Module 03 Computer Investigation Process
Module 03 Computer Investigation Process
Forensic Investigator
Module III
Computer Investigation
Process
Scenario
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Module Objective
~ Investigating methodology
~ Evaluating the case
~ Investigation plan
~ Importance of data-recovery workstations and
software
~ Implementing an investigation
~ Collecting the evidence
~ Closing the case
~ Case evaluation
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Module Flow
Importance of data-recovery
Investigation plan
workstations and software
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Investigating Computer Crime
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Investigating a Company Policy
Violation
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Investigation Methodology
Initial assessment
about the case
Prepare a
detailed design
Determination of
the required resources
Identify the
risk involved
Investigate the
data recovered
Completion of
case report
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Document Everything
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Investigation Plan
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Obtain Search Warrant
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Shutdown the Computer
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Chain-of Evidence Form
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Confiscation of Computer Equipments
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Preserving the Evidence
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Importance of Data-recovery
Workstations and Software
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Configuring Windows 98 Workstation
to Boot into MS-DOS
~ Initiate Windows 98 and run command
prompt.
~ Type msconfig and click Ok button.
~ Select startup settings on the General Tab.
~ Click Advanced button.
~ Click the Enable Startup Menu check box.
~ Click OK to close the Advanced
Troubleshooting Settings.
~ Close the System Configuration Utility window.
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
To Add a command to the MSDOS.SYS
File
Changing
setting
to 59
Changing
setting
to 59
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Implementing an Investigation
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Understanding Bit-stream Copies
0101010101010
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Imaging the Evidence Disk
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Examining the Digital Evidence
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Closing the Case
~ The investigator should include what was
done and results in the final report
~ Basic report includes: who,what,when,where
and how
~ In a good computing investigation the steps
can be repeated and the result obtained are
same every time
~ The report should explain the computer and
network processes
~ Explanation should be provided for
various processes and the inner working
of the system and its various
interrelated components
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Case Evaluation
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Summary