Digital Forensics Flashcards
is a branch of Forensic Science that focuses on identifying, acquiring, processing, analyzing, and reporting on data stored electronically
Digital forensics
is the process of storing, analyzing, retrieving, and preserving electronic data that may be useful in an investigation. It includes data from hard drives in computers, mobile phones, smart appliances, vehicle navigation systems, electronic door locks, and other digital devices (Simplilearn, 2023)
Digital forensics
a component of almost all criminal activities and digital forensics support is crucial for law enforcement investigations
Electronic evidence/ Digital evidence
Steps of Digital Forensics
- Identification
- Preservation
- Analysis
- Documentation
- Presentation
this is the initial stage in which the individuals or devices to be analyzed are identified as likely sources of significant evidence
Identification
It focuses on safeguarding relevant electronically stored information (ESI) by capturing and preserving the crime scene, documenting relevant information such as visual images, and how it was obtained
Preservation
It is a methodical examination of the evidence of the information gathered. This examination produces data objects, including system and user-generated files, and seeks specific answers and points of departure for conclusions
Analysis
These are tried-and-true procedures for documenting the analysis’s conclusions, and they must allow other competent examiners to read through and duplicate the results
Documentation
The collection of digital information, which may entail removing electronic devices from the crime/incident scene and copying or printing the device(s), is critical to the investigation.
Presentation
It analyzes digital evidence obtained from laptops, computers, and storage media to support ongoing investigations and legal proceedings.
Computer Forensics
It entails obtaining evidence from small electronic devices such as personal digital assistants, mobile phones, tablets, sim cards, and gaming consoles.
Mobile Device Forensics
Network or cyber forensics depends on the data obtained from monitoring and analyzing cyber network activities such as attacks, breaches, or system collapse caused by malicious software and abnormal network traffic.
Network Forensics
This sub-specialty focuses on the extraction and analysis of digital images to verify authenticity and metadata and determine the history and information surrounding them.
Digital Image Forensics
This field examines audio-visual evidence to determine its authenticity or any additional information you can extract, such as location and time intervals.
Digital Video/Audio Forensics
It refers to the recovery of information from a running computer’s RAM and is also known as live acquisition.
Memory Forensics