Forensic Examination of Digital Evidence

28.06.2016 Views

James K. Pace Senior Special Agent Chief of Computer Forensics and Investigations U.S. Army Criminal Investigation Laboratory Forest Park, Georgia Scott R. Patronik Chief, Division of Technology and Advancement Erie County Sheriff’s Office Buffalo, New York Greg Redfern Director Department of Defense Computer Investigations Training Program Linthicum, Maryland Henry R. Reeve General Counsel Second Judicial District Denver, Colorado Jim Riccardi, Jr. Electronic Crime Specialist National Law Enforcement and Corrections Technology Center–Northeast Rome, New York Greg Schmidt Investigations/Technical Computer Forensics Examiner Plano, Texas Howard Schmidt Vice Chair President’s Critical Infrastructure Protection Board Washington, D.C. Raemarie Schmidt Computer Crimes Training Specialist National White Collar Crime Center Computer Crime Section Fairmont, West Virginia John A. Sgromolo President Digital Forensics, Inc. Clearwater, Florida George Sidor Sr. Computer Forensics Investigator G-Wag, Inc. St. Albert, Alberta Canada Mike Weil Computer Forensic Examiner DoD Computer Forensics Laboratory Linthicum, Maryland viii

Contents Foreword . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . iii Technical Working Group for the Examination of Digital Evidence. . . . . . . . . . v Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 Chapter 1. Policy and Procedure Development . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Chapter 2. Evidence Assessment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 Chapter 3. Evidence Acquisition . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 Chapter 4. Evidence Examination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 Chapter 5. Documenting and Reporting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 Appendix A. Case Examples . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23 Appendix B. Glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39 Appendix C. Sample Worksheets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43 Appendix D. Examples of Request for Service Forms . . . . . . . . . . . . . . . . . . . . . 51 Appendix E. Legal Resources List . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Appendix F. Technical Resources List . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61 Appendix G. Training Resources List . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83 Appendix H. List of Organizations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 87 ix

James K. Pace<br />

Senior Special Agent<br />

Chief <strong>of</strong> Computer <strong>Forensic</strong>s and<br />

Investigations<br />

U.S. Army Criminal Investigation<br />

Laboratory<br />

Forest Park, Georgia<br />

Scott R. Patronik<br />

Chief, Division <strong>of</strong> Technology and<br />

Advancement<br />

Erie County Sheriff’s Office<br />

Buffalo, New York<br />

Greg Redfern<br />

Director<br />

Department <strong>of</strong> Defense Computer<br />

Investigations Training Program<br />

Linthicum, Maryland<br />

Henry R. Reeve<br />

General Counsel<br />

Second Judicial District<br />

Denver, Colorado<br />

Jim Riccardi, Jr.<br />

Electronic Crime Specialist<br />

National Law Enforcement and Corrections<br />

Technology Center–Northeast<br />

Rome, New York<br />

Greg Schmidt<br />

Investigations/Technical<br />

Computer <strong>Forensic</strong>s Examiner<br />

Plano, Texas<br />

Howard Schmidt<br />

Vice Chair<br />

President’s Critical Infrastructure<br />

Protection Board<br />

Washington, D.C.<br />

Raemarie Schmidt<br />

Computer Crimes Training Specialist<br />

National White Collar Crime Center<br />

Computer Crime Section<br />

Fairmont, West Virginia<br />

John A. Sgromolo<br />

President<br />

<strong>Digital</strong> <strong>Forensic</strong>s, Inc.<br />

Clearwater, Florida<br />

George Sidor<br />

Sr. Computer <strong>Forensic</strong>s Investigator<br />

G-Wag, Inc.<br />

St. Albert, Alberta<br />

Canada<br />

Mike Weil<br />

Computer <strong>Forensic</strong> Examiner<br />

DoD Computer <strong>Forensic</strong>s Laboratory<br />

Linthicum, Maryland<br />

viii

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!