Digital Evidence Flashcards
What are sources of digital evidence that could be found at a crime scene?
Phones, computers, tablets, laptops, routers, drones, SD cards, USB sticks
What should you always do before recovering electronics at a crime scene, and why?
Seek expert advice to prevent alteration, loss or encryption of data
How can you prevent remote wiping and data changes?
Place in faraday bag and keep powered on, get to digital department ASAP
What do you do when trying to recover a computer/PC that is switched OFF?
- Disconnect from mains
- Package in close-fitting, rigid box
- Document all actions
What do you do when trying to recover a computer/PC that is switched ON?
Consider if investigators need to know what the computer is doing right now and if it will encrypt itself when removed from power. if the answer is no to both:
- Disconnect from mains
- Package in close-fitting, rigid box
- Record all actions and the time you disconnected it from power
If unsure: seek expert advice, leave device alone
What do you when trying to recover a running laptop?
- Remove battery at the back
- Remove powder cable, record time
- Package in close-fitting, rigid box
If no external battery: - Don’t open lid
- Place in faraday bag and get to digital ASAP
What do you do when trying to recover a phone/tablet?
- Place in faraday bag and keep powered on, get to digital ASAP
How to recover a router?
- Disconnect from powder
- Package in close fitting, rigid box
Can you swab devices?
Yes if you don’t touch buttons and the device is off
Can you fingerprint devices?
No as aluminium powder can damage them, but you can photograph and gel lift screens