Computer Forensics Expert
Computer forensics is the practice of collecting, analyzing and reporting on digital data in a way that is legally admissible. It can be used in the detection and prevention of crime and in any dispute where evidence is stored digitally. This discipline follows a process similar to that of other forensic disciplines, and faces similar problems.
There are few areas of crime or litigation to which computer forensics cannot be applied. Law enforcement agencies have been among the earliest and heaviest users of computer forensics and have consequently often been at the forefront of advances in the field.
Computer equipment can constitute a “crime scene”, for example with hacking or denial-of-service attacks, or it may hold evidence in the form of emails, Internet history, documents or other files related to crimes such as murder, kidnapping, fraud, drug trafficking, child pornography, etc.
What can be analyzed?
- Computer equipment (servers and personal computers)
- Email accounts and associated messages
- External storage devices: USB drives, SD cards, CDs, DVDs
- Mobile phones, smartphones, tablets, PDAs…
- Database systems
- Forums and social networks
- Websites that have disappeared in the face of an investigation
- Complex software systems (ERP, CRM, accounting solutions, etc.)
It is not only the content of emails, documents and other files that may be of interest to investigators, but also what the computer forensics expert refers to as metadata. This metadata is associated with the files.
More recently, commercial organizations have used computer forensics to their benefit in a variety of cases, such as:
- Intellectual property theft
- Industrial espionage
- Workplace disputes
- Fraud investigations
- Forgeries
- Bankruptcy investigations
- Inappropriate use of email and the Internet in the workplace
- Regulatory compliance
See the section on the services offered within our computer forensics expert and computer forensics portfolio.
Protocol
For digital evidence to be admissible it must be reliable and not prejudicial, which means that at all stages of a forensic team’s work, the admissibility of the investigation must be a priority in the computer forensic work.
The four fundamental principles for a forensic analysis carried out by a computer forensics expert are:
- No action should change the data held on a computer or storage media that may later be challenged in court.
- Where a person finds it necessary to access original data held on a computer or storage media, that person must be competent to do so and able to give evidence explaining the relevance and the consequences of their actions.
- A reliable record must be kept of the audits and other records made of all processes applied to electronic evidence on a computer system. An independent third party must be able to examine the processes and obtain the same result.
- The person in charge of the investigation has overall responsibility for ensuring that the law and these principles are complied with.
Stages of the computer forensic examiner’s work
More about presentation
This stage generally involves preparing a structured report that answers the initial questions, together with the findings subsequently made by the examiner. It would also cover any other information the examiner considers relevant to the investigation.
The report must be written with the end reader in mind; in many cases the reader does not have a technical profile, so the terminology must suit the reader. The latter should not be mistaken for a justification for not knowing and using technical language, since the report must also meet sufficient technical requirements for the conclusions to be probative.
More about preparation
This is a critical and vitally important stage that is often overlooked in the examination process. It may include, for example, educating or training clients (companies) on preparing the system; for instance, forensic examinations will provide more consistent and valuable evidence if a device’s audit features or options have been enabled before any incident occurs; for example by making use of log files. The computer forensics examiner therefore also has the task of informing clients of the options available in the systems that make up a company’s IT infrastructure.
More about assessment
The assessment stage includes receiving instructions, clarifying those instructions and allocating roles and resources. A risk analysis for carrying out the enforcement may include an assessment of the likelihood of physical threat when entering a suspect’s property and the best way to counter it. Commercial organizations, government and private clients also have to be aware of health and safety issues, conflicts of interest and the possible financial and reputational risks of accepting a particular project.
The assessment must be a meticulous process in which the computer forensics expert must know as precisely as possible the background and the purpose of the expert analysis or audit to be carried out.
More about collection
If the acquisition is to be carried out on site and not in a computer forensics laboratory, this stage would include identifying devices that may store evidence and securing the scene where that evidence is collected. Interviews or meetings with staff who may hold information relevant to the examination (end users of the equipment, the manager, the person responsible for IT services, …) are generally held at this stage.
The collection stage also includes labeling and bagging evidence items on site, to be sealed in tamper-evident bags or envelopes. At Forenlab we have protective material for disks, cards and USB devices that is shock-proof, waterproof, etc., in order to guarantee transport of the material used to our forensic laboratory.
More about analysis
The analysis depends on the specific characteristics of each job. The computer forensics expert normally provides information to the client during the analysis and from this dialogue the analysis may take a different path or be narrowed to specific areas. The analysis must be accurate, complete, impartial, recorded and repeatable.
There are many tools available for forensic analysis. The main requirements of a computer forensics tool are that it does what it is supposed to do, and the only way for examiners to be sure of this is to test it regularly and calibrate the tools on which the analysis relies. It is well known in the industry that there are pseudo-professionals whose work consists solely of running an automated tool that produces standard reports without knowing what the results obtained are based on. Objectively, this kind of evidence always brings disastrous results for those who commission it, since in questioning at the hearing, if court proceedings are opened, the expert must be able to answer every question asked, justifying the results.
To verify that a tool works correctly, the dual-tool process is used (if the examiner’s tool “A” finds artifact “X” at position “Y”, then tool “B” must replicate these results).
More about review
As with the preparation stage, the review stage is often overlooked. This may be due to the perceived cost of doing work that is not billable, or the need to “move on”. However, building a review into every computer expert report can help save money and, above all, raise the quality of the report submitted by the computer forensics expert.
A review of an analysis can be simple, quick and can begin during any of the previous stages. Any lessons learned at this stage must be applied to the next examination and fed into the preparation stage.