Chapter 5: Computer Investigation Process
Being a digital forensic examiner requires you to have a plan to conduct the investigation. For instance, there is the kitchen sink approach – where the person requesting the examination states, I want it all. However, this is not practical when the smallest drive from a system might contain hundreds of thousands of pages or events. While the kitchen sink approach is a plan, it may not be the most efficient.
In reality, your search method will depend on the crime you are investigating, and whether there are limitations to the scope of the search. In some investigations, the judicial authority may restrict an investigator's access to digital evidence to only email messages, or you may be limited to a specific date and time within the forensic image.
In this chapter, we will first go through timeline analysis, where a user's activity is analyzed temporally. Then, we will examine the storage containers that are used...