Digital-Forensics-and-Analyzing-Data

Published on
Embed video
Share video
Ask about this video

Scene 1 (0s)

ooe. Digital Forensics and Analyzing Data. Digital forensics is the scientific acquisition, analysis, and preservation of data contained in electronic media whose information can be used as evidence in a court of law. It represents the most intricate part of cyber crime investigation, often yielding the strongest evidence..

Scene 2 (20s)

The Evolution of Computer Forensics. Traditional Methods.

Scene 3 (55s)

9-3. The Changing Landscape of Digital Evidence. Operating Systems.

Scene 4 (1m 23s)

Four Phases of Digital Forensics. Collection. Preservation of evidence for analysis through exact bit-stream copies of original media, protected by cryptographic hashing algorithms to ensure unaltered duplication..

Scene 5 (1m 53s)

Collection Challenges and Requirements. Traditional digital forensics best practices require making a full bit-stream copy of physical volumes. This normally entails physically removing hard drives from suspect systems and attaching them to another system for forensic duplication..

Scene 6 (2m 20s)

Nontraditional Devices Present New Challenges. Mobile Devices.

Scene 7 (2m 58s)

Enterprise Storage Systems. Corporate and government environments present storage systems ranging from multiterabytes to petabytes. A 20 terabyte SAN array creates considerable complexity for obtaining forensic images of physical drives and reassembling logical volumes..

Scene 8 (3m 31s)

Modern Forensic Challenges. Memory Acquisition. Memory analysis is increasingly needed for running systems, especially as systems can be compromised without accessing disk. Malware like Witty Worm exists only in memory. Without specialized hardware, true bit-by-bit memory imaging is impossible without affecting some data..

Scene 9 (4m 3s)

Examination and Analysis. Examination Phase. Examination consists of methodical sifting and combing of data—examining dates, metadata, images, document content, and more. The traditional forensic menu of keyword searches and automated scripts may miss key evidence..

Scene 10 (4m 38s)

Reporting: The Critical Final Phase. The report compiles all documentation, evidence from examinations, and analysis. It must contain documentation of all systems analyzed, tools used, and discoveries made, with dates, times, and detailed results..