Building Basic Computer Forensics Laboratory
Building Basic Computer Forensics Laboratory
Forensics Laboratory
• Lab Space
• Equipment Needs
• Software Needs
• Supply needs
• Training
• Procedures
Lab Space
• Secure
• Adequate electricity for equipment
• Adequate cooling, low humidity for
equipment
• Desks/benches for forensic analysis and
administrative work
• Locking rooms, or containers for
evidence, both original and Derivative
• Internet connection
Equipment – Write Blockers
• Hardware write
blockers
– Support all types of
hard drives
– www.wiebetech.com
Equipment – Exam Computers
• Currently evaluating
Apple GS5 and Apple
Raid
• Can Tri Boot and run
Apple, windows and
Linux from same
box
Exam Computers - Storage
• 1 Terabyte drives
are here. How much
is that?
– 1 million photos
– 16 days of DVD
quality video
– 1 million minutes of
music
Exam Computers - Storage
• Network switch,
cabling, network
cards for forensic
work
• Another complete set
for Internet and a
firewall, can be
combined
firewall/router/switch
Equipment – Cell Phones/PDAs
NOTES:
– The field of computer forensics requires daily learning, technology
changes everyday
– Testing – Each Examiner should take and pass a competency test,
to show they understand both forensic principals as well as tool
use.
Laboratory Policies
www.rcfl.gov
www.phrcfl.org