Forensic Process Phases Flashcards
Identification
Identification / Seizure phase; primary stage in arrival, identification and evidence collection
Acquisition and Imaging
Dig. evidence is acquired, through obtaining a forensic copy or a logocal extraction of data stored on a device
Analysis
Includes the processes and procedures performed on evidence
Reporting
Includes the documentation and presentation of the analysis findings
Analysis Breakdown
Performing link / timeline / file signature analysis
Data carving - reassemble fragmented files in unallocated / free space
Advanced Searches - keywords/watchlists, regular expressions/pattern
analysis, and dates
Background info - first responders / detectives or complainant
Location based data from commercially available tools
Reporting Findings
Report breakdown;
Establishes background,
Documents the evidentiary chain of custody,
Identifies in detail the seized media,
Documents the steps taken to preserve evidence,
Describes processes used to acquire and analyse,
Details findings