The Personal Computer As Evidence
Expanded Course Outline
An 8 Hour Course of Instruction
- Important Background Information for a DOS/WINDOWS Computer
- Using the Directory and File Structure
- Investigating with DIR, the File Manager, or the Windows Explorer
- Understanding File Extensions
- Recognizing Standard and Unique Extensions
- Understanding the Booting Process
- Specifying Hardware Booby Traps
- Defining Software Booby Traps
- Behind the Scenes
- Defining Attributes
- Read-Only, Hidden, System,
- Discovering Hidden Files
- At the C: Prompt in DOS
- In the Windows 3.1 File Manager
- In the Windows 95-98 Explorer
- In the Windows NT
- With 3rd Party programs (e.g. Norton Utilities)
- Understanding Slack Space
- Understanding Free Space
- Understanding Hidden Disk Drives and Drive Partitions
- How to Discover Their Existence
- How to Analyze Their Contents
- What Really Happens During Information Discard
- Deletions - File Oriented
- Formatting - Drive Oriented
- Defragmentation - Drive Oriented
- Automatic Internet Storage Mechanisms
- Email Retention
- Graphic Image Retention
- URL Web Site Retention
- Computer Forensics Issues
- Recognizing Types of Files: Text, Graphic, Binary, Encrypted
- Viewing Contents of These Files
- How to Reconstruct File Contents When Possible
- Mirroring and Analytical Procedures
- Understanding the Mechanisms
- Obtaining Alternative Analytical Software
- Step by Step Procedures to Follow
- Using "Expert Witness" Software
- Using "Safeback" Software
- Using Shareware/Freeware
- Understanding Tradeoffs in the Software
- Hardware and Software Precautions to Take
- Initial Handling of Computer Systems and Storage Devices
- Safe Handling Techniques for Computers, Peripherals, and Storage
Media
- Chain of Custody Issues
- Avoiding Booby Traps
- Step by Step Avoidance Measures - Hardware
- Step by Step Avoidance Measures - Software
- Recovering Data After Attempted Information Discard
- Deletions - File Oriented
- Formatting - Drive Oriented
- Defragmentation - Drive Oriented
- Automatic Internet Storage Mechanisms
- Email Retention
- Graphic Image Retention
- URL Web Site Retention
- Legal and Effective Seizure Steps
- CAVEAT: Exercise Caution & Why
- USDOJ Seizure Protocols
- Issues in Warrant Creation
- Preventing the Loss of a Warrant
- Creating General Procedures in Your Dept.
- Analytical Steps for Hardware Assessment
- Determining All the System Parts
- Documenting System Components and Connections
- Deconstructing the System
- Looking for Additional Devices and Storage Media
- Dealing With MacIntosh Computers
- Understanding Structural Differences
- Using Alternatives for Mac Capture and Analysis Software
- Considerations in Mac Hardware Mirroring
- Internet Analysis Mechanisms
- Investigating Browser Cache Files
- Using the Browser History Files
- Exploring Computer and Web Usage Through Bookmark Analysis
- Tracking Newsgroup Usage
- Understanding How the Other Side Obtains Information About
You
- When you visit their web site
- When you send them an email
- When you visit a Chat Room
- When you join or post to a Newsgroup
- Discovering Email-Related Information
- Understanding the Headers
- Determining the Origin/Sender of the Email
- Revealing Fake IDs in the Email Transmission
- Backtracking to the Service Provider
- Presentation Tips for Reports and Testimony
- What to Include in Your Computer Analysis Reports
- Fundamental Protocols for Documentation
- Options for Organizing Computer Evidence
- What to Expect in Depositions and Trial Testimony
- How to Present Computer Evidence to a Lay Jury
Back to Main Computer Forensics Law Enforcement Seminar Page