DIG4EVIDENCE
INVESTIGATING
COMPUTER FORENSICS
HIGH TECH INVESTIGATIONS
DIGITAL FORENSICS
About Us
What is Computer Forensics?
Computer Forensics is the collection, preservation, analysis, and presentation of computer and digital
related evidence. Computer evidence as it relates to criminal and civil cases, corporate civil litigation, and internal employee investigations.
Far more information is retained on a computer than most people realize. It's also more difficult to completely remove information
than is generally thought. For these reasons (and many more), computer forensics can often find evidence of, or even completely recover,
lost or deleted information, even if it was intentionally deleted.
What are the common scenarios?
- Employee Internet abuse
- Unauthorized disclosure of corporate information and data (accidental and intentional)
- Industrial espionage
- Damage assessment (following an incident)
- Criminal fraud and deception cases - More
general criminal cases
How is a computer forensic investigation approached?
Secure
the subject system (from tampering during the operation)
Access/copy hidden, protected and temporary
files
Investigate data/settings from installed applications/programs
Take a copy of hard drive
(if applicable) Identify and recover all files (including those deleted)
Study 'special' areas on the drive (eg:
residue from previously deleted files)
Assess the system , including its structure; consider general factors relating
to the users activity; create a detailed report