Please enable JavaScript.
Coggle requires JavaScript to display documents.
Digital Forensic, Ram, Chain of custody process, Aquisition, SWGDE Best…
Digital Forensic
Storage Forensics
Explain - Investigative process focusing on analyzing storage media and systems for digital evidence
-
-
Disk Imaging
Creating a bit for bit copy (forensics image) of storage devices for analysis - mainly used for preservation of data
-
Email Forensics
Overview
Mail User Agent
Client’s email software Ex. Gmail, Yahoo!mail, Microsoft LiveMail
-
Mail Delivery Agent
Application responsible for receiving an email message from MTA and store in into mailbox of the recipient
-
-
-
Web browsing Forensics
-
Web browsing Artefacts
-
Cache
Chrome Cache is stored using an Index file ('index'), a number of Data Block files ('data#'), and a number of separate data files ('f######')
HTTP Cookies
HTTP Cookies are stored in the 'Cookies' SQLite database, within the 'cookies' table
Downloads
Chrome Downloads are stored in the 'History' SQLite database, within the 'downloads' and 'downloads_url_chains' tables
Favicons
Chrome Favicons are stored in the 'Favicons' SQLite database, within the 'favicons', 'favicon_bitmaps' and 'icon_mapping' tables. Older versions of Chrome stored Favicons in a 'Thumbnails' SQLite database, within the 'favicons' table.
Form History
Chrome Form History is stored in the 'Web Data' SQLite database, within the 'autofill' table. Older versions of Chrome
stored associated dates within an 'autofill_dates' table
-
-
-
-
-
-
-
Chain of custody process
Identification and Collection : Evidence is collected at the crime scene by authorized personnel, and the location, time, and people involved are documented
Packaging and Sealing: The collected evidence is properly packaged and sealed to prevent tampering or damage.
Packaging and Sealing: The collected evidence is properly packaged and sealed to prevent tampering or damage.
Custody Transfer: Evidence is transferred between individuals or locations, and each transfer is documented.
Storage and Security: Evidence is stored securely to prevent unauthorized access, tampering, loss, or damage.
Documentation of Access: Any examination, testing, or movement of evidence is documented, including the purpose and individuals involved.
Court Presentation: Testimony is provided in court by individuals who handled the evidence, establishing the chain of custody and ensuring its integrity.
-
Aquisition
In digital forensics, "acquisition" refers to the process of collecting and capturing digital evidence from various sources. It involves creating a forensic image or a copy of the original data in a forensically sound manner to preserve the integrity of the evidence. Data acquisition is a subset of the acquisition process, specifically focusing on the collection of digital data.
-