Chapter 2: The Forensic Analysis Process
We will now discuss the forensic analysis process. As a forensic investigator, you will need to create a process that will enable you to conduct an efficient investigation. You also need to make sure you are familiar with your tools and the results that they will provide. Without a process, you will waste time examining data that will not have an impact on your investigation and you will not be able to rely on your tools. You want to make sure you are getting valid results from the tools you deploy. To be thorough and efficient, you must use critical thinking to determine the best method of conducting an investigation or exam.
While there are similarities in every investigation, you will find there are differences that will require you to have an exam strategy to be efficient. I am not a fan of keeping an examination checklist because there will be areas that are not applicable, such as different operating systems, physical topography...