This seizure method can search through a phone’s memory dump for crucial evidence
What is Paraben device seizure?
This phase includes examining file and directory contents and recovering deleted
Content
This is one of the first tool of choice in investigating large volumes of data
What is hashing
This makes cyber-crime fundamentally different than traditional crime
What is trans-border nature
In this case, the Ninth-Circuit case stated border agents need reasonable suspicion of criminal activity to justify a forensic search of a laptop seized at the border
What was the United States Versus Collerman
This is the art of copying areas of a hard drive
What is imaging, or at a minimum, the allocated and unallocated areas of a hard disk are copied
These are primary uses for Digital forensic tools
What is to fire employees, convict criminals, and demonstrate innocence
A means of forensic examiner to ensure the integrity of digital evidence in court
Hashing
These are the three basic Crime Scene Investigation steps that must be completed before admission of the evidence in court
What are acquisition, identification, and evaluation.
United States v. Gurczynski No. 17-0139/AR Opinion of the Court established that these two types of drives hold evidence discovered by a digital forensic examiner
What is a thumb and hard?
This is a Complexity Problem in digital forensics
What is that acquired data are typically at the lowest and most raw format
Session Token Protocol (STOP)
What is protocol used in the forensic analysis of a computer involved in malicious network activity
This is any function that can be used to map data of arbitrary size to data of a fixed size
What is a hash function?
The legal process of admissibility of science digital forensics in judicial cases is known as this.
What is known the Daubert Standard
In this case forensic experts also analyzed email accounts from his time at Harvard, and found no signs of the email chain this individual produced alleging an agreement between the two to share the company 50/50.
What is the case of Paul Ceglia vs Mark Zuckerberg
Forensic tools used to examine data on a physical hard drive
What do EnCase, Forensic Toolkit (FTK) and The Sleuth Kit (TSK) all have in common?
This person deals with extracting, gathering and analyzing data from a computer or computers, networks and other digital media with subsequent preparation of reports and opinions of this media for evidentiary or other states purposes such as data/digital security, audit, or assessment
Who is a Digital Forensic Examiner
This is a primary, yet underappreciated, tool in digital forensic investigations.
What is hashing
What limits digital evidence from being obtained from any devices capable of storing digital data
What are strict national and international guidelines for its use in this process
This was a case where a man was shot and killed but there were no eyewitnesses, However, the prosecutors were able to get their hands on 88,000 e-mails and other messages on Michelle’s computer including personal ads that Michelle had posted in 1999
What was Michelle Theer (2000)
Digital forensic tool highlighted in the BTK serial killer case.
What is EnCase?
This is the focus of Digital Forensics
What is the discovery, recovery, and validation of information from computer systems
Based on the dataset, files can be filtered in or out from the process of investigation and broadly categorized in the following two categories
What is Known-to-be-good and Known-to be-bad
In general, this is the goal of digital forensic analysis
What is to Identify digital evidence for an investigation
In this case the Ninth Circuit ruled that border agents need reasonable suspicion of criminal activity to justify a forensic search of a laptop seized at the border
United States v. Cotterman