The Basics of Digital Forensics v5
The Basics of Digital Forensics v5
DIGITAL
FORENSICS
WHAT IS DIGITAL FORENSICS?
The Interpol definition of digital forensics makes clear a key distinction between
forensics and e-discovery: the focus on preserving evidence so it is admissible in
court. Typically, forensic investigators work on images—validated duplicates of the
material present on the original device—rather than working with the original or
“live” systems.
Identify evidence Isolate and Reconstruct the Document the Present the narrative
present on digital preserve data in narrative of the narrative and and evidence to the
devices a forensic image event using evidence court or other
of the device(s) available data supporting it responsible party
» Preserve data
» Identify data
» Extract, copy, or image data
» Analyze data
» Document or present data to laypersons
Digital forensics tools can fall into many different categories, including disk
and data capture, email analysis, file analysis, file viewers, internet analysis,
mobile device analysis, network forensics, and registry analysis. They may help
investigators decrypt encrypted data, crack passwords, and recover deleted files.
Digital forensic tools may be specially crafted to work with computer data, mobile
phone data, or both.
But today, more and more private sector organizations need forensic investigatory
capabilities. Whether they are media or journalistic outlets looking to break
stories, or enterprises that need to understand what happened in a cybersecurity
event or a regulatory compliance violation, they need investigators capable
of completing thorough, defensible, forensically sound investigations. Not all
private sector investigators come from law enforcement agencies—although
many do, as discussed in episode 14 of FTK Over the Air. Educational institutions
also train undergraduate and graduate students in digital forensics technology
and techniques, creating future generations of cybersecurity and digital forensic
professionals for both the public and private sectors alike.