What Happens In A Computer Forensic Investigation

We have always heard of the word "hack". Its mostly used in related to computers and gets blamed for everything bad that happens in futuristic crime action movie. Most of these are not entirely true but network systems do get hacked. Most companies are confident of what their IT department is capable off.

However that does not mean that an employee can not be tempted to do a little snooping of his own. Most of the time offenders are within the company itself. The accessibility of the internet also poses a problem. Anyone can be anything online. This is why fraud, phishing, and identity theft happen.

The computer is an important part of our lives. Sending letters have been entirely changed through emails. Communications have been dominated by instant messaging and texts. Portable storage devices that were only known to IT professionals are now used by the general public. We already have an idea of what computer forensics is but what does happen in a typical investigation?

The computer crime scene

First like any other investigation would start, the location is regarded as a crime scene. The computer analyst will take digital photographs and secure documentary evidence. This includes printouts, notes and disks in the scene. If you have hired a computer forensic expert you should leave everything to them. The computer system should left as it is whether it is turned on or off.

If the computer is turned on the computer analyst will gather all the information that he can from the running applications. It will then be shutdown in a way that the data will not be lost. Doing a standard shutdown or pulling the plug is not an option. Both of these methods may cause the lost or damage of the data in the computer system.

The computer forensic analyst then documents the configuration of the system. This will include the order of hard drives, modem, LAN, storage subsystems, cable connections, and wireless networking hardware. The analyst will take digital photographs and make a diagram. They will also take portable storage devices within the area that may contain substantial evidence.

After that the hard drive will be taken to the lab. It's not suitable to examine data in the same hardware. Offenders who engage in cyber crimes are also aware that important data can be retrieved to convict them. Countermeasures, viruses and booby traps may be installed in the system to damage electronic evidence.

Analysts take the hard drive in their lab instead to make an exact duplicate of its contents. This process is called Imaging. Analysts have their own tools to make sure that the data is copied completely and accurately.

The duplicate will then be verified by an algorithm. The data is then examined and analyzed. The analyst makes a report containing his findings and all that was done during the investigation starting from the acquisition of the data. The evidence that will be found will be presented in court of prosecution takes place.

The analyst will be an expert witness to present his findings. The most important thing about computer forensic experts is that they are trained in handling evidence. Any IT professional can extract data but they will not be able to preserve it.

The legal aspect of the field makes it different and therefore important.

 

 
Translate Page Into German Translate Page Into French Translate Page Into Italian Translate Page Into Portuguese Translate Page Into Spanish Translate Page Into Japanese Translate Page Into Korean

More Articles

 

 

Search This Site

 

Related Products And FREE Videos





 

More Articles


Employment In Computer Forensics

... Information can be a formidable weapon. It can be used for leverage or for blackmail. Computer forensic analysts can extract important information from emails and messages from instant messaging. They can also find out if a certain computer has been used for illegal communications and activities. Their ... 

Read Full Article  


Computer Forensics Investigators — Who Are They?

... one of your multi-million projects gets corrupted, it crashes, and then it burns? Sure enough, you will think that it is the end of the world for you. Just imagine how you and your staff have concerted your efforts just so the project will materialize and now that you are nearly feeling the glory of its ... 

Read Full Article  


Computer Forensic Training: An Overview

... Requirement There are no licensure examinations to be undergone only that there are certain credentials that should be supplied. Among the major credentials that one can present are the formal education bases such as the Certified Computer Examiner or CCE and the Certified Information Systems Security ... 

Read Full Article  


Computer Forensics Software: The Tools Of The Trade

... exact duplicate of a hard drive. They analyze the contents of the copy to know if the computer has been used for illegal activities or criminal acts. They can also trace emails and instant messages. They have their own toolkits and programs to help them do this job. This is why you have to hire them because ... 

Read Full Article  


The Advantages And Disadvantages Of Computer Forensics

... of purposes which has made digital and electronic evidence important. However there are still setbacks to this field. Pros and Cons The exchange of information is taking place everyday over the internet. Although this may be convenient for us, it can also pose as an opportunity for criminals. Phishing, ... 

Read Full Article