100 likes | 185 Views
Digital Forensics. Hardware components. Motherboard System bus CPU ROM RAM HDD Input devices Output devices. Storing and Retrieving Data. OS Formatting and Partitioning the HDD Mapping the HDD Sectors Clusters Tracks Cylinders. Documenting the Electronic Crime Scene.
E N D
Hardware components • Motherboard • System bus • CPU • ROM • RAM • HDD • Input devices • Output devices
Storing and Retrieving Data • OS • Formatting and Partitioning the HDD • Mapping the HDD • Sectors • Clusters • Tracks • Cylinders
Documenting the Electronic Crime Scene • Document the scene • Photograph overall layout • Photograph all connections • Decide on data acquisition method • Forensic Image Acquisition • Must not alter data in anyway • Can’t just boot up or will alter HDD • Remove HDD and place in forensic computer • Use MD5 or SHA algorithms to fingerprint disk
Analysis of Electronic Data • Visible data • Data/Work product files • Swap file data • Temporary files • Latent Data • Slack space • RAM slack • File slack • Unallocated space • Defragmenting • Swap files/swap space • Deleted files
The Internet • Browsers • URL • Hypertext • Bookmark • Search engines • Email • Mailing lists • Newsgroups
The World-Wide Web • Internet cache • Cookies • Internet history • Bookmarks/Favorites
Forensic Analysis of Internet Data • IP addresses • Email, Chat and IM • Hacking • Firewall
Forensic Investigation of Internet Communications • Connections • Modem • Broadband • DSL • Wi-Fi • Routers • VoIP • ISPs • IP • Domains
Forensic Psychiatry/Psychology • Psychological testing • Rorschach • Thematic-Apperception Test • Personality Inventories • Intellectual and Cognitive Assessment • Altered State Interviews