1 Intro To Forensicsv1
1 Intro To Forensicsv1
and Investigations
Fifth Edition
Digital Forensic Investigation Process
1) Identification
2) Preservation
3) Analysis
4) Documentation
5) Presentation Chapter 1
Intro to Forensics
Objectives
• Describe the field of digital forensics
• Digital forensics
– The application of computer science and
investigative procedures for a legal purpose
involving the analysis of digital evidence after
proper search authority, chain of custody,
validation with mathematics, use of validated
tools, repeatability, reporting, and possible expert
presentation.
– Public-sector
investigations
– Private-sector
investigations
• Chain of custody
– Route the evidence takes from the time you find it
until the case is closed or goes to court
Guide to Computer Forensics and Investigations Fifth Edition 19
© Cengage Learning 2018
An Overview of a Computer Crime
• Computers can contain information that helps law
enforcement determine:
– Chain of events leading to a crime
– Evidence that can lead to a conviction
• Misuse includes:
– Surfing the Internet
– Sending personal e-mails
– Using company computers for personal tasks