Showing posts with label computer forensics investigator. Show all posts
Showing posts with label computer forensics investigator. Show all posts

Monday, 21 September 2015

Certified Cell Phone Examiner to Investigate and Recover Evidences

No matter what kind of mobile phone is used, whether it is a smart phone device or a common cell phone, it is basically used for call and messaging purposes.  All kinds of cell phones are playing a significant part as digital evidences in investigations regarding criminal and civil litigations.  The technology which has been used in these cell phones enables them to save each and every repository about personal information.  That saved data is referred to as solid evidence. With the help of cell phone forensics useful information from the cell phones can be obtained like call records, location, files, multimedia files and appointments that can be used as admissible evidence in all the legal proceedings.  A  Certified Cell Phone Examiner or a forensic expert team is deployed by private or government sector so as to categorize the useful information or evidences.

Private or government sector cell phone forensic investigators are trained in use of advanced forensic tools and have expertise in many techniques used to recover distinct kinds of evidences.  Additionally, investigators deal with the most stringent aspects of cell phone forensic evidence recovery, such as device’s flash memory analysis, even when the device is un-operational, broken, or when the analysis is not compatible with the forensic application.  

  • Cell Phone Examiners extensively deal with assembling evidence from the cell phones in varied sorts:
  • Records of Call History
  • Recovery of Contact List/ Phone Book
  • Recovery of Text Message / Determining receiver & sender and thus creating a timeline for events
  • Recovery of To Do List
  • Analysis of Cell Phone Chat/ Email
  • Recovery of Multimedia Message
  • Extracting Audios/Photos/Videos
  • Tracing of  Social Networking Activities
  • Data Extraction from Physical Memory/Sim Cards
  • Access Encrypted Data & Back Up Files / Decode Data
  • Detecting of Spyware/ Malware

The extent of cell phone forensic examination is broadly increasing in several investigation areas.   They  primarily follow  this investigative measure in  order to deal with white collar crimes like securities fraud, bankruptcy frauds, investment frauds,  bank frauds, Ponzi schemes,  identity thefts and serious offenses like homicides, child pornography, cyber bullying, stalking, and espionage. Cell phone examiners are proficient in recovering lost/deleted information or evidence from all sorts of cell phone models including array of high-tech smart phones such as Blackberry, Androids and iPhones.

ICFECI provide Cell Phone Examiners specialized in tracking transactions, social connections, appointment schedules, communication by third party applications, meetings and location trace with respect to the event’s timeline.   Cell Phone Examiners are experienced and well trained in performing as a professional witness in presenting digital/electronic evidence.


Cell Phone Examiners handle preservation, acquisition, and processing of evidence, in a forensically sound manner.  Evidence custody is maintained in full compliance with codes and rules of evidence.


Tuesday, 18 August 2015

5 STEPS TO CONDUCT A COMPUTER FORENSIC INVESTIGATION

The increase in criminal activities involving the use of electronics warrants a structured investigation of criminal and civil litigations by employing computer forensic analysis. Digital forensic analysis is a meticulous process of uncovering data/ evidence that is relevant to the successful resolution of a case. However, deploying digital forensics to aid investigation demands a team of experienced computer forensic analysts, high end digital forensic tools and equipment and an organized lab where evidence recovered can be converted to structured reports thus helping the effective representation of defendants during trials.
Here is a detailed view of the process that can help you understand its role, limitations and the activities involved if you are willing to pursue a career in the stream.
 https://www.einvestigator.com/wp-content/uploads/2013/12/computer-forensic-software.png
Selecting a Process of Investigation
Digital Forensic has been a part of investigation procedures since 1984 when officials started employing computer programs to uncover evidence hidden in electronics and digital formats. The process has evolved to become more organized, sophisticated and well equipped with latest tools and technologies. However, choosing a particular method of investigation is the duty of the digital forensic analyst. A messy process of analysis can lead to the accumulation of random data and inconclusive evidence thus directly affecting the outcome of a trial. It is important to construct a design plan and to choose appropriate tools and software to conduct the investigation and ensure that not a single step has been bypassed or ignored. 

Acquisition
Once the case study is completed and a strategy decided upon, the first basic step involves the acquisition of data/ evidence in the form of digital documents, videos, images, files, financial records, accounts, recent computer activity, browsing history, emails and social media messages. Computer forensic analysts are experts in finding evidence by recovering deleted files, emails, social media activities, tracking and monitoring transactions, tapping into servers and finding relevant data to support an investigation. 

 http://www.pennfoster.edu/~/media/Images/Tabs/Programs/ForensicComputerExaminerCert.ashx
Also a dedicated part of computer forensics involves retrieving information from cell phones in the form of call records, location information, phonebook details, text messages and other personal details like schedules, appointment details, videos and image files. In this phase the analysts ensure that the evidence has been retrieved using methodologies that abide by the law and are done with proper approval of authorizing personnel. 

Identification
This phase requires analysts to separate the relevant discovery in digital format and converting them into a form understood easily by laymen, judges and juries alike. All the retrieved data can be preserved in the form of raw digital data.  The raw data may then be culled and processed. The resulting data can then be organized producing well systematized reports using forensic tools.  Organization of the retrieved data is accomplished by using sophisticated forensic tools like Forensic Toolkit (FTK), Mobile Phone Examiner (MPE+) and dtSearch as efficient document search tools.   
 http://www.criminaljusticeprogramsonline.com/cjo/assets/iStock_000005044123Small.jpg
The relevant data may be hosted on an evidence review platform, accessible via internet.
Evaluation
This is the most important phase of digital forensic investigation which decides whether authentic and conclusive evidence has been discovered and subsequently determines the outcome of the litigation. The forensic analysts strive to find whether the information obtained is legitimate evidence and whether it can be presented during a trial. The components identified and preserved during the previous phases are correlated, a timeline of events is established and an inference is drawn that is relevant to the case and provides sufficient support in favor of the defendant. The Evaluation phase is an important element of effective representation of the client since it directly affects the successful resolution of a case. 

Admission
The carefully constructed reports and material evidence are of no use if they are discarded in a court of law as "inadmissible evidence". Therefore it is imperative that the proofs have been obtained using legal means, with permission from the authorizing entity, and the evidence is relevant. This factor will lend reliability to the evidence especially if it has been retrieved by a Certified Computer Forensic Examiner and ensure that the evidence is admissible at trial. 

Computer Forensic Investigation is a process which requires expertise and years of experience and desired results can be achieved only by following a well defined strategy.

Sunday, 19 July 2015

ROLE OF A COMPUTER FORENSIC EXAMINER IN AN INVESTIGATION



Electronic and digital devices have the scope of storing a vast amount of information regarding a person’s personal and professional life.  It is a reliable repository of crucial information that needs to be extracted and presented to verify or nullify the events in a legal proceeding. Digital Media & Storage Devices including computers, laptops and tablets becoming a potential source of evidence in all litigations has made the involvement of a digital forensic expert inevitable. 

http://www.pennfoster.edu/~/media/Images/Tabs/Programs/ForensicComputerExaminerCert.ashx

A Computer Forensic Examiner plays an integral part in the investigation and successful resolution of a case. While forensic analysts are known by different names such as computer forensic analysts, digital forensic investigators/ specialists/ experts, their job essentially revolves around evidence management and representation. They are experienced in identifying, organizing and preserving data or evidence in an efficient manner in order to provide accurate proofs in support of statements during a trial. 

The role of a Computer forensic specialist is not limited to evidence recovery and presentation. Unbeknownst to most, forensic analysts are capable of providing a new direction to a case and make a huge difference in courtrooms with their analytical ability, critical thinking and expert presentation of facts in a convincing manner. Here is a brief summary of duties performed by these expert professionals to aid an investigation:

Evidence Recovery, Management & Representation
This is the primary responsibility of a forensic examiner. Whether it is an encrypted document or deleted files, digital forensic specialists are capable of converting them into formats acceptable in courts. They have the ability and knowledge to analyze and track evidence in any form like documents, files, videos, images, encrypted data, deleted/ hidden information, emails, messages, identifying modifications, altercation and recent digital and internet activities.
http://www.invsolutionsllc.net/wp-content/uploads/2011/08/Computer-Forensics.png

Besides dealing with a variety of evidence, analysts are trained to locate data/ evidence from any digital source. They deploy tools, techniques and critical analysis to break through complex gadgets or day to day devices like computers, laptops, cell phones, tablets, SD cards, peripheral as well as connecting devices in addition to network servers, social media activity tracking and evaluating financial statements, records and accounts. Forensic Examiners have a knack for wading through a vast amount of data and locating the required information.

Correlating Events & Statements
Information is of no use if it cannot prove a point or lead the case towards success. It is a crucial aspect of forensic investigation to establish timeline of events, verify or nullify the statements of witnesses and present witnesses to support facts and circumstances. Digital Forensic Analysts are experienced and skilled in analyzing the information and compiling them to establish a coherent inferences or conclusions.

 http://www.pegasus-investigations.co.uk/wp-content/uploads/2011/07/computer-forensics.jpg
Expert Witness Testimony
The witness presented by an expert digital forensic analyst aided by digital evidence acts as a solid way of presenting testimony. Forensic analysts are trained to present evidence in a convincing manner as well as explain jargons and complex technicalities in simple user friendly terms that can be easily admitted by judges & juries. The efficient representation of facts & figures and the inferences drawn thereby by an experienced forensic examiner ensures the successful resolution of a legal proceeding. 

However, before approaching an investigative agency to aid you in computer forensic examination you need to make certain that the organization is reputed, experienced and the required resources and skills to handle privileged information obtained during the investigation in a confidential manner.