The Purpose of Computer Forensics Examination & Investigation

Computer forensics obtains, preserves, retrieves, and examines computer data usable as evidence in a court of law. Unlike many forensic disciplines, computer forensic science produces direct information rather than data that requires interpretation by analysts.

  1. How the Data is Used

    • Computer forensics can establish a timeline of events and determine malicious or criminal intent and activity.

    What Information is Examined

    • Investigators can establish what websites users visited, what data they copied from files, what files they deleted, and what applications they installed or uninstalled.

    Chronology

    • Not only can computer forensics can identify what users did on a computer, it can show when they did it.

    Importance of Data Preservation

    • Investigators must be careful to protect preserve digital data, which is highly susceptible to alteration, modification, deletion, and destruction. Computer analysts can also look at hidden files and retrieve deleted emails and files.

    Storage Media

    • Not only do investigators examine computers, they look at storage devices and media-like cameras, cell phones, servers, portable drives, and flash drives. They can also give testimony about their examination and investigation of the data in court.

Related Searches:

References

Comments

You May Also Like

Related Ads

Featured