Identifying physical locations
Knowing the system’s physical location may help you prove or disprove the allegations against the subject you are investigating. For example, there was an investigation into a compromise of the organization’s network. A former employee was the suspect in the attack because of their threats during the termination process. When the suspect was interviewed, he denied being in the area and stated he was out of state. A judge authorized a search warrant for the suspect’s mobile device and laptop computer. When conducting the forensic analysis of the laptop, the examiner found it to have been recently restored to a new version of the operating system. Artifacts in the unallocated space led us to believe the user had wiped the device. (The user overwrote all available sectors with hexadecimal 00 characters.) The suspect had not tampered with the mobile device, and we could analyze the device. We were able to map out the Wi-Fi hotspots the...