Media analysis
You can use timeline analysis on several vectors, such as network analysis, media analysis, software analysis, and hardware analysis. Network analysis is where you analyze log files, trace files, and the communication content between users and their devices. Media analysis is analyzing physical storage devices such as hard drives, SSD drives, thumb drives, or optical storage disks. You will examine the content, allocated space, and slack space. Finally, when performing software analysis, you reverse-engineer malicious code and analyze the protection code for potential exports.
So, let’s look at media analysis. The primary source for your digital investigation will be the forensic images of storage devices such as hard drives, SSDs, USB devices, optical disks, and mobile devices such as smartphones. Depending on your organization, you may be the person responsible for creating the forensic image, or the forensic image may be provided to you from another part...