Week 4 Flashcards
Three Types of Search + Seizure/Legal Authority
CRIMINAL CASES
- search warrant w/ probable cause (warrant can have different parameters like phone vs. building)
- 4th Amendment - protects against Search and Seizure
- consent is given by owner and can be revoked and search must stop
CIVIL CASES
- court order is the legal authority/demand
- can also come w protective order (to protect person being searched. if investigator leaked something then they can be held in contempt.
consent can still be revoked.
CORPORATE INVESTIGATIONS
- written permission by “keeper of record” who is the legal authority
- consult w/ corporate counsel
Riley v. California (2014)
said that phone cannot be searched without a warrant
Legal Authority 4th Amendment Exceptions
(3)
Exigency
emergency
Probationer/Parolee
Probation officer can ask to search parolee any time.
Border Searches
protects national security
5th Amendment
Person cannot be witness against themself.
Is giving password self-incrimination?
Yes. cannot compel password.
Scope of Case
CSAM = images and video
IP theft = computer data
peripheral drives = hard drives, thumb drives
gaming systems
Alexas - can listen in - show proof of life.
Documentation
WHO WHAT WHEN WHERE WHY
document original scene meticulously
take photos of everything
Crime Scene Considerations
- safety, PPE
- know state of digital evidence (encryption)
- avoid cross contamination
- what needs to be seized?
- isolate/ID main suspects
- document existing conditions
- use special packaging
- maintain chain of custody
- triage
Triage
quick look @ evidence to determine what must be seized
inital survey of scene
not forensically sound
have to minorly change date to triage but it’s okay if you can justify it
can’t triage for all devices
need access to Windows system to triage
Triage can show…
- web history
- IP address history
- connected devices log
- user account info
- existence of known CSAM pics
Should triage data be used in court?
No! hasn’t been analyzed. just rough overview and tells you where to look for data.
Digital Device Physical Seizure
Computers
Hard Drives
SSD Drives
Peripheral Drives