Forensic Sterilisation Flashcards
The Wiping Process
The wiping process overwrites
the data on the external device with a known character
Overwriting Data
During the wiping process, the
investigator can also choose how many times to
overwrite
Most forensic software suites do NOT have the ability
to recover information that has been overwritten one
time
Documentation
Sterilization proccess assists when testifying, shows that the necessary steps were taken to
eliminate any residual data and to prevent cross
contamination of data, performed in lab, wiping and verification verified and throughly documented
Remote wiping
If any signal is recieved when seizied device is powered on, could potentially be a remote wipe of the device or override data stored on device
Shielding device methods
Faraday bags isolate - allow for no interaction
Faraday boxes isolate - allow for evidence preview
Faraday Tents - allow for isolation of a larger area and direct interaction
Faraday paint - allow for entire rooms to be isolated
Arson can / tin foil - homemade versions, low tech and may not be as effective
Airplane mode - easiest built in feature in most devices
Off state
Leave off to avoid - evidence deletion / override, location data and general alteration to the device
Off state steps
Wear PPE to avoid DNA contamination
Note device details, make model ESN and carrier
Note physical condition
If possible remove SIM card
Employ mobile shielding methods
Package and label device and transport safely
On state
Document information,
applications, and settings of the device at the crime
scene
Keep an external power source connected until device is able to be processed
On state steps
Only additional step is that the handset must also be kept charged