官术网_书友最值得收藏!

Digital evidence

As a normal reaction, the change in technology led to a change of possible evidence, as compared to previous traditional evidence. All the components of the computer system could be evidence, such as the following:

  • The hard drive of the criminal or the victim
  • The operating system artifacts and special files
  • The network traffic
  • The computer memory
  • Mobile phones and tablets
  • Cloud storage
  • Shared storage
  • Network devices
  • The systems' logs
  • The devices' logs
  • GPS devices
  • Simply, any device that can store or process data

Due to the wide range of possible evidence, the incident handler or first responder who will handle and process the available devices in the incident scene must have sufficient experience in dealing with whatever types of evidence they may find at the scene.

Handling digital devices is a very significant task, which the whole investigation process relies on. This is considered to be one of the main principal needs that have to be fulfilled in order to conduct successful digital analysis.

主站蜘蛛池模板: 宜昌市| 兰考县| 阳东县| 济源市| 乌拉特后旗| 崇左市| 花垣县| 西盟| 汝阳县| 台中市| 新津县| 邵东县| 专栏| 青州市| 平果县| 旬阳县| 吴忠市| 沁源县| 大同市| 延长县| 芦山县| 平南县| 新安县| 恩施市| 平阴县| 抚顺县| 高雄市| 兴安县| 铁岭县| 来宾市| 山西省| 广德县| 雅安市| 大宁县| 清河县| 靖安县| 疏勒县| 北川| 抚顺市| 永泰县| 湖北省|