Tools
Session Analysis
Hashing
Legal Process
Cases
100

This seizure method can search through a phone’s memory dump for crucial evidence

What is Paraben device seizure?


100

This phase includes examining file and directory contents and recovering deleted


Content

100

This is one of the first tool of choice in investigating large volumes of data

What is hashing

100

This makes cyber-crime fundamentally different than traditional crime

What is trans-border nature

100

In this case, the Ninth-Circuit case stated border agents need reasonable suspicion of criminal activity to justify a forensic search of a laptop seized at the border

What was the United States Versus Collerman

200

This is the art of copying areas of a hard drive


What is imaging, or at a minimum, the allocated and unallocated areas of a hard disk are copied

200

These are primary uses for Digital forensic tools

What is to fire employees, convict criminals, and demonstrate innocence

200

A means of forensic examiner to ensure the integrity of digital evidence in court

Hashing

200

These are the three basic Crime Scene Investigation steps that must be completed before admission of the evidence in court

 What are acquisition, identification, and evaluation.

200

United States v. Gurczynski No. 17-0139/AR Opinion of the Court established that these two types of drives hold evidence discovered by a digital forensic examiner


What is a thumb and hard?


300

This is a Complexity Problem in digital forensics

What is that acquired data are typically at the lowest and most raw format

300

Session Token Protocol (STOP)

What is protocol used in the forensic analysis of a computer involved in malicious network activity

300

This is any function that can be used to map data of arbitrary size to data of a fixed size

What is a hash function?

300

The legal process of admissibility of science digital forensics in judicial cases is known as this.


What is known the Daubert Standard


300

In this case forensic experts also analyzed email accounts from his time at Harvard, and found no signs of the email chain this individual produced alleging an agreement between the two to share the company 50/50.

What is the case of Paul Ceglia vs Mark Zuckerberg

400

Forensic tools used to examine data on a physical hard drive

What do EnCase, Forensic Toolkit (FTK) and The Sleuth Kit (TSK) all have in common?

400

This person deals with extracting, gathering and analyzing data from a computer or computers, networks and other digital media with subsequent preparation of reports and opinions of this media for evidentiary or other states purposes such as data/digital security, audit, or assessment

Who is a Digital Forensic Examiner

400

This is a primary, yet underappreciated, tool in digital forensic investigations.

What is hashing

400

What limits digital evidence from being obtained from any devices capable of storing digital data

What are strict national and international guidelines for its use in this process

400

This was a case where a man was shot and killed but there were no eyewitnesses, However, the prosecutors were able to get their hands on 88,000 e-mails and other messages on Michelle’s computer including personal ads that Michelle had posted in 1999

What was Michelle Theer (2000)

500

Digital forensic tool highlighted in the BTK serial killer case.

What is EnCase?

500

This is the focus of Digital Forensics



What is the discovery, recovery, and validation of information from computer systems

500

Based on the dataset, files can be filtered in or out from the process of investigation and broadly categorized in the following two categories

What is Known-to-be-good and Known-to be-bad

500

In general, this is the goal of digital forensic analysis

What is to Identify digital evidence for an investigation

500

In this case the Ninth Circuit ruled that border agents need reasonable suspicion of criminal activity to justify a forensic search of a laptop seized at the border

United States v. Cotterman

M
e
n
u