Computer Related Evidence & What is this computer geek going to do now that I have done all the hard work?

Slides:



Advertisements
Similar presentations
Computer Forensic Analysis By Aaron Cheeseman Excerpt from Investigating Computer-Related Crime By Peter Stephenson (2000) CRC Press LLC - Computer Crimes.
Advertisements

Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall
File Management Chapter 3
Text Searches Slack Space Unallocated Space
Windows XP Basics OVERVIEW Next.
An Introduction to Computer Forensics James L. Antonakos Professor Computer Science Department.
Computer Forensics 101 Essential Knowledge for 21 st Century Investigators with Case Studies Presented by Steve Abrams, M.S. Abrams Computer Forensics.
X-Ways Trace Prepared By: Leen F. Arikat Supervisor: Dr. Lo’ai Tawalbeh.
Windows Overview LEIT 429x Steve Builta. Where we are going… Overview of operating Systems Overview of Windows 9x Take and Edit digital Photos.
COS/PSA 413 Day 3. Agenda Questions? Blackboard access? Assignment 1 due September 3:35PM –Hands-On Project 1-2 and 2-2 on page 26 of the text Finish.
COS/PSA 413 Day 16. Agenda Lab 7 Corrected –2 A’s, 1 B and 2 F’s –Some of you need to start putting more effort into these labs –I also expect to be equal.
COS/PSA 413 Day 15. Agenda Assignment 3 corrected –5 A’s, 4 B’s and 1 C Lab 5 corrected –4 A’s and 1 B Lab 6 corrected –A, 2 B’s, 1 C and 1 D Lab 7 write-up.
The sequence of folders to a file or folder is called a(n) ________.
PMI Inventory Tracker™
Security+ All-In-One Edition Chapter 20 – Forensics Brian E. Brzezicki.
Capturing Computer Evidence Extracting Information.
Guide to Computer Forensics and Investigations, Second Edition
Chapter 4: Operating Systems and File Management 1 Operating Systems and File Management Chapter 4.
Project 8 Mastering Digital Media: Picture Files.
Microsoft Office Illustrated Fundamentals Unit B: Understanding File Management.
Module 1.4 File management. Contents Introduction Windows Explorer The need to organise More about files Working with files Test and improve your knowledge.
CYBER FORENSICS PRESENTER: JACO VENTER. CYBER FORENSICS - AGENDA Dealing with electronic evidence – Non or Cyber Experts Forensic Imaging / Forensic Application.
With Internet Explorer 8© 2011 Pearson Education, Inc. Publishing as Prentice Hall1 Go! with Internet Explorer 8 Getting Started.
Course ILT Folder and file management Unit objectives Explore the contents of a hard disk and view file and folder attributes by using Windows Explorer.
With Windows 7 Comprehensive© 2012 Pearson Education, Inc. Publishing as Prentice Hall1 PowerPoint Presentation to Accompany GO! with Windows 7 Comprehensive.
I Can… Define basic file management and related terms Identify levels of a file system Identify and explain ways to view files in Windows OS Explain the.
Computer Basics.  Be sure to check with your school’s Network Administrator and/or Handbook before you make changes to your school computer.
Chapter 6: Managing Your Data The Windows XP File System File system task on DOS or UNIX Vs. Windows XP –cd or chdir would change your current directory.
Project 3 File, Document, Folder Management, Windows XP Explorer Windows XP Service Pack 2 Edition Comprehensive Concepts and Techniques.
Microsoft Office 2003 Illustrated Introductory with Programs, Files, and Folders Working.
Guide to Computer Forensics and Investigations, Second Edition Chapter 2 Understanding Computer Investigation.
SLIR Computer Lab: Orientation and Training December 16, 1998.
Teach Yourself Windows 98 Module 2: Working with Files, Folders, and the Desktop.
Digital Crime Scene Investigative Process
Gorman, Stubbs, & CEP Inc. 1 Introduction to Operating Systems Lesson 4 Microsoft Windows XP.
Bits, Bytes, Files, Hard Drives. Bits, Bytes, Letters and Words ● Bit – single piece of information ● Either a 0 or a 1 ● Byte – 8 bits of information.
Microsoft Office 2008 for Mac – Illustrated Unit C: Understanding File Management.
Computing Fundamentals Module Lesson 3 — Changing Settings and Customizing the Desktop Computer Literacy BASICS.
Module 13: Computer Investigations Introduction Digital Evidence Preserving Evidence Analysis of Digital Evidence Writing Investigative Reports Proven.
With Windows 7 Introductory© 2011 Pearson Education, Inc. Publishing as Prentice Hall1 Windows 7 Introductory Chapter 3 Advanced File Management and Advanced.
Project 6 Advanced File and Web Searching. 2 CHAPTER OBJECTIVES  Begin a new file or folder search, save a search, and find a file using a saved search.
1J. M. Kizza - Ethical And Social Issues Module 13: Computer Investigations Introduction Introduction Digital Evidence Digital Evidence Preserving Evidence.
XP New Perspectives on Windows 2000 Professional Windows 2000 Tutorial 2 1 Microsoft Windows 2000 Professional Tutorial 2 – Working With Files.
Windows and File Management
Microsoft Office XP Illustrated Introductory, Enhanced with Programs, Files, and Folders Working.
CMPF124: Basics Skills for Knowledge Workers Manipulating Windows GUI.
ETT 229 Fall Agenda ► 10:00-10:25 – File Management Review ► 10:25-11:00 – ► 11:00-11:15 – Quiz.
Unit 2—Using the Computer Lesson 9 Windows and File Management.
Emedia Training Created October 13, 2009 By Thomas Redd.
Copyright © 2006 Prentice-Hall. All rights reserved.1 Computer Literacy for IC 3 Unit 1: Computing Fundamentals Project 6: Using Windows.
IT1001 – Personal Computer Hardware & system Operations Week7- Introduction to backup & restore tools Introduction to user account with access rights.
Have fun on the internet while being safe!!  Do you know what cyber safety means?.. YesNo.
Matthew Glenn AP2 Techno for Tanzania This presentation will cover the different utilities on a computer.
Windows 2000 Unit A A1 – A24 and Ap1 – Ap3 (Formatting a Disk)
Windows XP Lab 2 Organizing Your Work Competencies.
THE PAPERLESS CLASSROOM: USING GOOGLE DRIVE TO CONDUCT A PAPERLESS RESEARCH PAPER: BENEFITS OF USING GOOGLE DRIVE TO CONDUCT A PAPERLESS RESEARCH PAPER,
EnCase  Starting a New Case  Adding a Device  Creating a Boot Disk  Keyword Search  Bookmarking  File Signatures  Exporting Files/Report  File.
Chapter 8 File Systems FAT 12/16/32. Defragmentation Defrag a hard drive – Control Panel  System and Security  Administration tools  Defrag hard drive.
Computer Forensics Tim Foley COSC 480 Nov. 17, 2006.
1 Lesson 9 Windows Management Computer Literacy BASICS: A Comprehensive Guide to IC 3, 3 rd Edition Morrison / Wells.
Unit Unit 4 – Windows OS File Structure Introducing Your Computer Widows File Types, Trees & Explorer.
Windows 7 and file management
Presented by Steve Abrams, M.S. Charleston, SC / Long Island, NY
Microsoft Windows 2000 Professional
Lesson 9 Windows Management
Module 2 Questions Prepared by Mr O Seguna next.
Fourth Amendment: “The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall.
File, Document, and Folder Management and Windows XP Explorer
Microsoft Office Illustrated Fundamentals
TERMS AND CONDITIONS   These PowerPoint slides are a tool for lecturers, and as such: YOU MAY add content to the slides, delete content from the slides,
Presentation transcript:

Computer Related Evidence & What is this computer geek going to do now that I have done all the hard work?

Rules We Live By And So Should you 4 Never Alter the Original Media! 4 Findings MUST be Verifiable! 4 Findings MUST be Reproducible!

PROCEDURES What your examiners can do for and with you.

4 Assist Preparing the Search Warrant. 4 Service of the Search Warrant. 4 Gathering the Computer Related Evidence(CRE).* 4 Image and Archive.* 4 Store and Secure Computer Related Evidence. 4 Examine.* 4 Review Findings with you.*

4 Complete a Report in the Format You Need.* 4 Prosecutor and Defense Interviews about the computer related evidence. 4 Testify. 4 Dispose / Clean Evidence.*

What We Will Not Do 4 Take Over Your Investigation!

Gathering Evidence 4 Securing 4 Turning off 4 Documenting 4 Marking 4 Transporting

Imaging and Archives 4 We work from an Image of the Suspect media. 4 Copy is stored on CD-R or Tape.

Examine 4 See The Rule We Live By. 4 Work from the copy with a variety of tools. 4 You have to tell us what is going on.

Review with You 4 What is nothing to me may be everything to you. 4 You (always) know a lot more than me.

Report the Findings 4 A report and Examples in the format you need. –Written, Officer’s Witness Statement. –Spread Sheets Showing file information. –Information Printed, on CD-R, Power Point. –Do live demos’ work? Yes or No

Interviews

4 #1 DO NOT LET ANYONE SHOW YOU WHERE THE EVIDENCE IS ON THE COMPUTER…………… 4 Let them talk about their great computer skills or lack of skill. 4 Ownership and use of each computer. 4 Passwords!

4 Like all interviews you are attempting to gather information. 4 What else would you like to know. –Online service, when used the most, computer at work? AND

Search Warrant VS Consent 4 When you can get a search warrant. 4 Consent- knowingly, freely and voluntarily. with the authority to give the consent.

You Found the”something” Are We Done?

Computer Examinations The Fun Stuff. 4 Proving the WHO, WHAT, WHERE, WHEN, HOW and maybe WHY.

Date and Time Stamps 4 Windows 9x and above tracks three dates and two times. 4 NTSF adds one date and one time 4 Other Operating Systems keep dates and time.

Windows > Properties

EnCase view of Date and Times

Deleted Files 4 DOS / Windows Only overwrites the first character of the DOS Directory.

File Slack & Unallocated Space 4 File Slack, the space between the end of the file and the end of the “Cluster”. 4 Unallocated Space, the space on the disk that is not assigned in the directory. (free space. 4 Both contain left over information.

Header Vs. File Extension 4 File Headers, what is important. 4 4A E B FF D8 FF E0 4 D0 CF 11 E0 A1 B1 1A E ,0,FE FF 09 00,29,4,0, File Extension, what we see. –*.ART, DOC, JPG,XLS

Previewing 4 Lets talk. 4 When to to it. 4 What are you looking for. 4 Tools. 4 Where to look.

Previewing. Lets Talk. 4 Consent 4 Damage to evidence 4 Testifying about it in court 4 Do you stand a chance of finding something. 4 False negative.

Previewing. When to do it. 4G4Group participation.

Previewing, When to do it. 4 Looking for text. –Easy anytime. –Have Examiner prepare EnCase Boot disk with search items. –Other tools. Norton disk editor, DIBS Mycroft V3 and others.

Previewing. When to do it. 4 Images. 4 There are not to many DOS based images viewers. 4 EnCase on laplink. 4 Copy out possible sources.

Previewing. Tools. 4 EnCase Laplink or Network Card. $2K 4 Pre- Search & Digit, NIS and Paul Bright. Free, unsupported. 4 Boot to “safe” DOS disk and copy out interesting items.

Previewing. Where to look. 4 C:\Windows\Temporary Internet File 4 C:\Windows\Recent AKA: –Start > Documents (right click & properties) 4 C:\Windows\History 4 Recycle bin 4 Internet Explorer, Recent and Favorites 4 My Documents > My Pictures ?

Previewing, Where else 4 Looking for Newsgroup Programs. –Free Agent, NewsRover, Outlook. 4 C:\Windows\Temp 4 The Directory in each Volume? –Folder Titled “kid pict” or some other obvious name.

Organizations. 4 CTIN 4 AGORA 4 HTCIA 4 IACIS 4 NWCCC