Book Image

Practical Digital Forensics

By : Richard Boddington
Book Image

Practical Digital Forensics

By: Richard Boddington

Overview of this book

Digital Forensics is a methodology which includes using various tools, techniques, and programming language. This book will get you started with digital forensics and then follow on to preparing investigation plan and preparing toolkit for investigation. In this book you will explore new and promising forensic processes and tools based on ‘disruptive technology’ that offer experienced and budding practitioners the means to regain control of their caseloads. During the course of the book, you will get to know about the technical side of digital forensics and various tools that are needed to perform digital forensics. This book will begin with giving a quick insight into the nature of digital evidence, where it is located and how it can be recovered and forensically examined to assist investigators. This book will take you through a series of chapters that look at the nature and circumstances of digital forensic examinations and explains the processes of evidence recovery and preservation from a range of digital devices, including mobile phones, and other media. This book has a range of case studies and simulations will allow you to apply the knowledge of the theory gained to real-life situations. By the end of this book you will have gained a sound insight into digital forensics and its key components.
Table of Contents (18 chapters)
Practical Digital Forensics
Credits
About the Author
Acknowledgment
About the Reviewer
www.PacktPub.com
Preface
Index

Case study – linking the evidence to the user


This case study relates to the examination of a forensic image of the defendant's laptop computer provided by law enforcement officers in 2006. A number of photographs and videos of underage sex were discovered on the defendant's laptop by a computer repairer, who reported the matter to the police, resulting in the seizure of the laptop and criminal charges being laid in 2008. The 2 year delay from arrest to trial may be assumed to be due to the heavy workload of the agency involved.

The defendant's apparent disbelief that he had downloaded illegal, pornographic files onto the laptop and the insistence of his innocence prompted the defense team's examination to measure the reliability of the relevant information, thereby assisting subsequent legal analysis. The offending material had been placed on the laptop during 2004 and 2005, and the laptop had been repaired by the same computer repairer during this period, who evidently did not notice and...