How Computer Forensics Analysts Work

Thanks to television shows most of us already have an idea of what forensics is. Although some scenes are not depicted correctly (examining specimens are more exhausting and mentally draining due to the constant demand for paying attention to details, they don't look as easy as they are in television with swooping camera angles) they have given us an idea on what they do in collecting evidence.

Computer forensics is part of this investigation. Due to the higher incidence of cyber crimes they are now an essential part of the legal process.

We already have an idea on what they do. However a computer forensics job entails a lot of procedures and expertise. Like any other evidence electronic data can also be fragile and damaged. There are certain steps to be followed to ensure that the data will be collected without being tampered.

A day in the work of a computer forensic analyst

The first thing that an analyst will do is to secure the data and the machine. The data can never be analyzed in the same system that it came from so exact copies are made. Usually the data in a hard drive is duplicated to extract the information needed.

The collection process starts when the analyst examines the surroundings of the machine. Other physical evidence such as notes, disks and printouts are also taken. Photographs of the surroundings are also taken. The area is also examined for portable storage devices.

If the computer system is still operating the information will be collected by examining its applications. Computers that are used for illegal communications may not have all of the data stored in the hard drive. Information stored in Random Access Memory will be lost if the computer is shut down so this step is important.

Open source tools are used to analyze on live computers. Analysts can also obtain an image of mapped drives and encrypted containers while they are on. The data from network connections are captured first, then running applications, and lastly from the Random Access Memory.

The computer is then shut off carefully in a way that it will not loose any data. The method used will depend in the computer and the operating system it uses. If proper shut down is made volatile data can be lost. Pulling the plug is not advisable either because it may corrupt the file system and loose important data.

The analyst then inspects for trap and photographs the configuration of the system. A diagram will also be made including serial number and markings.

The analyst then makes an exact duplicate of the hard drive called Imaging. They often use hard drive duplicators or software imaging tools. This is done in sector levels to make bit-stream copies of ever part that is accessible to the user which can store data.

The original hard drive is then installed with a hardware write protection and sent to a secure storage. After making a complete and accurate copy the duplicated data can now be analyzed for evidence. Analysts use algorithm to make sure that the imaging process is verified. Two algorithms are generally used in this process.

The analyst then renders his opinion then documents everything that was done. A report is made that contains all the findings of the analyst and whether or not it has been used in an illegal activity or criminal act.

 

 
Translate Page Into German Translate Page Into French Translate Page Into Italian Translate Page Into Portuguese Translate Page Into Spanish Translate Page Into Japanese Translate Page Into Korean

More Articles

 

 

Search This Site

 

Related Products And FREE Videos





 

More Articles


Your Network Security Breached? Hire A Computer Forensic Expert!

... others require you to ship the hard drive to them. The hard drive can be taken out by an IT employee, put in an antistatic bag, taped securely, bubble wrapped, placed in a box then shipped. You may have to call the company first before you ship them. Letting your IT personnel make a preliminary investigation ... 

Read Full Article  


Computer Forensic History: Tracing Its Beginnings

... with the civil action or crime. Some very meticulous individuals will likely disagree as to the correctness of the use of "forensics" instead of "forensic science" since the first term is held to be a synonym for something that is related to the courts or any legal matter. A part of computer forensic ... 

Read Full Article  


Considerations In A Computer Forensic Analyst's Job

... commit fraud. A day in the job Watching forensic television shows don't exactly depict a day in the job of forensic investigators. The tasks that they do are mentally draining and time consuming. They may look interesting due to great camera angles and effects but in reality it takes lots of patience ... 

Read Full Article  


The Advantages And Disadvantages Of Computer Forensics

... to make them admissible in court. Computer forensics is beneficial but it also has disadvantages. Computers are the most dominant form of technology. It has been used in variety of purposes which has made digital and electronic evidence important. However there are still setbacks to this field. Pros and ... 

Read Full Article  


Employment In Computer Forensics

... advanced courses that analysts can take to widen their knowledge. It can be a certification for certain software or learn new tools and topics. Technology is continually changing and developing so analysts have to take certification programs to add and upgrade their tool kits. Finding the right program ... 

Read Full Article