|
|
||||||
IT FORENSICS 3 - EVIDENCE FROM COMPUTERS & LAPTOPS |
| HOME | Comp Forensics 2 | PC's & Laptops | Comp Evidence 1 | Comp Evidence 2 | Fingerprinting | Offices | | Corporate Client | Private Client | Legal Client |
|
Evidence will be most often found in files that are stored on hard drives, whether internal or external. Files may, of course, have been deleted and will need running of sophisticated recovery programmes. Dates and time of creation can be of vital importance, as can modification dates, deletion dates etc. Temporary back up files, web cache , address books etc may be re-created with application. Areas for consideration include: |
|||
User Created Files: May contain evidence of relevant activity, e.g. address books and database files that can prove associations with persons external or internal, or undisclosed communication. Images can be rebuilt even if deleted, as can video or scanned documents. Such files may be in the form of: |
|||
|
|||
|
User Protected Files: A user may encrypt or password-protect important data, or hide files on a hard disk, within other files, or attempt to hide incriminating data under an innocent sounding name. User Protected files may be in the form of: |
|||
|
|||
Computer Generated Files: Evidence may also be found in files and data areas that are created routinely by Operating Systems - something of which the user is often not aware. Password recovery is often achievable through recovery and examination. Some file components hold evidentiary value such as time and date creation/ modification / deletion / access; even turning the machine on may alter some of this information e.g. the last time a PC was booted may be of importance. The attributes of a particular file may be a solid indication or pointer. Data may be retrieved from: |
|||
|
Area Office |
Telephone |
Email |
Satellite offices |
||||||
01483 200999 |
|||||||||
0207 158 0332 |
|
||||||||
0118 9733 049 |
|
||||||||
02380 308274 |
|||||||||
01293 769475 |
|||||||||
01252 308475 |
|||||||||
01202 366156 |
|||||||||
01494 619397 |
highwycombe@answers.uk.com |
| Tel: 0800 980 4 267 | "searching the world for answers" |