What you need to know Flashcards
Daubert standard:
Standard used by a trial judge to make a preliminary assessment of whether an expert’s
scientific testimony is based on reasoning or methodology that is scientifically valid and can
properly be applied to the facts at issue.
The Communications Assistance to Law Enforcement Act of 1994 (CALEA)
a federal wiretap law for
traditional wired telephony.
The Electronic Communications Privacy Act of 1986
governs the privacy and disclosure,
access, and interception of content and traffic data related to electronic communications.
The Children’s Online Privacy Protection Act of 1998 (COPPA)
protects children 13 years of age
and under from the collection and use of their personal information by websites.
The Wireless Communications and Public Safety Act of 1999
allows for collection and use of
“empty” communications, which means nonverbal and nontext communications, such as GPS
information.
five types of drive connections:
● Integrated Drive Electronics (IDE) [spoiler answer]
● Extended Integrated Drive Electronics (EIDE)
● Parallel Advanced Technology Attachment (PATA)
● Serial Advanced Technology Attachment (SATA)
● Serial SCSI
Solid-state drives
use Negated AND (NAND) gate–based flash memory,
which retains memory even without power.
advanced forensic file format
AFF file
format is part of the AFF Library and Toolkit, which is a set of open-source computer forensics
programs. Sleuth Kit and Autopsy both support this file format.
EnCase
Creates exact copy of hard drive. EnCase calculates an MD5 hash when the drive is acquired. This hash is
used to check for changes, alterations, or errors.
The Forensic Toolkit (FTK) from AccessData
useful at cracking passwords.
provides tools to search and analyze the Windows Registry.
Steganography
art and science of writing hidden messages. common methods
of performing this technique is the least significant bit
basic steganography terms
-Payload is the information to be covertly communicated.
-Carrier (or carrier file) is the signal, stream, or file in which the payload is hidden.
-Channel is the type of medium used. This may be a passive channel, such as photos,
video, or sound files,
Ophcrack
depend on rainbow tables. Ophcrack is usually very
successful at cracking Windows local machine passwords.
GUID Partition Table
used primarily with computers that have an Intel-based processor.
The /etc Directory
where configuration files are located.