Media analysis
There are several vectors that you can use timeline analysis on, such as network analysis, media analysis, software analysis, and hardware analysis. Network analysis is where you are analyzing log files, trace files, and the communication content between users and their devices. Media analysis is where you are analyzing physical storage devices such as hard drives, SSD drives, thumb drives, or optical storage disks. You will examine the content, allocated space, and slack space. When performing software analysis, you are reverse-engineering malicious code or analyzing the protection code for potential exports.
So, let's look at media analysis. The primary source of your digital investigation will be the forensic images of storage devices such as hard drives, SSDs, USB devices, optical disks, and mobile devices such as smartphones. Depending on your organization, you may be the person responsible for creating the forensic image, or the forensic...