9 - 4: Forensic Techniques Flashcards
Four main types of investigations
1) Operational/Administrative 2) Criminal Investigations 3) Civil Investigations 4) Regulatory
Operational investigations
Investigate issues in technology services/performance
Criminal investigations
Intended to investigate criminal activity
Civil investigations
Non-criminal legal offenses involving a dispute between two parties
Regulatory investigations
Carried out by government or other regulatory bodies
Interrogations
When an interview subject withdraws consent, is only for law enforcement
Types of evidence
1) Real evidence 2) Documentary evidence 3) Testimonial evidence
Real evidence
Tangible items
Documentary evidence
Information in written or digital form, including logs
Documentary evidence rules
1) must be authenticated, attested to its legitimacy 2) best evidence 3) parole evidence
Best evidence rule
Original documents are always superior
Parole evidence rule
The court assumes a written agreement between to parties to be the only agreement and no verbal agreement is legally binding
Testimonial evidence
A statement written or said under oath
Direct evidence
Witness recounts what they observed
Testimonial evidence types
1) Direct evidence 2) Expert Opinion
Expert opinion
The court recognizes an authority in a field to interpret information
Hearsay
Evidence based on what one person told another, not admissible
Goal of digital forensics
Collect, preserve, analyze, and interpret digital evidence
Volatility
The permanence or likelihood to change a piece of evidence has
Order of volatility
1) Network traffic 2) Memory Contents 3) System and process data 4) Files 5) Logs 6) Archived Records
Time offsets
Difference in timestamps between data evidence
First rule of investigation
NEVER alter data captured
Forensic file reading
1) Create an image of the physical media 2) use a write-blocker/forensic disk controller to prevent any data editing or creation