Elizabeth Sheldon is a director of Evidence Talks, One of the most highly regarded computer forensics consultancies in the UK, Evidence Talks lead the way with unique solutions to some of the problems faced by industry today. More information visit- evidencetalks.com
Turning on the computer
The biggest no-no. It writes large amounts of data to the hard disk, potentially wiping all traces of a deleted file forever. Data is automatically updated and therefore altered. Turning the computer on affects the swap file and registry as well as the list of most recently used documents. Dates when a file was created, last modified, last accessed and updated can all be unwittingly altered.
Investigating email with email
Investigating emails with an email client carries a host of potential dangers. Going into a suspect’s inbox in Outlook and reading an email which has not been opened before may create a read receipt, leaving a clear trace of the activity. Although often done to try and confirm suspicions, it can be considered tampering with the evidence.
Losing evidence
Failing to either make a forensic image of the hard drives of staff when they leave, or replace the hard drive and store the original, runs the risk of losing important data and therefore being unable to substantiate claims made at a later date.
Creating a copy of a person’s computer as it was when last used is key to preserving data.
DIY data recovery
Unskilled staff attempting to recover data from machines they suspect contain evidence is a big problem. Often, people can’t resist the urge to ‘have a quick look’ when an incident occurs. And although in many cases technical support will be called in, unfortunately, they will generally not have the specialist skills needed to investigate in an evidentially-sound manner. Correctly recovering data is expert work and should only be carried out by suitably qualified professionals.
Following evidential URLs
This is really dangerous territory. Apart from the risk of incriminating yourself — in the case of child abuse images you are essentially committing the same ‘offence’ as the suspect — there is also the possibility of compromising confidential data. You should never click on links in emails, even when they are from a supposedly trusted source.
Preserving digital evidence - Shutting down the PC
Simply, DON’T! Computers like to be very orderly, so when you shut down they will do a lot of ‘housekeeping’ — tidying up files, overwriting deleted information and changing times and dates which are vital to any investigation. If you have to turn the computer off, simply pull the plug. This freezes it and creates a ‘snapshot’ in time which can be forensically examined using a whole range of tools.
Jumping to conclusions
A common mistake when a computer crime is committed is to assume guilt and embark on a witch hunt for the culprit.
But is vital not to jump to conclusions. Just because there is incriminating material on somebody’s computer does not mean they put it there. Somebody else may have hacked their password, or it could have been a Trojan horse or other virus of which they had no knowledge, and therefore no control over.
Ignoring the evidence
Many ‘first responders’ will miss vital evidence by failing to follow correct procedures. Simply pulling the plug on the
computer will wipe the contents of RAM, which may contain useful information, particularly in cases of hacking or server damage. CDs, DVDs, digital cameras and personal organisers on a person’s desk are also often overlooked.
Incorrectly marked tapes
This is the bane of the life of a forensic analyst. It is extremely frustrating when investigating an incident to find that he data on a back-up tape is different from what is stated on the label. It is vital to have a data back-up and retention policy and be consistent in the implementation of it. Everyone involved in security must be aware of what their organisation’s back-up procedures are.
Being careless with evidence
Badly-handled evidence can stop a criminal investigation in its tracks. Evidence should always be carefully secured and then packaged with care. If not, fragile date can be damaged or even lost while stored or being transported. The evidence collection process should always begin with the creation of an incident log, in which the times and dates of any action taken are recorded.
- Related Videos
- Related Articles
- Ask / Related Q&A
- You can recover all your lost data with help of Computer forensics experts
- The Challenges Faced by the Computer Forensics Experts
- Computer Forensics Expert - An Ideal Career Option
- An Introduction to Computer Forensics
- Dealing With Computer Abuse Without Digging Bigger Holes!
- Computer Forensics - a Brief Introduction
- Understanding Computer Forensics Reports - A Loud Whisper!
- Divorce and Computer Evidence




DSi Download Center: A SCAM?
By: Sarah Brown | 29/12/2009If you've been looking for DSi games online, you've probably seen something about a site called the DSi Download Center. And you, like me, probably wondered if DSi Download Center is a scam or a legitimate deal ? Not too long ago I was online and doing a Google search for DSi games to download from some place other than the Nintendo store. Through my searches I came across a couple places that talked about the DSi Download Center.
LOCATE YOUR LAPTOP
By: seema bansal | 29/12/2009Laptop thefts are very common nowadays, spilling a lot of financial burden on not only the laptop owners, but also the insurance companies. With the increase in the laptop thefts, the increase in the piracy has also made the market injected with the curse of increase in the duplication of the products as well as the parts of the laptops. So to avoid all these not only to save your laptop, but also as a social cause, you need to take up something that will stop the laptop theft events.
Examsoon 000-296 practice test
By: Adela1987 | 29/12/2009Examsoon offers you a comprehensive certification test solution to help you become IBM certified professional. This certification preparation guide comes with free study guide, sample questions and answers, pdf exam, braindumps and answers lab that give you the experience of actual Storage Sales for IBM Certified Solution Designer exam. This preparation kit also contains study notes, 000-296 pdf, 000-296 download, 000-296 practice test and 000-296 review.
Spyware, what is it and how to prevent it
By: Jarvis Edwards | 29/12/2009This article will describe what spyware is and how to prevent it from appearing on your computer.
Avoiding Malware and Spyware Online
By: Bubba Vine | 27/12/2009Avoiding malware and spyware online is getting harder, its becoming more and more common and a lot of the time people get infected without even knowing.
Warning Signal For Freeware - Are You Alert For The Pains That May Come Forth
By: Jose Sogiros | 27/12/2009Computer Software security measures is not uniquely pertaining publishers. As Well, the user must be sensible of troubles that might originate when clicking done with the software permit agreements without properly interpreting them.
Network Security A practical guide
By: freepedia | 26/12/2009Network Security: a practical guide provides a comprehensive review of network security issues, with relevance to corporate networks, from both an administrative and user perspective.
Pass4side 9L0-509 study questions
By: Adela1987 | 26/12/2009Pass4side Practice Exams for Apple 9L0-509 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.Pass4side Apple 9L0-509 Preparation Diary is my own preparation guide, there is no guarantee you’ll pass the exam, just by reading the article. Keep the article as starting point, do more research, I put enough reference wherever required, so expand your reading with references mentioned. Good Luck.
Top 10 Ways People Damage Evidence
By: Elizabeth Sheldo | 03/08/2009 | SecurityTurning the computer on affects the swap file and registry as well as the list of most recently used documents. Investigating emails with an email client carries a host of potential dangers. Failing to either make a forensic image of the hard drives of staff when they leave, or replace the hard drive.
Showing Your Hand
By: Elizabeth Sheldo | 10/06/2009 | Computer ForensicsHaving imaged and analysed the suspects computer disks and found the evidence all that remains is the process of presenting that evidence for use in any criminal, civil or disciplinary hearings.
Protecting The Evidence
By: Elizabeth Sheldo | 10/06/2009 | Computer ForensicsIn court cases, computer evidence can be dismissed if even the slightest doubt over it's veracity can be shown, making the process of adducing the evidence correctly vital to the success of otherwise of the case.
Evidentially Sound Advice
By: Elizabeth Sheldo | 10/06/2009 | Computer ForensicsThe key role of computer forensics is the protection, adducing and presentation of evidence, in that order. In all abuse cases, protection of the evidence is both critical and central to the organisations ability to investigate and take action against the abuser.
Customize Your Own T-Shirt From Promopays.Ca
By: Elizabeth Sheldo | 10/06/2009 | Customer ServiceThe screen printed t-shirts available at this company are made using state of the art techniques and break through technologies to deliver the customers promotional t-shirts of their choice.