Mandatory Conduct of Digital Forensic Examination on the - DIDM ...
Mandatory Conduct of Digital Forensic Examination on the - DIDM ...
Mandatory Conduct of Digital Forensic Examination on the - DIDM ...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />
Department ol<strong>the</strong> Interior and Local Government<br />
Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />
NATIONAL HEADQUARTERS, PHILIPPINE NATIONAL POLICE<br />
DIRECTORATE FOR INVESTIGATION AND DETECTIVE MANAGEMENT<br />
Camp Crame, Quez<strong>on</strong> City<br />
MEMORANDUM<br />
FOR<br />
FROM<br />
SUBJECT :<br />
DATE<br />
1. References:<br />
See Distributi<strong>on</strong><br />
01C, <strong>DIDM</strong>/TF USIG Commander<br />
<str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />
<strong>on</strong> <strong>the</strong> Recovered Cellular Ph<strong>on</strong>es, Computers, <str<strong>on</strong>g>Digital</str<strong>on</strong>g><br />
Storage Media, and o<strong>the</strong>r Electr<strong>on</strong>ic <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage<br />
Devices in All Cases Handled by SITG<br />
JUN 1 3 2012<br />
a. European Uni<strong>on</strong> — Philippines Justice Support Program (EPJUST);<br />
b. SOP Number 02/11 re: Procedures in <strong>the</strong> Creati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> Special<br />
Investigati<strong>on</strong> Task Group (SITG) to Handle Heinous and Sensati<strong>on</strong>al Crimes dated<br />
January 26, 2011; and<br />
c. Memo Directive from T<strong>DIDM</strong> re: <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> All<br />
Firearms, Shells and Slugs Recovered During Police Operati<strong>on</strong>s dated February 11,<br />
2011.<br />
d. Memo <str<strong>on</strong>g>of</str<strong>on</strong>g> CIDG re: Format for Request <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g>.<br />
2. This pertains to <strong>the</strong> recovered electr<strong>on</strong>ic evidence such as Cellular<br />
Ph<strong>on</strong>es, Computers, <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Media (Hard Disk Drives, USB Flash Drives, CD,<br />
DVD, etc.) and o<strong>the</strong>r electr<strong>on</strong>ic digital storage devices that may c<strong>on</strong>tain digital<br />
evidence that must be submitted to <strong>the</strong> Criminal Investigati<strong>on</strong> and Detecti<strong>on</strong> Group<br />
(CIDG), <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory for <strong>the</strong> c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />
and Analysis. The European Uni<strong>on</strong> (EU) experts thru <strong>the</strong> EPJUST program observed<br />
that <strong>the</strong> capability <str<strong>on</strong>g>of</str<strong>on</strong>g> CIDG in c<strong>on</strong>ducting digital forensic examinati<strong>on</strong>s is not being<br />
fully utilized in <strong>the</strong> investigati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> cases.<br />
3. The process will ensure <strong>the</strong> integrity <str<strong>on</strong>g>of</str<strong>on</strong>g> digital evidence as well as to<br />
prevent any accidental tampering <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> original evidence. The extracted informati<strong>on</strong><br />
may provide evidentiary value as well as indispensable leads in <strong>the</strong> identificati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g><br />
suspect(s).<br />
4. Please be informed also that <strong>the</strong> CIDG, as <str<strong>on</strong>g>of</str<strong>on</strong>g> this date has already six (6)<br />
functi<strong>on</strong>ing digital forensic laboratories which were strategically situated in <strong>the</strong><br />
following CIDG Offices with <strong>the</strong> attached capabilities to wit: (ANNEX-A)<br />
a CIDG Headquarters - Anti-Transnati<strong>on</strong>al and Cyber Crime Divisi<strong>on</strong><br />
b. 5 RCIDU - Camp Sime<strong>on</strong> A Ole, Legazpi City<br />
c. 7 RCIDU -- Cebu City, Police Provincial Office<br />
d. 9 RCIDU — Camp BataIla, Zamboanga City<br />
e. 11 RCIDU — Camp Domingo Le<strong>on</strong>or, Davao City<br />
f. 12 RCIDU — Camp Fermin Lira, General Santos City<br />
g. 10 RCIDU — Camp Alagar, Cagayan De Oro City - Forthcoming
5. Based <strong>on</strong> <strong>the</strong> foregoing, c<strong>on</strong>cerned PNP units/<str<strong>on</strong>g>of</str<strong>on</strong>g>fices are hereby directed<br />
to undertake <strong>the</strong> following directives:<br />
a. In all cases handled by SITG, c<strong>on</strong>cerned PNP units/<str<strong>on</strong>g>of</str<strong>on</strong>g>fices shall<br />
ensure that all recovered or seized electr<strong>on</strong>ic evidence such as Cellular Ph<strong>on</strong>es,<br />
Computers, <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Media ( Hard Disk Drives, USB Flash Drives, CD, DVD,<br />
etc.) and o<strong>the</strong>r electr<strong>on</strong>ic digital storage devices are forwarded to <strong>the</strong> Criminal<br />
Investigati<strong>on</strong> and Detecti<strong>on</strong> Group (CIDG), <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory for digital<br />
forensic examinati<strong>on</strong> at <strong>the</strong> so<strong>on</strong>est possible time taking into account <strong>the</strong> wea<strong>the</strong>r<br />
c<strong>on</strong>diti<strong>on</strong>, availability <str<strong>on</strong>g>of</str<strong>on</strong>g> transportati<strong>on</strong> and travel time from post to CIDG <str<strong>on</strong>g>of</str<strong>on</strong>g>fice<br />
operating a digital forensic laboratory.<br />
b. C<strong>on</strong>cerned PNP unit/<str<strong>on</strong>g>of</str<strong>on</strong>g>fice requesting digital forensic examinati<strong>on</strong> shall<br />
adhere to <strong>the</strong> policy, standards, and requirements set by <strong>the</strong> CIDG digital forensic<br />
laboratories. The requesting party should indicate <strong>on</strong> <strong>the</strong>ir request that <strong>the</strong> evidence<br />
to be submitted for digital forensic examinati<strong>on</strong> is handled by SITG and indicate<br />
priority <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> request. Requesting party shall also adopt <strong>the</strong> standard request<br />
memorandum format and completely fill-up all necessary forms given by <strong>the</strong> CIDG<br />
digital forensic laboratories. (ANNEX-B)<br />
c. Up<strong>on</strong> completi<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> digital forensic examinati<strong>on</strong>, <strong>the</strong> CIDG should<br />
immediately notify <strong>the</strong> requesting party within 24 hours using <strong>the</strong> fastest means <str<strong>on</strong>g>of</str<strong>on</strong>g><br />
communicati<strong>on</strong> available but not limited to such as: Email, SMS text, or by teleph<strong>on</strong>e<br />
that <strong>the</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g>ficial result <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> digital forensic examinati<strong>on</strong> is already available for<br />
release to <strong>the</strong> requesting party.<br />
d. The requesting party shall pick-up <strong>the</strong> report <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> digital forensic<br />
examinati<strong>on</strong> within five (5) days up<strong>on</strong> receipt <str<strong>on</strong>g>of</str<strong>on</strong>g> said notice or such l<strong>on</strong>ger period,<br />
taking into account <strong>the</strong> wea<strong>the</strong>r c<strong>on</strong>diti<strong>on</strong>, availability <str<strong>on</strong>g>of</str<strong>on</strong>g> transportati<strong>on</strong> and <strong>the</strong> travel<br />
time from post to CIDG <str<strong>on</strong>g>of</str<strong>on</strong>g>fice.<br />
6. This directive shall be applicable <strong>on</strong>ly <strong>on</strong> cases handled by Special<br />
Investigati<strong>on</strong> Task Group (SITG) c<strong>on</strong>sidering <strong>the</strong> manpower and financial<br />
requirements it would entail.<br />
7. In additi<strong>on</strong>, this directive shall not prevent PNP Crime Laboratory from<br />
c<strong>on</strong>ducting all available and applicable forensic examinati<strong>on</strong>s, relevant to <strong>the</strong> crime<br />
committed, <strong>on</strong> <strong>the</strong> recovered electr<strong>on</strong>ic evidence.<br />
8. Fur<strong>the</strong>r, it is imperative that <strong>the</strong> rule <strong>on</strong> chain <str<strong>on</strong>g>of</str<strong>on</strong>g> custody be strictly and<br />
meticulously observed.<br />
9. For strict compliance and widest disseminati<strong>on</strong>.<br />
Distributi<strong>on</strong>:<br />
RDs, PROs<br />
Dirs, NOSUs<br />
Copy Furnished:<br />
Command Group<br />
D-Staff<br />
CHRIST ii PHE A LAXA, CSEE<br />
Police senior Superintendent
Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />
Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />
Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />
NATIONAL HEADUARTERS, PHILIPPINE NATIONAL POLICE<br />
QESTIGATION AND DETECTIVE MANAGEMENT<br />
DIRECTOR ATE FOR INV<br />
Camp Crame, Quez<strong>on</strong> City<br />
MEMORANDUM<br />
FOR<br />
FROM<br />
SUBJECT<br />
DATE<br />
1. References:<br />
a.<br />
Director, CIDG<br />
01C, DIDWTF USIG Commander<br />
Proposed <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g><br />
<str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <strong>on</strong> <strong>the</strong> Recovered Cellular Ph<strong>on</strong>es,<br />
Laptops and O<strong>the</strong>r Electr<strong>on</strong>ic <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Devices<br />
in All Cases Handled by SITG<br />
MAY 2 4 2012<br />
European Uni<strong>on</strong> — Philippines Justice Support Program (EPJUST);<br />
SOP Number 02/11 re: Procedures in <strong>the</strong> Creati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> Special<br />
b.<br />
Investigati<strong>on</strong> Task Group (SITG) to Handle Heinous and Sensati<strong>on</strong>al Crimes dated<br />
January 26, 2011; and<br />
Memo Directive from T<strong>DIDM</strong> re: <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> All<br />
c.<br />
Firearms, Shells and Slugs Recovered During Police Operati<strong>on</strong>s dated February 11,<br />
2011.<br />
This pertains to <strong>the</strong> recovered cellular ph<strong>on</strong>es (CPs), laptops and o<strong>the</strong>r<br />
2.<br />
electr<strong>on</strong>ic digital storage devices which must be submitted to your Office for <strong>the</strong><br />
c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> digital forensic examinati<strong>on</strong>. The European Uni<strong>on</strong> (EU) experts thru <strong>the</strong><br />
EPJUST program observed that <strong>the</strong> capability <str<strong>on</strong>g>of</str<strong>on</strong>g> CG ID in c<strong>on</strong>ducting digital forensic<br />
<str<strong>on</strong>g>of</str<strong>on</strong>g> cases.<br />
examinati<strong>on</strong> is not being fully utilized in <strong>the</strong> investigati<strong>on</strong><br />
C<strong>on</strong>sidering that not all investigators are aware <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> capability <str<strong>on</strong>g>of</str<strong>on</strong>g> your<br />
3.<br />
<str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory to retrieve deleted messages, documents, pictures, etc.<br />
which might be used as possible leads in <strong>the</strong> investigati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> cases, this Directorate<br />
plans to issue a memo-directive that will make <strong>the</strong> c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> digital forensic<br />
examinati<strong>on</strong>s <strong>on</strong> <strong>the</strong> recovered CPs, laptops and o<strong>the</strong>r electr<strong>on</strong>ic digital storage<br />
devices mandatory. Attached is a copy <str<strong>on</strong>g>of</str<strong>on</strong>g> said draft memo-directive. (Tab A)<br />
2012 .<br />
4.<br />
ITCON, kindly submit comments/inputs regarding this matter NLT May 30,<br />
CENTEP CHRIST HER A LAXA, CSEE<br />
Police -nior Superintendent<br />
.(n) •<br />
-6/1/-)
MEMORANDUM<br />
Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />
Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />
Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />
PHILIPPINE NATIONAL POLICE<br />
CRIMINAL INVESTIGATION AND DETECTION GROUP<br />
Camp Crame, Quez<strong>on</strong> City<br />
FOR 01C, <strong>DIDM</strong>/TF USIG Commander<br />
FROM Director, CIDG<br />
SUBJECT<br />
DATE June 7, 2012<br />
Proposed <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g><br />
<str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <strong>on</strong> <strong>the</strong> Recovered Cellular Ph<strong>on</strong>es, Laptops<br />
and O<strong>the</strong>r Electr<strong>on</strong>ic <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Devices in All Cases<br />
Handled By SITG<br />
1. Reference : Memo from 01C, <strong>DIDM</strong>/TF USIG Commander<br />
dated May 24, 2012, with subject same as above.<br />
2. In c<strong>on</strong>necti<strong>on</strong> with <strong>the</strong> above reference, attached is <strong>the</strong> proposed<br />
draft for mandatory c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> digital forensic examinati<strong>on</strong> <strong>on</strong> <strong>the</strong> recovered<br />
cellular ph<strong>on</strong>es, laptops and o<strong>the</strong>r electr<strong>on</strong>ic digital storage devices in all cases<br />
handled by SITG and necessary form needed by all <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratories<br />
to be filled-up by requesting parties.<br />
3. Request acknowledge receipt.<br />
FOR THE DIRECTOR, CIDG:<br />
GILBERT CAASI SA, PESE, MCSE, EnCE<br />
Police Senior Su erintendent (DSC)<br />
n<br />
ry,
Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />
Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />
Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />
PHILIPPINE NATIONAL POLICE<br />
CRIMINAL INVESTIGATION AND DETECTION GROUP<br />
ANTI-TRANSNATIONAL AND CYBER CRIME DIVISION<br />
Camp Crame, Quez<strong>on</strong> City<br />
<str<strong>on</strong>g>Digital</str<strong>on</strong>g> and Electr<strong>on</strong>ic <str<strong>on</strong>g>Forensic</str<strong>on</strong>g>s Laboratory<br />
Capabilities<br />
n Cyber Crime Incident Resp<strong>on</strong>se (Handling <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Evidence)<br />
o Recover volatile data currently running <strong>on</strong> <strong>the</strong> computer system and<br />
network;<br />
o Analyze volatile data recovered during incident resp<strong>on</strong>se<br />
o<br />
procedure; and<br />
<str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> search and seizure <str<strong>on</strong>g>of</str<strong>on</strong>g> electr<strong>on</strong>ic evidence found in <strong>the</strong><br />
computer crime scene.<br />
n Computer <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> and Analysis<br />
o Using internati<strong>on</strong>al standard hardware and s<str<strong>on</strong>g>of</str<strong>on</strong>g>tware for computer<br />
forensic examinati<strong>on</strong> such as <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Computers, Tableau Write<br />
Blockers, EnCase, <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Tool Kit (FTK), and FTK Imager;<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> digital media forensic imaging and au<strong>the</strong>nticati<strong>on</strong>;<br />
o Recover and analyze operating system artifacts;<br />
o Recover deleted files and folders, Internet history files, Internet<br />
cache files, and email artifacts from computer system storage<br />
media;<br />
o Access some encrypted and password protected files<br />
o Analyze files metadata and properties;<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> file system analysis (FAT, NTFS, HFS+, EXT2);<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> hash value analysis and file signature analysis;<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> live acquisiti<strong>on</strong> forensic imaging; and<br />
o Provide <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> Reports.<br />
n Cellph<strong>on</strong>e <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />
o Using internati<strong>on</strong>al standard Cellph<strong>on</strong>e forensic hardware and<br />
s<str<strong>on</strong>g>of</str<strong>on</strong>g>tware such as Cellebrite UFED/PA, XRY/XACT, EnCase<br />
Neutrino, SimC<strong>on</strong>, Data Pilot, Fernico ZRT, and Mobile Edit<br />
applicati<strong>on</strong>;<br />
o Recover deleted text messages (SMS and MMS);<br />
o Recover deleted files from Cellph<strong>on</strong>e storage media;<br />
o Recover Ph<strong>on</strong>e Book, C<strong>on</strong>tacts, Dialed Numbers, Received Calls<br />
and Miss Calls; and<br />
o Generate Cellph<strong>on</strong>e <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> Reports.<br />
Computer Crime Unit — Capabilities<br />
Page 1
n Computer Network Logs and Stego Analysis<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> network logs analysis;<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Malware analysis; and<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Steganography analysis.<br />
n Training<br />
n<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Cyber Crime Incident Resp<strong>on</strong>se and <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Evidence<br />
Handling Training;<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Computer <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Training; and<br />
o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Cyber Crime Awareness Training<br />
Serve as an expert witness in court proceedings c<strong>on</strong>cerning digital<br />
evidence.<br />
Computer Crime Unit — Capabilities<br />
Page 2
MEMORANDUM<br />
FOR<br />
FROM<br />
SUBJECT<br />
DATE<br />
1.<br />
uepartment or we interior anu Local L'overrirnent<br />
NATIONAL POLICE COMMISSION<br />
PHILIPPINE NATIONAL POLICE<br />
References:<br />
Director, CIDG<br />
(Attn: C, ATCCD)<br />
Request for <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />
2. Request that Anti-Transnati<strong>on</strong>al and Cyber Crime Divisi<strong>on</strong> (ATCCD),<br />
CIDG c<strong>on</strong>duct digital forensic examinati<strong>on</strong> <strong>on</strong> <strong>the</strong> accompanying specimen specifically<br />
describe <strong>on</strong> <strong>the</strong> attached <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> Request Form.<br />
3.<br />
Background <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> case with <strong>the</strong> following informati<strong>on</strong>:<br />
a) NATURE OF CASE<br />
b) VICTIM<br />
c) SUSPECT<br />
d) TDPO<br />
4. Facts <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Case:<br />
5.<br />
forensi • , n111,41...s .4..w.v......<br />
Herewith is/are <strong>the</strong> required storage media necessary for <strong>the</strong> digital<br />
Submitted <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Media for<br />
<str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />
Cellular Ph<strong>on</strong>e<br />
Computer System Unit /<br />
Hard Drive and o<strong>the</strong>r storage<br />
media.<br />
Required Storage Media<br />
2 pcs. DVD-R with Case<br />
External Storage Media or Hard Drive, which<br />
capacity must be twice <strong>the</strong> capacity <str<strong>on</strong>g>of</str<strong>on</strong>g> evidence<br />
submitted storage media.<br />
6. The bearer <str<strong>on</strong>g>of</str<strong>on</strong>g> this request is investigator-<strong>on</strong> case.<br />
Note:<br />
a. (For cases from Regi<strong>on</strong> 3, 4a, and NCR must be delivered<br />
pers<strong>on</strong>ally by <strong>the</strong> investigator-<strong>on</strong> case.),<br />
b. (For cases from o<strong>the</strong>r Regi<strong>on</strong>s preferably delivered by<br />
investigator-<strong>on</strong> case or <str<strong>on</strong>g>of</str<strong>on</strong>g>ficial Liais<strong>on</strong> Officer.)<br />
7. Fur<strong>the</strong>r request that this Office be furnished a copy <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> ATCCD digital<br />
forensic examinati<strong>on</strong> result for our reference.<br />
(CHIEF OF OFFICE)
Lab Case #:<br />
REPUBLIC OF THE PHILIPPINES<br />
Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />
Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />
PHILIPPINE NATIONAL POLICE<br />
CRIMINAL INVESTIGATION AND DETECTION GROUP<br />
ANTI-TRANSNATIONAL AND CYBER CRIME DIVISION<br />
Camp Crame, Quez<strong>on</strong> City<br />
Submitting/Requesting Agency:<br />
Agency Address:<br />
C<strong>on</strong>tact Official/Investigator:<br />
Type/Print:<br />
Signature:<br />
Type/Print:<br />
Signature:<br />
<str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory<br />
EVIDENCE CUSTODY FORM<br />
CHAIN OF CUSTODY<br />
Item # Date/Time Received From: Received By: Reas<strong>on</strong>:<br />
Type/Print:<br />
Signature:<br />
Type/Print:<br />
Signature:<br />
Date/Time:<br />
Agency Case #:<br />
Nature <str<strong>on</strong>g>of</str<strong>on</strong>g> Crime/s:<br />
C<strong>on</strong>tact #:
A. Request For:<br />
Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />
Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />
Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />
PHILIPPINE NATIONAL POLICE<br />
CRIMINAL INVESTIGATION AND DETECTION GROUP<br />
ANTI-TRANSNATIONAL AND CYBER CRIME DIVISION<br />
Camp Crame, Quez<strong>on</strong> City<br />
!SECTION III: COURT/SUSPECT/S INFORMATION<br />
A. Prosecutor Assign( d: (last, first)<br />
B. Ph<strong>on</strong>e Number:<br />
D. Suspect/s Name: ( 3st, first)<br />
<str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory<br />
REQUEST FOR DIGITAL FORENSICS ASSISTANCE<br />
q Lab: q On-site q Technical Assistance q Training<br />
q O<strong>the</strong>rs:<br />
B. Mode <str<strong>on</strong>g>of</str<strong>on</strong>g> Request:<br />
q Initial (Original agency investigati<strong>on</strong>) q Follow-up (Prosecutor follow-up request)<br />
q O<strong>the</strong>rs:<br />
SECTION II: CASE INFORMATION<br />
A. Submitting Agency: B. Date: C. Time:<br />
D. Agency Address:<br />
E. Agency Case Number:<br />
G. Legal Authority:<br />
q<br />
I<br />
q<br />
q<br />
Search Warrant<br />
Court Order<br />
C<strong>on</strong>sent to Search<br />
O<strong>the</strong>rs*<br />
F. Nature <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Crime/s:<br />
Note:<br />
Provide a copy <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Search Warrant,<br />
Affidavit, Written C<strong>on</strong>sent, C<strong>on</strong>sent<br />
Acknowledgement Form, and Synopsis <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong><br />
case or o<strong>the</strong>r Documentati<strong>on</strong>.<br />
H. Investigators Name: (last, first) I. Cellph<strong>on</strong>e Number: J. Office Number:<br />
K. Investigators Email:<br />
L. Is Investigator ISDE Trained?<br />
E. In custody/Detained:<br />
ECTION IV: EVIDENCE INFORMATION<br />
A. Search/Seized/ C B. Time: C. Locati<strong>on</strong>:<br />
q Yes q No<br />
C. Email Address:<br />
q Yes No
D. Items to be Examined:<br />
It #: Type <str<strong>on</strong>g>of</str<strong>on</strong>g> Items/Media Descripti<strong>on</strong> (make &<br />
model)<br />
Serial Numbers<br />
E. Has any<strong>on</strong>e viewed/examined/accessed this evidence prior to submissi<strong>on</strong>?<br />
q Yes *<br />
F. List any <str<strong>on</strong>g>Digital</str<strong>on</strong>g><br />
q No<br />
<str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Lab members c<strong>on</strong>sulted:<br />
G. Special Handling: (check all that apply)<br />
q Bio Hazard q Classified Material<br />
q Suspected Terrorism q O<strong>the</strong>rs:<br />
Financial Records<br />
* Internet History and<br />
log files<br />
*Email/IM/Text<br />
Messages<br />
C<strong>on</strong>tact Lists<br />
Call History<br />
* Clarificati<strong>on</strong> and comments<br />
*<br />
q Drug Related q Nati<strong>on</strong>al Interest<br />
Please identify <strong>the</strong> types <str<strong>on</strong>g>of</str<strong>on</strong>g> evidence/informati<strong>on</strong> to be searched for! recovered:<br />
q q q q q<br />
Word Processing /Text<br />
Documents<br />
Credit Card info/Checkwriting<br />
programs<br />
Child Pornography<br />
Images<br />
Owner Informati<strong>on</strong><br />
q q q q q<br />
(O<strong>the</strong>r/Keywords — Please be specific)<br />
If child pornography images are found during <strong>the</strong> course <str<strong>on</strong>g>of</str<strong>on</strong>g> an examinati<strong>on</strong>, <strong>the</strong> examiner will:<br />
1. Use a hard drive duplicator from <strong>the</strong> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Lab to duplicate <strong>the</strong> original hard drive.<br />
2. Replace <strong>the</strong> original drive with a duplicate hard drive <str<strong>on</strong>g>of</str<strong>on</strong>g> equal or greater size.<br />
3. Remove all child pornography from <strong>the</strong> duplicate hard drive (which will remain <strong>on</strong>-site or will be<br />
returned to <strong>the</strong> victim/suspect (when required to do so)).<br />
4. Maintain <strong>the</strong> original hard drive and imaile in <strong>the</strong> Di , ital <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Lab for anal sis.<br />
SECTION VI: REQUESTING CASE AGENT /INVESTIGATOR CONFIRMATION<br />
A. Rank / Name /Tit e:<br />
1:1*111•1 n VII •<br />
A. Lab Case #:<br />
B. Signature:<br />
BlIclifil NZ :4 4Z KitallWamcgixki g 1%<br />
Process Rank/Name Signature Time/Date<br />
B. Received by<br />
C. Assigned by<br />
D. Assigned to<br />
E. Priority<br />
F. Lab Case Status<br />
q Imaging q <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g>/Analysis q Report Submitted<br />
q Archived q Pulled out<br />
Remarks: