Section 2: Investigation
In this section, you will learn how to identify the evidence you have collected, analyze it, and draw conclusions to determine whether the facts and circumstances found in the digital evidence support the hypothesis that a crime/incident did or did not occur.
The following chapters are in the section:
- Chapter 5, Computer Investigation Process
- Chapter 6, Windows Artifact Analysis
- Chapter 7, RAM Memory Forensic Analysis
- Chapter 8, Email Forensics — Investigation Techniques
- Chapter 9, Internet Artifacts