figure 14: Source of Digital Evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 36 / 69
Module 1
Type of Digital Forensics
Digital forensics is not a single, uniform activity; rather, it is a
collection of specialized sub-disciplines, each focusing on different
sources of digital data. The classification of digital forensics depends
on the type of device, data storage mechanism, and communication
medium involved in an investigation. As digital ecosystems grow more
complex, forensic investigations increasingly require expertise across
multiple forensic domains.
Example:
A corporate data breach may require computer forensics (employee
laptop), network forensics (data exfiltration), and database forensics
(altered records).
[Link] Joshi (WS-50 (AB2,FB3)) DF 37 / 69
Module 1
Type of Digital Forensics
Figure 15: Digital Forensics
[Link] Joshi (WS-50 (AB2,FB3)) DF 38 / 69
Module 1
Computer Forensics
It Focuses on digital evidence stored in computers and storage media
Figure 16: Computer Forensics
It Examines:
Hard disks, SSDs, USB drives
File systems (FAT, NTFS, EXT)
Operating system artifacts and user activity
[Link] Joshi (WS-50 (AB2,FB3)) DF 39 / 69
Module 1
Computer Forensics
The Investigators analyze
Deleted files
System logs
Installed applications
Browser history
Example Investigating an employee accused of leaking confidential
files using a company laptop
[Link] Joshi (WS-50 (AB2,FB3)) DF 40 / 69
Module 1
Computer Forensics
Computer forensics plays a critical role in investigations involving
intellectual property theft, unauthorized system access, insider misuse,
and malware infections. A major challenge in computer forensics is
handling large volumes of data while ensuring that evidence integrity is
preserved. Investigators must follow strict procedures, such as working
only on forensic images rather than original devices, to maintain the
legal admissibility of the evidence.
[Link] Joshi (WS-50 (AB2,FB3)) DF 41 / 69
Module 1
Computer Forensics: Real-World Story
Scenario: Insider Data Theft
[Link] Joshi (WS-50 (AB2,FB3)) DF 42 / 69
Module 1
Computer Forensics: Real-World Story
Scenario: Insider Data Theft
An employee was suspected of leaking confidential company data
before resigning. The employee claimed no files were copied.
[Link] Joshi (WS-50 (AB2,FB3)) DF 42 / 69
Module 1
Computer Forensics: Real-World Story
Scenario: Insider Data Theft
An employee was suspected of leaking confidential company data
before resigning. The employee claimed no files were copied.
Computer forensic analysis revealed:
Deleted confidential files
USB device connection history
File access timestamps
[Link] Joshi (WS-50 (AB2,FB3)) DF 42 / 69
Module 1
Computer Forensics: Real-World Story
Scenario: Insider Data Theft
An employee was suspected of leaking confidential company data
before resigning. The employee claimed no files were copied.
Computer forensic analysis revealed:
Deleted confidential files
USB device connection history
File access timestamps
Key Learning: Deleted files and system logs can reconstruct user
actions and prove misconduct.
[Link] Joshi (WS-50 (AB2,FB3)) DF 42 / 69
Module 1
Network Forensics
Figure 17: Network Forensics
Network Forensics Deals with:-
Packet captures
Firewall and IDS logs
Network sessions
Often involves volatile evidence, which may be lost quickly
Used to trace:Cyberattacks,Unauthorized access,Data exfiltration
[Link] Joshi (WS-50 (AB2,FB3)) DF 43 / 69
Module 1
Network Forensics
Network forensic investigations are commonly used in cases involving
denial-of-service attacks, unauthorized network intrusions, data
exfiltration, and insider threats. Investigators analyze packet captures,
firewall logs, intrusion detection system alerts, and routing information
to trace the source and impact of malicious activities. Network
forensics often works in close coordination with computer and mobile
forensics to provide a comprehensive understanding of an incident.
Example: Analyzing Wireshark packet captures after a DDoS attack
on a university server.
[Link] Joshi (WS-50 (AB2,FB3)) DF 44 / 69
Module 1
Network Forensics: Real-World Story
Scenario: University Website Under DDoS Attack
[Link] Joshi (WS-50 (AB2,FB3)) DF 45 / 69
Module 1
Network Forensics: Real-World Story
Scenario: University Website Under DDoS Attack
The university examination portal suddenly became unavailable during
online exams.
[Link] Joshi (WS-50 (AB2,FB3)) DF 45 / 69
Module 1
Network Forensics: Real-World Story
Scenario: University Website Under DDoS Attack
The university examination portal suddenly became unavailable during
online exams.
Network forensic investigation involved:
Packet capture analysis
Firewall and IDS logs
Traffic pattern examination
[Link] Joshi (WS-50 (AB2,FB3)) DF 45 / 69
Module 1
Network Forensics: Real-World Story
Scenario: University Website Under DDoS Attack
The university examination portal suddenly became unavailable during
online exams.
Network forensic investigation involved:
Packet capture analysis
Firewall and IDS logs
Traffic pattern examination
Key Learning: Network forensics identifies malicious activity through
traffic analysis, even without file access.
[Link] Joshi (WS-50 (AB2,FB3)) DF 45 / 69
Module 1
Database Forensics
It Investigates data stored in database management systems:
Transaction logs
Audit trails
User access records
used to detect: Data manipulation, Fraud, Unauthorized Access
Example:
Analyzing bank database logs to identify fraudulent transaction entries.
[Link] Joshi (WS-50 (AB2,FB3)) DF 46 / 69
Module 1
Database Forensics: Real-World Story
Scenario: Banking Fraud Detection
[Link] Joshi (WS-50 (AB2,FB3)) DF 47 / 69
Module 1
Database Forensics: Real-World Story
Scenario: Banking Fraud Detection
Small discrepancies appeared across thousands of bank accounts.
[Link] Joshi (WS-50 (AB2,FB3)) DF 47 / 69
Module 1
Database Forensics: Real-World Story
Scenario: Banking Fraud Detection
Small discrepancies appeared across thousands of bank accounts.
Database forensic analysis found:
Manipulated transaction logs
Unauthorized database queries
Audit trail inconsistencies
[Link] Joshi (WS-50 (AB2,FB3)) DF 47 / 69
Module 1
Database Forensics: Real-World Story
Scenario: Banking Fraud Detection
Small discrepancies appeared across thousands of bank accounts.
Database forensic analysis found:
Manipulated transaction logs
Unauthorized database queries
Audit trail inconsistencies
Key Learning: Database logs can expose fraud even when no visible
data is altered.
[Link] Joshi (WS-50 (AB2,FB3)) DF 47 / 69
Module 1
Mobile Forensics
Figure 18: Mobile Forensics
[Link] Joshi (WS-50 (AB2,FB3)) DF 48 / 69
Module 1
Mobile Forensics
It focuses on smartphones and tablets:
Call logs
SMS, WhatsApp, emails
Photos, videos
GPS location data
Challenges include:Encryption,OS restrictions,Frequent software
updates
Example:
Recovering deleted WhatsApp messages from a suspect’s mobile phone.
[Link] Joshi (WS-50 (AB2,FB3)) DF 49 / 69
Module 1
Mobile Forensics: Real-World Story
Scenario: Hit-and-Run Investigation
[Link] Joshi (WS-50 (AB2,FB3)) DF 50 / 69
Module 1
Mobile Forensics: Real-World Story
Scenario: Hit-and-Run Investigation
A suspect denied being present at the accident scene.
[Link] Joshi (WS-50 (AB2,FB3)) DF 50 / 69
Module 1
Mobile Forensics: Real-World Story
Scenario: Hit-and-Run Investigation
A suspect denied being present at the accident scene.
Mobile forensic analysis revealed:
GPS location history
Deleted messages
App usage timestamps
[Link] Joshi (WS-50 (AB2,FB3)) DF 50 / 69
Module 1
Mobile Forensics: Real-World Story
Scenario: Hit-and-Run Investigation
A suspect denied being present at the accident scene.
Mobile forensic analysis revealed:
GPS location history
Deleted messages
App usage timestamps
Key Learning: Mobile devices silently record location and activity
that can contradict verbal claims.
[Link] Joshi (WS-50 (AB2,FB3)) DF 50 / 69
Module 1
Digital Crime Investigation Lifecycle
The Digital Crime Investigation Lifecycle is a structured and
systematic framework used to handle digital evidence from the moment
a crime is suspected until findings are presented in a court of law.
[Link] Joshi (WS-50 (AB2,FB3)) DF 51 / 69
Module 1
Digital Crime Investigation Lifecycle
The Digital Crime Investigation Lifecycle is a structured and
systematic framework used to handle digital evidence from the moment
a crime is suspected until findings are presented in a court of law.
It ensures that:
Evidence integrity is preserved
Investigation steps are repeatable
Results are legally defensible
[Link] Joshi (WS-50 (AB2,FB3)) DF 51 / 69
Module 1
Digital Crime Investigation Lifecycle
The Digital Crime Investigation Lifecycle is a structured and
systematic framework used to handle digital evidence from the moment
a crime is suspected until findings are presented in a court of law.
It ensures that:
Evidence integrity is preserved
Investigation steps are repeatable
Results are legally defensible
This lifecycle prevents ad-hoc investigations that may compromise
evidence or violate legal procedures.
[Link] Joshi (WS-50 (AB2,FB3)) DF 51 / 69
Module 1
Why is a Lifecycle Necessary?
Digital evidence is fundamentally different from physical evidence.
[Link] Joshi (WS-50 (AB2,FB3)) DF 52 / 69
Module 1
Why is a Lifecycle Necessary?
Digital evidence is fundamentally different from physical evidence.
It is fragile and easily altered
It can be modified unintentionally
It is invisible without forensic tools
[Link] Joshi (WS-50 (AB2,FB3)) DF 52 / 69
Module 1
Why is a Lifecycle Necessary?
Digital evidence is fundamentally different from physical evidence.
It is fragile and easily altered
It can be modified unintentionally
It is invisible without forensic tools
Without a defined lifecycle:
Evidence may be contaminated
Investigation results may not be reproducible
Courts may reject the evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 52 / 69
Module 1
Digital Crime Investigation Lifecycle
[Link] Joshi (WS-50 (AB2,FB3)) DF 53 / 69
Module 1
Digital Crime Investigation Lifecycle
Major Phases: Identification → Preservation → Acquisition →
Examination → Analysis → Documentation → Presentation
[Link] Joshi (WS-50 (AB2,FB3)) DF 53 / 69
Module 1
Identification Phase
Identification involves recognizing potential sources of digital evidence
related to an incident.
[Link] Joshi (WS-50 (AB2,FB3)) DF 54 / 69
Module 1
Identification Phase
Identification involves recognizing potential sources of digital evidence
related to an incident.
Examples include:
Computers and laptops
Mobile phones
External storage devices
Network logs and cloud accounts
[Link] Joshi (WS-50 (AB2,FB3)) DF 54 / 69
Module 1
Identification Phase
Identification involves recognizing potential sources of digital evidence
related to an incident.
Examples include:
Computers and laptops
Mobile phones
External storage devices
Network logs and cloud accounts
Key Point: Identification is deciding what may contain evidence, not
collecting it.
[Link] Joshi (WS-50 (AB2,FB3)) DF 54 / 69
Module 1
Preservation Phase
Preservation ensures that identified evidence is protected from
alteration or destruction.
[Link] Joshi (WS-50 (AB2,FB3)) DF 55 / 69
Module 1
Preservation Phase
Preservation ensures that identified evidence is protected from
alteration or destruction.
Common preservation techniques:
Isolating devices from networks
Using write blockers
Preventing unauthorized access
[Link] Joshi (WS-50 (AB2,FB3)) DF 55 / 69
Module 1
Preservation Phase
Preservation ensures that identified evidence is protected from
alteration or destruction.
Common preservation techniques:
Isolating devices from networks
Using write blockers
Preventing unauthorized access
If evidence is altered at this stage, the entire investigation may be
compromised.
[Link] Joshi (WS-50 (AB2,FB3)) DF 55 / 69
Module 1
Acquisition Phase
Acquisition involves creating a forensic copy of the digital evidence.
[Link] Joshi (WS-50 (AB2,FB3)) DF 56 / 69
Module 1
Acquisition Phase
Acquisition involves creating a forensic copy of the digital evidence.
Disk imaging
Memory acquisition
Network traffic capture
[Link] Joshi (WS-50 (AB2,FB3)) DF 56 / 69
Module 1
Acquisition Phase
Acquisition involves creating a forensic copy of the digital evidence.
Disk imaging
Memory acquisition
Network traffic capture
Golden Rule: Never perform analysis on original evidence.
[Link] Joshi (WS-50 (AB2,FB3)) DF 56 / 69
Module 1
Examination vs Analysis
Examination
Focuses on extracting relevant data from evidence such as files, logs,
and metadata.
[Link] Joshi (WS-50 (AB2,FB3)) DF 57 / 69
Module 1
Examination vs Analysis
Examination
Focuses on extracting relevant data from evidence such as files, logs,
and metadata.
Analysis
Involves interpreting extracted data to reconstruct events and
determine intent.
[Link] Joshi (WS-50 (AB2,FB3)) DF 57 / 69
Module 1
Examination vs Analysis
Examination
Focuses on extracting relevant data from evidence such as files, logs,
and metadata.
Analysis
Involves interpreting extracted data to reconstruct events and
determine intent.
Common Mistake: Students often confuse examination with
analysis.
[Link] Joshi (WS-50 (AB2,FB3)) DF 57 / 69
Module 1
Documentation and Presentation
Documentation records every action taken during the investigation.
[Link] Joshi (WS-50 (AB2,FB3)) DF 58 / 69
Module 1
Documentation and Presentation
Documentation records every action taken during the investigation.
Includes:
Tools used
Procedures followed
Observations made
[Link] Joshi (WS-50 (AB2,FB3)) DF 58 / 69
Module 1
Documentation and Presentation
Documentation records every action taken during the investigation.
Includes:
Tools used
Procedures followed
Observations made
Presentation communicates findings in a clear, legally acceptable
manner to courts or authorities.
[Link] Joshi (WS-50 (AB2,FB3)) DF 58 / 69
Module 1
Real-World Story: Following the Investigation Lifecycle
Scenario: Corporate Data Breach Investigation
[Link] Joshi (WS-50 (AB2,FB3)) DF 59 / 69
Module 1
Real-World Story: Following the Investigation Lifecycle
Scenario: Corporate Data Breach Investigation
A multinational company detected unauthorized access to its internal
servers. Sensitive design documents were leaked online.
[Link] Joshi (WS-50 (AB2,FB3)) DF 59 / 69
Module 1
Real-World Story: Following the Investigation Lifecycle
Scenario: Corporate Data Breach Investigation
A multinational company detected unauthorized access to its internal
servers. Sensitive design documents were leaked online.
Investigators followed the digital crime investigation lifecycle:
Identification: Suspected employee laptops, server logs, and
email accounts
Preservation: Isolated systems and restricted access
Acquisition: Created forensic images of hard drives and log
servers
Examination & Analysis: Correlated file access logs and email
timestamps
Documentation & Presentation: Submitted findings to legal
authorities
[Link] Joshi (WS-50 (AB2,FB3)) DF 59 / 69
Module 1
Real-World Story: Following the Investigation Lifecycle
Scenario: Corporate Data Breach Investigation
A multinational company detected unauthorized access to its internal
servers. Sensitive design documents were leaked online.
Investigators followed the digital crime investigation lifecycle:
Identification: Suspected employee laptops, server logs, and
email accounts
Preservation: Isolated systems and restricted access
Acquisition: Created forensic images of hard drives and log
servers
Examination & Analysis: Correlated file access logs and email
timestamps
Documentation & Presentation: Submitted findings to legal
authorities
Key Learning: Skipping any lifecycle phase could have compromised
the investigation.
[Link] Joshi (WS-50 (AB2,FB3)) DF 59 / 69
Module 1
Real-World Story: When Procedure Is Ignored
Scenario: Evidence Contamination
[Link] Joshi (WS-50 (AB2,FB3)) DF 60 / 69
Module 1
Real-World Story: When Procedure Is Ignored
Scenario: Evidence Contamination
An investigator powered on a suspect’s computer to “check what was
inside” before forensic acquisition.
[Link] Joshi (WS-50 (AB2,FB3)) DF 60 / 69
Module 1
Real-World Story: When Procedure Is Ignored
Scenario: Evidence Contamination
An investigator powered on a suspect’s computer to “check what was
inside” before forensic acquisition.
This action:
Modified system timestamps
Altered running processes
Contaminated volatile evidence
[Link] Joshi (WS-50 (AB2,FB3)) DF 60 / 69
Module 1
Real-World Story: When Procedure Is Ignored
Scenario: Evidence Contamination
An investigator powered on a suspect’s computer to “check what was
inside” before forensic acquisition.
This action:
Modified system timestamps
Altered running processes
Contaminated volatile evidence
Outcome: Defense questioned evidence integrity and the court
rejected key findings.
[Link] Joshi (WS-50 (AB2,FB3)) DF 60 / 69
Module 1
Real-World Story: When Procedure Is Ignored
Scenario: Evidence Contamination
An investigator powered on a suspect’s computer to “check what was
inside” before forensic acquisition.
This action:
Modified system timestamps
Altered running processes
Contaminated volatile evidence
Outcome: Defense questioned evidence integrity and the court
rejected key findings.
Lesson: Digital forensics is procedural before it is technical.
[Link] Joshi (WS-50 (AB2,FB3)) DF 60 / 69
Module 1
Chain of Custody
Chain of Custody is a chronological record that tracks the handling of
digital evidence from collection to court presentation.
[Link] Joshi (WS-50 (AB2,FB3)) DF 61 / 69
Module 1
Chain of Custody
Chain of Custody is a chronological record that tracks the handling of
digital evidence from collection to court presentation.
It answers:
Who collected the evidence?
When and how was it handled?
Who accessed it later and why?
[Link] Joshi (WS-50 (AB2,FB3)) DF 61 / 69
Module 1
Chain of Custody Diagram
[Link] Joshi (WS-50 (AB2,FB3)) DF 62 / 69
Module 1
Chain of Custody Diagram
Maintaining an unbroken chain of custody is essential for evidence
admissibility.
[Link] Joshi (WS-50 (AB2,FB3)) DF 62 / 69
Module 1
Why Chain of Custody is Important
Ensures evidence integrity
Prevents tampering allegations
Establishes legal credibility
[Link] Joshi (WS-50 (AB2,FB3)) DF 63 / 69
Module 1
Why Chain of Custody is Important
Ensures evidence integrity
Prevents tampering allegations
Establishes legal credibility
Key Teaching Line: Even perfect forensic analysis can fail without
proper documentation.
[Link] Joshi (WS-50 (AB2,FB3)) DF 63 / 69
Module 1
Evidence Handling Best Practices
Never work on original evidence
Use write blockers during acquisition
Label and seal evidence properly
Store evidence securely
Maintain access logs
[Link] Joshi (WS-50 (AB2,FB3)) DF 64 / 69
Module 1
Evidence Handling Best Practices
Never work on original evidence
Use write blockers during acquisition
Label and seal evidence properly
Store evidence securely
Maintain access logs
Proper handling ensures evidence remains reliable and admissible.
[Link] Joshi (WS-50 (AB2,FB3)) DF 64 / 69
Module 1
Real-World Lesson
In a cybercrime case, strong technical evidence was rejected in court
due to incomplete chain of custody records.
[Link] Joshi (WS-50 (AB2,FB3)) DF 65 / 69
Module 1
Real-World Lesson
In a cybercrime case, strong technical evidence was rejected in court
due to incomplete chain of custody records.
Lesson: Procedural errors can override technical findings.
[Link] Joshi (WS-50 (AB2,FB3)) DF 65 / 69
Module 1
Summary
Digital investigations must follow a defined lifecycle
Each phase protects evidence integrity
Chain of custody ensures legal admissibility
Evidence handling is as important as analysis
[Link] Joshi (WS-50 (AB2,FB3)) DF 66 / 69
Module 1
Real-World Story: Chain of Custody Failure
Scenario: Laptop Seized but Not Logged
[Link] Joshi (WS-50 (AB2,FB3)) DF 67 / 69
Module 1
Real-World Story: Chain of Custody Failure
Scenario: Laptop Seized but Not Logged
A suspect’s laptop was seized during a cybercrime investigation.
However, access logs during storage were not maintained.
[Link] Joshi (WS-50 (AB2,FB3)) DF 67 / 69
Module 1
Real-World Story: Chain of Custody Failure
Scenario: Laptop Seized but Not Logged
A suspect’s laptop was seized during a cybercrime investigation.
However, access logs during storage were not maintained.
During trial:
Defense questioned who accessed the laptop
No documentation proved evidence integrity
[Link] Joshi (WS-50 (AB2,FB3)) DF 67 / 69
Module 1
Real-World Story: Chain of Custody Failure
Scenario: Laptop Seized but Not Logged
A suspect’s laptop was seized during a cybercrime investigation.
However, access logs during storage were not maintained.
During trial:
Defense questioned who accessed the laptop
No documentation proved evidence integrity
Outcome: Digital evidence was declared inadmissible.
[Link] Joshi (WS-50 (AB2,FB3)) DF 67 / 69
Module 1
Real-World Story: Chain of Custody Failure
Scenario: Laptop Seized but Not Logged
A suspect’s laptop was seized during a cybercrime investigation.
However, access logs during storage were not maintained.
During trial:
Defense questioned who accessed the laptop
No documentation proved evidence integrity
Outcome: Digital evidence was declared inadmissible.
Key Learning: A broken chain of custody can free a guilty person.
[Link] Joshi (WS-50 (AB2,FB3)) DF 67 / 69
Module 1
Real-World Story: Evidence Handling Done Right
Scenario: Successful Cybercrime Prosecution
[Link] Joshi (WS-50 (AB2,FB3)) DF 68 / 69
Module 1
Real-World Story: Evidence Handling Done Right
Scenario: Successful Cybercrime Prosecution
Investigators used write blockers, labeled devices, logged every transfer,
and analyzed only forensic images.
[Link] Joshi (WS-50 (AB2,FB3)) DF 68 / 69
Module 1
Real-World Story: Evidence Handling Done Right
Scenario: Successful Cybercrime Prosecution
Investigators used write blockers, labeled devices, logged every transfer,
and analyzed only forensic images.
Chain of custody records showed:
Who handled the evidence
When and why access occurred
Secure storage conditions
[Link] Joshi (WS-50 (AB2,FB3)) DF 68 / 69
Module 1
Real-World Story: Evidence Handling Done Right
Scenario: Successful Cybercrime Prosecution
Investigators used write blockers, labeled devices, logged every transfer,
and analyzed only forensic images.
Chain of custody records showed:
Who handled the evidence
When and why access occurred
Secure storage conditions
Outcome: Evidence was accepted in court and the suspect was
convicted.
[Link] Joshi (WS-50 (AB2,FB3)) DF 68 / 69
Module 1
Real-World Story: Evidence Handling Done Right
Scenario: Successful Cybercrime Prosecution
Investigators used write blockers, labeled devices, logged every transfer,
and analyzed only forensic images.
Chain of custody records showed:
Who handled the evidence
When and why access occurred
Secure storage conditions
Outcome: Evidence was accepted in court and the suspect was
convicted.
Lesson: Strong procedures strengthen technical findings.
[Link] Joshi (WS-50 (AB2,FB3)) DF 68 / 69
Module 1
Class Reflection
Think and Answer:
[Link] Joshi (WS-50 (AB2,FB3)) DF 69 / 69
Module 1
Class Reflection
Think and Answer:
Which is more dangerous in digital forensics?
Weak technical skills
Weak procedural discipline
[Link] Joshi (WS-50 (AB2,FB3)) DF 69 / 69
Module 1
Class Reflection
Think and Answer:
Which is more dangerous in digital forensics?
Weak technical skills
Weak procedural discipline
Expected Discussion: Procedural mistakes can invalidate even
perfect technical analysis.
[Link] Joshi (WS-50 (AB2,FB3)) DF 69 / 69