Week 4 Flashcards

1
Q

Three Types of Search + Seizure/Legal Authority

A

CRIMINAL CASES
- search warrant w/ probable cause (warrant can have different parameters like phone vs. building)
- 4th Amendment - protects against Search and Seizure
- consent is given by owner and can be revoked and search must stop

CIVIL CASES
- court order is the legal authority/demand
- can also come w protective order (to protect person being searched. if investigator leaked something then they can be held in contempt.
consent can still be revoked.

CORPORATE INVESTIGATIONS
- written permission by “keeper of record” who is the legal authority
- consult w/ corporate counsel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Riley v. California (2014)

A

said that phone cannot be searched without a warrant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Legal Authority 4th Amendment Exceptions

A

(3)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Exigency

A

emergency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Probationer/Parolee

A

Probation officer can ask to search parolee any time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Border Searches

A

protects national security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

5th Amendment

A

Person cannot be witness against themself.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is giving password self-incrimination?

A

Yes. cannot compel password.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Scope of Case

A

CSAM = images and video
IP theft = computer data
peripheral drives = hard drives, thumb drives
gaming systems
Alexas - can listen in - show proof of life.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Documentation

A

WHO WHAT WHEN WHERE WHY

document original scene meticulously

take photos of everything

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Crime Scene Considerations

A
  • safety, PPE
  • know state of digital evidence (encryption)
  • avoid cross contamination
  • what needs to be seized?
  • isolate/ID main suspects
  • document existing conditions
  • use special packaging
  • maintain chain of custody
  • triage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Triage

A

quick look @ evidence to determine what must be seized

inital survey of scene

not forensically sound

have to minorly change date to triage but it’s okay if you can justify it

can’t triage for all devices

need access to Windows system to triage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Triage can show…

A
  • web history
  • IP address history
  • connected devices log
  • user account info
  • existence of known CSAM pics
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Should triage data be used in court?

A

No! hasn’t been analyzed. just rough overview and tells you where to look for data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Digital Device Physical Seizure

A

Computers
Hard Drives
SSD Drives
Peripheral Drives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Computers

A

has volatile memory or random access memory (RAM) - RAM is the waiting room between the computer hard drive and what is seen on screen.
Passwords to encryption can be in RAM.

15
Q

Hard Drives

A

need a Faraday bag

label w date, time, person who seized/packed item

16
Q

SSD Drives and Stand-alone computers

A

they have different approaches

17
Q

Peripheral Devices

A

USBs
SD Cards
portable hard drives

18
Q

All devices are self-contained and still require the same precautions as stand-alone hard drives, like Faraday bags.

A

-

19
Q

Is on-scene manipulation okay?

A

If it can be justified and isn’t too severe.

it is never worth losing valuable evidence over a legal misstep.

if you do smth wrong/change smth, don’t lie! document

20
Q

PROPER SEIZURE

A

Don’t manipulate device more.

Put in airplane mode, off wifi, off bluetooth.

Prevent remote wipe and preserves data.

faraday bags

21
Q

DON’T

A

just scroll through phone
place phone in chip bad
forget to ask for passcode

22
Q

Ensure evidence not altered

A
23
Q

OS Triage

A
  • made by Eric Zimmerman
  • provides on-scene investigators w/ real time info about systems
  • can be used on mounted media
  • can show times, dates, shut downs, whose account it is, which accts need password, files access, USB insertions
  • can see forensic tools plugged in
24
Q

mounted media

A

making storage device’s files and directories to user and OS - can then examine contents of logical image?