官术网_书友最值得收藏!

Examination and analysis

This is the ultimate step of the investigation, and it aims to uncover data that is present on the device. Examination is done by applying well-tested and scientific methods to conclusively establish results. The analysis phase is focused on separating relevant data from the rest and probing for data that is of value to the underlying case. The examination process starts with a copy of the evidence acquired using some of the techniques described previously, which will be covered in detail in coming chapters. Examination and analysis using third-party tools is generally performed by importing the device's memory dump into a mobile forensics tool that will automatically retrieve the results. Understanding the case is also crucial to performing a targeted analysis of the data. For example, a case about child pornography may require focusing on all of the images present on the device rather than looking at other artifacts.

It is important that you have a fair knowledge of how the forensic tools that are used for examination work. Proficient use of the features and options available in a tool will drastically speed up the examination process. Sometimes, due to programming flaws in the software, a tool may not be able to recognize or convert bits into a format comprehensible by you. Hence, it is crucial that you have the necessary skills to identify such situations and use alternate tools or software to construct the results. In some cases, an individual may purposefully tamper with the device information or may delete/hide some crucial data. Forensic analysts should understand the limitations of their tools and sometimes compensate for them to achieve the best possible results. 

主站蜘蛛池模板: 通海县| 理塘县| 原平市| 栾城县| 宝丰县| 玛曲县| 大厂| 嘉义县| 台湾省| 桓仁| 台江县| 雅安市| 民乐县| 宁德市| 图片| 宁远县| 伽师县| 武宣县| 肇源县| 壤塘县| 台湾省| 章丘市| 且末县| 清原| 集贤县| 如东县| 东兰县| 明星| 昌图县| 呼伦贝尔市| 黄冈市| 宿松县| 呼和浩特市| 通山县| 巴楚县| 贵港市| 曲沃县| 双桥区| 金阳县| 建宁县| 汉中市|