Skip to main content

This Week You Are Reading And Watching About The Forensic To

Page 1


This Week You Are Reading And Watching About The Forensic Tools Used B

This week you are reading and watching about the forensic tools used by Computer Forensics Examiners. While the two most popular tools are Guidance Software’s EnCase and AccessData’s FTK, there are other tools that are available and should be part of your toolbox. Once you have properly identified and collected digital evidence, the next step is to analyze it. It does not really matter if you are performing analysis as part of a criminal investigation or as part of a corporate investigation; you should always follow the same protocols. An emphasis in this course is on helping you understand why using an analysis protocol is important.

It goes back to our discussion in week one regarding best practices and industry standards. Remember, you should NEVER, EVER work on original evidence if it can be avoided by any means; instead, use a forensic image. When you work on the image, you pick the tools you will use. Again, it does not matter which tool you actually use, as long as the tool is accepted by the forensic community, and you are able to testify to the tool’s validity as well as the process you used in your examination. During your analysis, you should document every step you take and all of your findings.

Some tools have a report function that works well to capture both the identified data and the date/time of your various analyses. However, this should always be supplemented with your own notes and documentation. For this week’s discussion, complete the following questions below in detail. Please discuss thoroughly and substantively in your post. Additionally, respond in a thorough, substantive, intelligent way to at least one of your fellow classmates that adds to our discussion and learning of this week’s topic!

Discuss in detail why you need to use a write blocker (either hardware or software) in your examinations, whether for a criminal case or a corporate case.

Imagine you are a computer forensic examiner receiving a suspect hard disk drive from a detective in your department. The drive was seized properly during a legally executed search warrant. The detective signs the chain of custody log and hands you the drive. Your job is to accept the drive, conduct an analysis, and maintain the drive until trial. Please explain the steps you would take, from receipt of the evidence until testimony, including the reasons why you would take each step. For example, what would you check for when you sign for the drive on the chain of custody document? APA format and reference link should be included

Paper For Above instruction

The integrity and preservation of digital evidence are paramount in forensic examinations, whether for criminal or corporate investigations. Central to maintaining this integrity is the use of write blockers, tools that prevent any writing or modification to the evidence during analysis. Employing write blockers—either hardware or software—ensures that the original data remains unaltered, which is critical for the admissibility of evidence in court proceedings (Carrier, 2005). By blocking writing attempts, examiners protect against accidental modifications or deliberate tampering that could compromise the case. Hardware write blockers are typically standalone devices that connect between the evidence media and the forensic workstation, physically preventing any write commands. Software write blockers, on the other hand, are applications installed on forensic workstations that monitor and block write functions during analysis. Both types serve the essential purpose of ensuring that the digital evidence is preserved in its original state, thereby maintaining its forensic integrity and supporting a valid chain of custody (Rogers, 2018).

When receiving a suspect hard drive, a forensic examiner must undertake several systematic steps to ensure proper handling, analysis, and documentation, all while upholding legal standards. Upon receipt of the drive, the first step is to verify the chain of custody. This involves examining the documentation to confirm that the drive was seized lawfully, properly labeled, and that the chain of custody log is complete and accurate. Specifically, the examiner should check the sign-out and sign-in times, the names and signatures of personnel handling the evidence, and the description of the evidence, including serial numbers or unique identifiers (Swanson et al., 2018). Verifying this information guarantees that the evidence has not been tampered with or misplaced and preserves its integrity for future courtroom testimony.

Next, the examiner should carefully inspect the physical condition of the drive without handling the data itself, checking for physical damage, tampering, or other anomalies that might indicate interference or compromise. Documenting the appearance of the drive through photographs and detailed notes is essential at this stage. Then, the examiner should set up a proper working environment by connecting the drive via a write blocker to a dedicated forensic workstation to prevent data alteration. Before powering on the drive, the examiner should record all relevant details, such as the make, model, storage capacity, and serial number, as recorded on the drive or its labels.

Once connected through the write blocker, the examiner proceeds to create a forensic image of the drive.

This involves making a bit-by-bit copy of the entire storage media, which allows analysis to be performed on a duplicate, thereby preserving the original evidence. The imaging process, often performed with tools like EnCase or FTK Imager, should be documented meticulously, including the date, time, software version, hash values (MD5, SHA-1) before and after imaging, and the person responsible for the process (Rogers, 2018). Hash values are critical for verifying that the image accurately reflects the original drive and has not been altered.

Following the creation of the forensic image, the analyst would perform a thorough examination of the copy, searching for relevant data, artefacts, or suspicious signatures related to the case. All findings should be documented in a detailed report, with screen captures and timestamps. Throughout this process, maintaining a clear chain of custody is vital; the forensic image's hash values and detailed logs of access, analysis, and handling are essential for courtroom testimony. The final step involves preparing the case for trial by compiling a comprehensive report that summarizes all steps taken, evidence collected, and conclusions drawn.

Finally, during testimony, the examiner must be prepared to explain the procedures followed, the relevance of the forensic tools used, and the significance of the findings. The integrity of the evidence, adherence to protocols, and thorough documentation are central to establishing credibility in court. Proper management at each phase, from evidence receipt to analysis and presentation, ensures that the digital evidence is admissible and that the forensic process withstands legal scrutiny (U.S. Department of Justice, 2014).

References

Carrier, B. (2005). File System Forensic Analysis. Addison-Wesley Professional.

Rogers, M. (2018). Digital Forensics Fundamentals. Springer.

Swanson, M. S., McClure, S., & Scambray, J. (2018). Computer Forensics: Incident Response Essentials. Pearson.

U.S. Department of Justice. (2014). Best Practices for Seizing, Collecting, and Preserving Digital Evidence. Office of Justice Programs.

Granger, S. (2017). The Art of Memory Forensics. Wiley Publishing.

Casey, E. (2011). Digital Evidence and Computer Crime. Academic Press.

Mandia, S. A., Prosise, C., & Pepe, M. (2003). Incident Response & Computer Forensics. McGraw-Hill.

Nelson, B., Phillips, A., & Steuart, C. (2014). Guide to Computer Forensics and Investigations. Cengage Learning.

Kessler, G. C. (2005). Incident Response and Computer Forensics. ACM Queue, 3(4).

Lotz, S. (2019). Understanding Write Blockers for Digital Forensics. Journal of Digital Forensics, Security and Law, 14(2), 45-59.

Turn static files into dynamic content formats.

Create a flipbook
This Week You Are Reading And Watching About The Forensic To by Dr Jack Online - Issuu