A typical computer/ digital forensic investigation involves three main stages and every stage has some basic steps that is to be followed before proceeding to the next step. Let us take a look at these three stages of computer forensic investigation in detail.

1. Preparation Stage
Before the experts go to the crime scene, they should be prepared for that particular type of crime scene such as who should visit the scene for that particular type of crime , and what tools are appropriate for the examination because there are many types of scene of crime,and every case has its appropriate tools and methods to handle it.
2. At the Scene of Crime
The second step, which is collection and preservation, are strict set of procedures with guidelines that must be followed. It involves a variety of measures to preserve the state of the crime scene as much as possible, and limit the destruction of potential evidence.
The standard methodology for collecting the digital evidence, while maintaining its integrity, is to create an image of the device; not only does this protect the integrity of the original device, but it also gives leeway for any inadvertent error that could take place while analysis.
Preserving digital evidence is a key factor in identifying a suspect as the perpetrator of a crime,
especially when there is a risk that any known party might attempt to tamper with
evidence.
Let us now read the preliminary steps that need to be taken for mobile phones and storage devices.
Mobile Phones
1.If the device is in the off mode, do not turn it on for whatever reason.
2.If the device is on, do not turn it off, and carefully check the level of the battery to make sure it will arrive the lab before it dies; meanwhile, the following precautions should be taken:
(a) Isolate the network from the device by placing it on the flight mode if possible or placed in a network insulation.
(b) Record the information on the screen, or simply photograph it which is better.
(c) Find out the serial number of the device if possible, by entering the following code on the phone- * # 06 # or by opening the battery cover and you will find the number behind the battery or next to it inside of the phone device.
(d) Unplug the appliance from power source.
(e) When the device receives incoming calls at the time of seizure the mobile phone, immediately isolate its network, knowing that such data e.g. who is calling and why will add new information for the case, but may be at the expense of important information created immediately before the incident.
(f) The mobile device should be sent to the digital evidence lab and all other things associated such as the electrical connectors and data connectors should also be sent.
(g) If there is a security code on the mobile phone device, the suspect or the victim should be asked (if possible) to save time and effort during the examination.
Storage Media Device
If the storage media is connected to the computer or smartphones:
(a) Wait for a while until it finishes the process(copying).
(b) Label and write down the place of where we found it.
(c) Put it in custom boxes, and send it to the digital evidence lab.
If it is not connected to any equipment:
(a) We do the labeling and write down the place of where we found it.
(b) Put it in custom boxes, and send it to the digital evidence lab.
If the storage media is an external hard drive, its serial number must be recorded and photographed from the outside including the data cable which should be attached also if any.
3. Digital Evidence at Lab Stage
In the third stage which has four phases –
1.Examination,
2. Analysis,
3. Reconstruction, and
4. presentation
The investigator will search for useful evidences in the data acquired in the first stage.
Anything relevant to the case, including emails, photos, video, text messages, transaction log files, and more, is sought at this stage, and extracted from the total data recovered.
In most cases, digital evidence could be hidden or deleted. The actual process of discovering this information varies between investigations largely because of differences in the devices to recover and a suspect’s data-hiding techniques.
But common strategies exist, including:
• Keyword searches: It can be implemented both within files and unallocated/slack
space, where hidden data is most often located;
• Identifying blacklisted files by file signature (also called hash value);
• Recovering deleted files;
• Extracting registry information: For example, TypedURLs lists every URL the user has visited and typed into the browser URL bar;
• Analyzing log data.
When a crime occurs, investigators form many initial hypotheses about what happened and who may be responsible; as evidence is recovered in the first phase, they repeatedly cycle between that first phase, and the third: crime reconstruction.
The crime reconstruction phase is the process of reconstructing events or actions that happened, according to the evidence recovered. As investigators find more evidence, many incorrect hypotheses will unproven, while one (or, at most, a few) will become more and more plausible, and can eventually be proven entirely.
Finally, the last phase in this stage, called the presentation phase, is to prepare reports in order to communicate findings to the Court.
Leave a Reply