11.01.2013 Views

Mandatory Conduct of Digital Forensic Examination on the - DIDM ...

Mandatory Conduct of Digital Forensic Examination on the - DIDM ...

Mandatory Conduct of Digital Forensic Examination on the - DIDM ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />

Department ol<strong>the</strong> Interior and Local Government<br />

Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />

NATIONAL HEADQUARTERS, PHILIPPINE NATIONAL POLICE<br />

DIRECTORATE FOR INVESTIGATION AND DETECTIVE MANAGEMENT<br />

Camp Crame, Quez<strong>on</strong> City<br />

MEMORANDUM<br />

FOR<br />

FROM<br />

SUBJECT :<br />

DATE<br />

1. References:<br />

See Distributi<strong>on</strong><br />

01C, <strong>DIDM</strong>/TF USIG Commander<br />

<str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />

<strong>on</strong> <strong>the</strong> Recovered Cellular Ph<strong>on</strong>es, Computers, <str<strong>on</strong>g>Digital</str<strong>on</strong>g><br />

Storage Media, and o<strong>the</strong>r Electr<strong>on</strong>ic <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage<br />

Devices in All Cases Handled by SITG<br />

JUN 1 3 2012<br />

a. European Uni<strong>on</strong> — Philippines Justice Support Program (EPJUST);<br />

b. SOP Number 02/11 re: Procedures in <strong>the</strong> Creati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> Special<br />

Investigati<strong>on</strong> Task Group (SITG) to Handle Heinous and Sensati<strong>on</strong>al Crimes dated<br />

January 26, 2011; and<br />

c. Memo Directive from T<strong>DIDM</strong> re: <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> All<br />

Firearms, Shells and Slugs Recovered During Police Operati<strong>on</strong>s dated February 11,<br />

2011.<br />

d. Memo <str<strong>on</strong>g>of</str<strong>on</strong>g> CIDG re: Format for Request <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g>.<br />

2. This pertains to <strong>the</strong> recovered electr<strong>on</strong>ic evidence such as Cellular<br />

Ph<strong>on</strong>es, Computers, <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Media (Hard Disk Drives, USB Flash Drives, CD,<br />

DVD, etc.) and o<strong>the</strong>r electr<strong>on</strong>ic digital storage devices that may c<strong>on</strong>tain digital<br />

evidence that must be submitted to <strong>the</strong> Criminal Investigati<strong>on</strong> and Detecti<strong>on</strong> Group<br />

(CIDG), <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory for <strong>the</strong> c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />

and Analysis. The European Uni<strong>on</strong> (EU) experts thru <strong>the</strong> EPJUST program observed<br />

that <strong>the</strong> capability <str<strong>on</strong>g>of</str<strong>on</strong>g> CIDG in c<strong>on</strong>ducting digital forensic examinati<strong>on</strong>s is not being<br />

fully utilized in <strong>the</strong> investigati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> cases.<br />

3. The process will ensure <strong>the</strong> integrity <str<strong>on</strong>g>of</str<strong>on</strong>g> digital evidence as well as to<br />

prevent any accidental tampering <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> original evidence. The extracted informati<strong>on</strong><br />

may provide evidentiary value as well as indispensable leads in <strong>the</strong> identificati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g><br />

suspect(s).<br />

4. Please be informed also that <strong>the</strong> CIDG, as <str<strong>on</strong>g>of</str<strong>on</strong>g> this date has already six (6)<br />

functi<strong>on</strong>ing digital forensic laboratories which were strategically situated in <strong>the</strong><br />

following CIDG Offices with <strong>the</strong> attached capabilities to wit: (ANNEX-A)<br />

a CIDG Headquarters - Anti-Transnati<strong>on</strong>al and Cyber Crime Divisi<strong>on</strong><br />

b. 5 RCIDU - Camp Sime<strong>on</strong> A Ole, Legazpi City<br />

c. 7 RCIDU -- Cebu City, Police Provincial Office<br />

d. 9 RCIDU — Camp BataIla, Zamboanga City<br />

e. 11 RCIDU — Camp Domingo Le<strong>on</strong>or, Davao City<br />

f. 12 RCIDU — Camp Fermin Lira, General Santos City<br />

g. 10 RCIDU — Camp Alagar, Cagayan De Oro City - Forthcoming


5. Based <strong>on</strong> <strong>the</strong> foregoing, c<strong>on</strong>cerned PNP units/<str<strong>on</strong>g>of</str<strong>on</strong>g>fices are hereby directed<br />

to undertake <strong>the</strong> following directives:<br />

a. In all cases handled by SITG, c<strong>on</strong>cerned PNP units/<str<strong>on</strong>g>of</str<strong>on</strong>g>fices shall<br />

ensure that all recovered or seized electr<strong>on</strong>ic evidence such as Cellular Ph<strong>on</strong>es,<br />

Computers, <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Media ( Hard Disk Drives, USB Flash Drives, CD, DVD,<br />

etc.) and o<strong>the</strong>r electr<strong>on</strong>ic digital storage devices are forwarded to <strong>the</strong> Criminal<br />

Investigati<strong>on</strong> and Detecti<strong>on</strong> Group (CIDG), <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory for digital<br />

forensic examinati<strong>on</strong> at <strong>the</strong> so<strong>on</strong>est possible time taking into account <strong>the</strong> wea<strong>the</strong>r<br />

c<strong>on</strong>diti<strong>on</strong>, availability <str<strong>on</strong>g>of</str<strong>on</strong>g> transportati<strong>on</strong> and travel time from post to CIDG <str<strong>on</strong>g>of</str<strong>on</strong>g>fice<br />

operating a digital forensic laboratory.<br />

b. C<strong>on</strong>cerned PNP unit/<str<strong>on</strong>g>of</str<strong>on</strong>g>fice requesting digital forensic examinati<strong>on</strong> shall<br />

adhere to <strong>the</strong> policy, standards, and requirements set by <strong>the</strong> CIDG digital forensic<br />

laboratories. The requesting party should indicate <strong>on</strong> <strong>the</strong>ir request that <strong>the</strong> evidence<br />

to be submitted for digital forensic examinati<strong>on</strong> is handled by SITG and indicate<br />

priority <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> request. Requesting party shall also adopt <strong>the</strong> standard request<br />

memorandum format and completely fill-up all necessary forms given by <strong>the</strong> CIDG<br />

digital forensic laboratories. (ANNEX-B)<br />

c. Up<strong>on</strong> completi<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> digital forensic examinati<strong>on</strong>, <strong>the</strong> CIDG should<br />

immediately notify <strong>the</strong> requesting party within 24 hours using <strong>the</strong> fastest means <str<strong>on</strong>g>of</str<strong>on</strong>g><br />

communicati<strong>on</strong> available but not limited to such as: Email, SMS text, or by teleph<strong>on</strong>e<br />

that <strong>the</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g>ficial result <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> digital forensic examinati<strong>on</strong> is already available for<br />

release to <strong>the</strong> requesting party.<br />

d. The requesting party shall pick-up <strong>the</strong> report <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> digital forensic<br />

examinati<strong>on</strong> within five (5) days up<strong>on</strong> receipt <str<strong>on</strong>g>of</str<strong>on</strong>g> said notice or such l<strong>on</strong>ger period,<br />

taking into account <strong>the</strong> wea<strong>the</strong>r c<strong>on</strong>diti<strong>on</strong>, availability <str<strong>on</strong>g>of</str<strong>on</strong>g> transportati<strong>on</strong> and <strong>the</strong> travel<br />

time from post to CIDG <str<strong>on</strong>g>of</str<strong>on</strong>g>fice.<br />

6. This directive shall be applicable <strong>on</strong>ly <strong>on</strong> cases handled by Special<br />

Investigati<strong>on</strong> Task Group (SITG) c<strong>on</strong>sidering <strong>the</strong> manpower and financial<br />

requirements it would entail.<br />

7. In additi<strong>on</strong>, this directive shall not prevent PNP Crime Laboratory from<br />

c<strong>on</strong>ducting all available and applicable forensic examinati<strong>on</strong>s, relevant to <strong>the</strong> crime<br />

committed, <strong>on</strong> <strong>the</strong> recovered electr<strong>on</strong>ic evidence.<br />

8. Fur<strong>the</strong>r, it is imperative that <strong>the</strong> rule <strong>on</strong> chain <str<strong>on</strong>g>of</str<strong>on</strong>g> custody be strictly and<br />

meticulously observed.<br />

9. For strict compliance and widest disseminati<strong>on</strong>.<br />

Distributi<strong>on</strong>:<br />

RDs, PROs<br />

Dirs, NOSUs<br />

Copy Furnished:<br />

Command Group<br />

D-Staff<br />

CHRIST ii PHE A LAXA, CSEE<br />

Police senior Superintendent


Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />

Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />

Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />

NATIONAL HEADUARTERS, PHILIPPINE NATIONAL POLICE<br />

QESTIGATION AND DETECTIVE MANAGEMENT<br />

DIRECTOR ATE FOR INV<br />

Camp Crame, Quez<strong>on</strong> City<br />

MEMORANDUM<br />

FOR<br />

FROM<br />

SUBJECT<br />

DATE<br />

1. References:<br />

a.<br />

Director, CIDG<br />

01C, DIDWTF USIG Commander<br />

Proposed <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g><br />

<str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <strong>on</strong> <strong>the</strong> Recovered Cellular Ph<strong>on</strong>es,<br />

Laptops and O<strong>the</strong>r Electr<strong>on</strong>ic <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Devices<br />

in All Cases Handled by SITG<br />

MAY 2 4 2012<br />

European Uni<strong>on</strong> — Philippines Justice Support Program (EPJUST);<br />

SOP Number 02/11 re: Procedures in <strong>the</strong> Creati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> Special<br />

b.<br />

Investigati<strong>on</strong> Task Group (SITG) to Handle Heinous and Sensati<strong>on</strong>al Crimes dated<br />

January 26, 2011; and<br />

Memo Directive from T<strong>DIDM</strong> re: <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> All<br />

c.<br />

Firearms, Shells and Slugs Recovered During Police Operati<strong>on</strong>s dated February 11,<br />

2011.<br />

This pertains to <strong>the</strong> recovered cellular ph<strong>on</strong>es (CPs), laptops and o<strong>the</strong>r<br />

2.<br />

electr<strong>on</strong>ic digital storage devices which must be submitted to your Office for <strong>the</strong><br />

c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> digital forensic examinati<strong>on</strong>. The European Uni<strong>on</strong> (EU) experts thru <strong>the</strong><br />

EPJUST program observed that <strong>the</strong> capability <str<strong>on</strong>g>of</str<strong>on</strong>g> CG ID in c<strong>on</strong>ducting digital forensic<br />

<str<strong>on</strong>g>of</str<strong>on</strong>g> cases.<br />

examinati<strong>on</strong> is not being fully utilized in <strong>the</strong> investigati<strong>on</strong><br />

C<strong>on</strong>sidering that not all investigators are aware <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> capability <str<strong>on</strong>g>of</str<strong>on</strong>g> your<br />

3.<br />

<str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory to retrieve deleted messages, documents, pictures, etc.<br />

which might be used as possible leads in <strong>the</strong> investigati<strong>on</strong> <str<strong>on</strong>g>of</str<strong>on</strong>g> cases, this Directorate<br />

plans to issue a memo-directive that will make <strong>the</strong> c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> digital forensic<br />

examinati<strong>on</strong>s <strong>on</strong> <strong>the</strong> recovered CPs, laptops and o<strong>the</strong>r electr<strong>on</strong>ic digital storage<br />

devices mandatory. Attached is a copy <str<strong>on</strong>g>of</str<strong>on</strong>g> said draft memo-directive. (Tab A)<br />

2012 .<br />

4.<br />

ITCON, kindly submit comments/inputs regarding this matter NLT May 30,<br />

CENTEP CHRIST HER A LAXA, CSEE<br />

Police -nior Superintendent<br />

.(n) •<br />

-6/1/-)


MEMORANDUM<br />

Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />

Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />

Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />

PHILIPPINE NATIONAL POLICE<br />

CRIMINAL INVESTIGATION AND DETECTION GROUP<br />

Camp Crame, Quez<strong>on</strong> City<br />

FOR 01C, <strong>DIDM</strong>/TF USIG Commander<br />

FROM Director, CIDG<br />

SUBJECT<br />

DATE June 7, 2012<br />

Proposed <str<strong>on</strong>g>Mandatory</str<strong>on</strong>g> <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g><br />

<str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> <strong>on</strong> <strong>the</strong> Recovered Cellular Ph<strong>on</strong>es, Laptops<br />

and O<strong>the</strong>r Electr<strong>on</strong>ic <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Storage Devices in All Cases<br />

Handled By SITG<br />

1. Reference : Memo from 01C, <strong>DIDM</strong>/TF USIG Commander<br />

dated May 24, 2012, with subject same as above.<br />

2. In c<strong>on</strong>necti<strong>on</strong> with <strong>the</strong> above reference, attached is <strong>the</strong> proposed<br />

draft for mandatory c<strong>on</strong>duct <str<strong>on</strong>g>of</str<strong>on</strong>g> digital forensic examinati<strong>on</strong> <strong>on</strong> <strong>the</strong> recovered<br />

cellular ph<strong>on</strong>es, laptops and o<strong>the</strong>r electr<strong>on</strong>ic digital storage devices in all cases<br />

handled by SITG and necessary form needed by all <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratories<br />

to be filled-up by requesting parties.<br />

3. Request acknowledge receipt.<br />

FOR THE DIRECTOR, CIDG:<br />

GILBERT CAASI SA, PESE, MCSE, EnCE<br />

Police Senior Su erintendent (DSC)<br />

n<br />

ry,


Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />

Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />

Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />

PHILIPPINE NATIONAL POLICE<br />

CRIMINAL INVESTIGATION AND DETECTION GROUP<br />

ANTI-TRANSNATIONAL AND CYBER CRIME DIVISION<br />

Camp Crame, Quez<strong>on</strong> City<br />

<str<strong>on</strong>g>Digital</str<strong>on</strong>g> and Electr<strong>on</strong>ic <str<strong>on</strong>g>Forensic</str<strong>on</strong>g>s Laboratory<br />

Capabilities<br />

n Cyber Crime Incident Resp<strong>on</strong>se (Handling <str<strong>on</strong>g>of</str<strong>on</strong>g> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Evidence)<br />

o Recover volatile data currently running <strong>on</strong> <strong>the</strong> computer system and<br />

network;<br />

o Analyze volatile data recovered during incident resp<strong>on</strong>se<br />

o<br />

procedure; and<br />

<str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> search and seizure <str<strong>on</strong>g>of</str<strong>on</strong>g> electr<strong>on</strong>ic evidence found in <strong>the</strong><br />

computer crime scene.<br />

n Computer <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> and Analysis<br />

o Using internati<strong>on</strong>al standard hardware and s<str<strong>on</strong>g>of</str<strong>on</strong>g>tware for computer<br />

forensic examinati<strong>on</strong> such as <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Computers, Tableau Write<br />

Blockers, EnCase, <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Tool Kit (FTK), and FTK Imager;<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> digital media forensic imaging and au<strong>the</strong>nticati<strong>on</strong>;<br />

o Recover and analyze operating system artifacts;<br />

o Recover deleted files and folders, Internet history files, Internet<br />

cache files, and email artifacts from computer system storage<br />

media;<br />

o Access some encrypted and password protected files<br />

o Analyze files metadata and properties;<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> file system analysis (FAT, NTFS, HFS+, EXT2);<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> hash value analysis and file signature analysis;<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> live acquisiti<strong>on</strong> forensic imaging; and<br />

o Provide <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> Reports.<br />

n Cellph<strong>on</strong>e <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />

o Using internati<strong>on</strong>al standard Cellph<strong>on</strong>e forensic hardware and<br />

s<str<strong>on</strong>g>of</str<strong>on</strong>g>tware such as Cellebrite UFED/PA, XRY/XACT, EnCase<br />

Neutrino, SimC<strong>on</strong>, Data Pilot, Fernico ZRT, and Mobile Edit<br />

applicati<strong>on</strong>;<br />

o Recover deleted text messages (SMS and MMS);<br />

o Recover deleted files from Cellph<strong>on</strong>e storage media;<br />

o Recover Ph<strong>on</strong>e Book, C<strong>on</strong>tacts, Dialed Numbers, Received Calls<br />

and Miss Calls; and<br />

o Generate Cellph<strong>on</strong>e <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> Reports.<br />

Computer Crime Unit — Capabilities<br />

Page 1


n Computer Network Logs and Stego Analysis<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> network logs analysis;<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Malware analysis; and<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Steganography analysis.<br />

n Training<br />

n<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Cyber Crime Incident Resp<strong>on</strong>se and <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Evidence<br />

Handling Training;<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Computer <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Training; and<br />

o <str<strong>on</strong>g>C<strong>on</strong>duct</str<strong>on</strong>g> Cyber Crime Awareness Training<br />

Serve as an expert witness in court proceedings c<strong>on</strong>cerning digital<br />

evidence.<br />

Computer Crime Unit — Capabilities<br />

Page 2


MEMORANDUM<br />

FOR<br />

FROM<br />

SUBJECT<br />

DATE<br />

1.<br />

uepartment or we interior anu Local L'overrirnent<br />

NATIONAL POLICE COMMISSION<br />

PHILIPPINE NATIONAL POLICE<br />

References:<br />

Director, CIDG<br />

(Attn: C, ATCCD)<br />

Request for <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />

2. Request that Anti-Transnati<strong>on</strong>al and Cyber Crime Divisi<strong>on</strong> (ATCCD),<br />

CIDG c<strong>on</strong>duct digital forensic examinati<strong>on</strong> <strong>on</strong> <strong>the</strong> accompanying specimen specifically<br />

describe <strong>on</strong> <strong>the</strong> attached <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g> Request Form.<br />

3.<br />

Background <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> case with <strong>the</strong> following informati<strong>on</strong>:<br />

a) NATURE OF CASE<br />

b) VICTIM<br />

c) SUSPECT<br />

d) TDPO<br />

4. Facts <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Case:<br />

5.<br />

forensi • , n111,41...s .4..w.v......<br />

Herewith is/are <strong>the</strong> required storage media necessary for <strong>the</strong> digital<br />

Submitted <str<strong>on</strong>g>Digital</str<strong>on</strong>g> Media for<br />

<str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g><br />

Cellular Ph<strong>on</strong>e<br />

Computer System Unit /<br />

Hard Drive and o<strong>the</strong>r storage<br />

media.<br />

Required Storage Media<br />

2 pcs. DVD-R with Case<br />

External Storage Media or Hard Drive, which<br />

capacity must be twice <strong>the</strong> capacity <str<strong>on</strong>g>of</str<strong>on</strong>g> evidence<br />

submitted storage media.<br />

6. The bearer <str<strong>on</strong>g>of</str<strong>on</strong>g> this request is investigator-<strong>on</strong> case.<br />

Note:<br />

a. (For cases from Regi<strong>on</strong> 3, 4a, and NCR must be delivered<br />

pers<strong>on</strong>ally by <strong>the</strong> investigator-<strong>on</strong> case.),<br />

b. (For cases from o<strong>the</strong>r Regi<strong>on</strong>s preferably delivered by<br />

investigator-<strong>on</strong> case or <str<strong>on</strong>g>of</str<strong>on</strong>g>ficial Liais<strong>on</strong> Officer.)<br />

7. Fur<strong>the</strong>r request that this Office be furnished a copy <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> ATCCD digital<br />

forensic examinati<strong>on</strong> result for our reference.<br />

(CHIEF OF OFFICE)


Lab Case #:<br />

REPUBLIC OF THE PHILIPPINES<br />

Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />

Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />

PHILIPPINE NATIONAL POLICE<br />

CRIMINAL INVESTIGATION AND DETECTION GROUP<br />

ANTI-TRANSNATIONAL AND CYBER CRIME DIVISION<br />

Camp Crame, Quez<strong>on</strong> City<br />

Submitting/Requesting Agency:<br />

Agency Address:<br />

C<strong>on</strong>tact Official/Investigator:<br />

Type/Print:<br />

Signature:<br />

Type/Print:<br />

Signature:<br />

<str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory<br />

EVIDENCE CUSTODY FORM<br />

CHAIN OF CUSTODY<br />

Item # Date/Time Received From: Received By: Reas<strong>on</strong>:<br />

Type/Print:<br />

Signature:<br />

Type/Print:<br />

Signature:<br />

Date/Time:<br />

Agency Case #:<br />

Nature <str<strong>on</strong>g>of</str<strong>on</strong>g> Crime/s:<br />

C<strong>on</strong>tact #:


A. Request For:<br />

Republic <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Philippines<br />

Department <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Interior and Local Government<br />

Nati<strong>on</strong>al Police Commissi<strong>on</strong><br />

PHILIPPINE NATIONAL POLICE<br />

CRIMINAL INVESTIGATION AND DETECTION GROUP<br />

ANTI-TRANSNATIONAL AND CYBER CRIME DIVISION<br />

Camp Crame, Quez<strong>on</strong> City<br />

!SECTION III: COURT/SUSPECT/S INFORMATION<br />

A. Prosecutor Assign( d: (last, first)<br />

B. Ph<strong>on</strong>e Number:<br />

D. Suspect/s Name: ( 3st, first)<br />

<str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Laboratory<br />

REQUEST FOR DIGITAL FORENSICS ASSISTANCE<br />

q Lab: q On-site q Technical Assistance q Training<br />

q O<strong>the</strong>rs:<br />

B. Mode <str<strong>on</strong>g>of</str<strong>on</strong>g> Request:<br />

q Initial (Original agency investigati<strong>on</strong>) q Follow-up (Prosecutor follow-up request)<br />

q O<strong>the</strong>rs:<br />

SECTION II: CASE INFORMATION<br />

A. Submitting Agency: B. Date: C. Time:<br />

D. Agency Address:<br />

E. Agency Case Number:<br />

G. Legal Authority:<br />

q<br />

I<br />

q<br />

q<br />

Search Warrant<br />

Court Order<br />

C<strong>on</strong>sent to Search<br />

O<strong>the</strong>rs*<br />

F. Nature <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Crime/s:<br />

Note:<br />

Provide a copy <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong> Search Warrant,<br />

Affidavit, Written C<strong>on</strong>sent, C<strong>on</strong>sent<br />

Acknowledgement Form, and Synopsis <str<strong>on</strong>g>of</str<strong>on</strong>g> <strong>the</strong><br />

case or o<strong>the</strong>r Documentati<strong>on</strong>.<br />

H. Investigators Name: (last, first) I. Cellph<strong>on</strong>e Number: J. Office Number:<br />

K. Investigators Email:<br />

L. Is Investigator ISDE Trained?<br />

E. In custody/Detained:<br />

ECTION IV: EVIDENCE INFORMATION<br />

A. Search/Seized/ C B. Time: C. Locati<strong>on</strong>:<br />

q Yes q No<br />

C. Email Address:<br />

q Yes No


D. Items to be Examined:<br />

It #: Type <str<strong>on</strong>g>of</str<strong>on</strong>g> Items/Media Descripti<strong>on</strong> (make &<br />

model)<br />

Serial Numbers<br />

E. Has any<strong>on</strong>e viewed/examined/accessed this evidence prior to submissi<strong>on</strong>?<br />

q Yes *<br />

F. List any <str<strong>on</strong>g>Digital</str<strong>on</strong>g><br />

q No<br />

<str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Lab members c<strong>on</strong>sulted:<br />

G. Special Handling: (check all that apply)<br />

q Bio Hazard q Classified Material<br />

q Suspected Terrorism q O<strong>the</strong>rs:<br />

Financial Records<br />

* Internet History and<br />

log files<br />

*Email/IM/Text<br />

Messages<br />

C<strong>on</strong>tact Lists<br />

Call History<br />

* Clarificati<strong>on</strong> and comments<br />

*<br />

q Drug Related q Nati<strong>on</strong>al Interest<br />

Please identify <strong>the</strong> types <str<strong>on</strong>g>of</str<strong>on</strong>g> evidence/informati<strong>on</strong> to be searched for! recovered:<br />

q q q q q<br />

Word Processing /Text<br />

Documents<br />

Credit Card info/Checkwriting<br />

programs<br />

Child Pornography<br />

Images<br />

Owner Informati<strong>on</strong><br />

q q q q q<br />

(O<strong>the</strong>r/Keywords — Please be specific)<br />

If child pornography images are found during <strong>the</strong> course <str<strong>on</strong>g>of</str<strong>on</strong>g> an examinati<strong>on</strong>, <strong>the</strong> examiner will:<br />

1. Use a hard drive duplicator from <strong>the</strong> <str<strong>on</strong>g>Digital</str<strong>on</strong>g> <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Lab to duplicate <strong>the</strong> original hard drive.<br />

2. Replace <strong>the</strong> original drive with a duplicate hard drive <str<strong>on</strong>g>of</str<strong>on</strong>g> equal or greater size.<br />

3. Remove all child pornography from <strong>the</strong> duplicate hard drive (which will remain <strong>on</strong>-site or will be<br />

returned to <strong>the</strong> victim/suspect (when required to do so)).<br />

4. Maintain <strong>the</strong> original hard drive and imaile in <strong>the</strong> Di , ital <str<strong>on</strong>g>Forensic</str<strong>on</strong>g> Lab for anal sis.<br />

SECTION VI: REQUESTING CASE AGENT /INVESTIGATOR CONFIRMATION<br />

A. Rank / Name /Tit e:<br />

1:1*111•1 n VII •<br />

A. Lab Case #:<br />

B. Signature:<br />

BlIclifil NZ :4 4Z KitallWamcgixki g 1%<br />

Process Rank/Name Signature Time/Date<br />

B. Received by<br />

C. Assigned by<br />

D. Assigned to<br />

E. Priority<br />

F. Lab Case Status<br />

q Imaging q <str<strong>on</strong>g>Examinati<strong>on</strong></str<strong>on</strong>g>/Analysis q Report Submitted<br />

q Archived q Pulled out<br />

Remarks:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!