Tag Archives: Computer Forensic

How to Become a Forensic Computer Professional

computerforensicprofessional A computer forensic professional collects electronic evidence and provides information to an investigation team. Being a computer forensic professional requires you to have skills to help criminal investigators solve computer crimes. You should have knowledge of criminology, business law and computer data analysis.

If you like crime scene investigation shows or the thought of cracking encrypted computer security codes excites you, then a career in computer forensics might be right …

Work in Forensics: 5 Key Steps

Work in Forensics: 5 Key StepsJoseph Naghdi, an experienced computer technologist, transitioned to digital forensics in early 2000 because he was intrigued by how data is stored and discovered on computers. Today, he’s a forensics analyst at Computer Forensics Lab, a U.K. consultancy specializing in computer forensic services and advanced data recovery. The high point of his work, he says, is when he solves tough cases, such as a recent phishing attack against a UK …

What Does It Take to Do Forensics?

Hardware 1. Become familiar with the inside of the computer 2. Understand hard drives and their settings 3. Motherboards 4. Power connections 5. Memory

Knowledge of Operating Systems and Software

Operating Systems –Microsoft Products –Linux RedHat –UNIX

Software –Forensic Software –HTML –Microsoft Office –Quick View Plus

Training 1. New Technologies (NTI) in Gresham, OregonGuidance Software (Encase)Access DataHTCIA Annual Conference 2. PatienceOne needs the ability to be able to sit in …

Where Should Computer Forensics Begin?

Analysis Areas –Email –Temp Files –Recycle Bin –Info File Fragments –Recent Link Files –Spool (printed) files –Internet History (index.dat) –Registry –Unallocated Space-free space on the hard drive –File Slack-free space between the end of the logical file and the end of physical file (cluster) –RAM Slack-free space between the end of the logical file and the end of the containing sector •Sector-the smallest group that can be accessed on the …

Acquiring Electronic Evidence from Hard Drive

Forensic Image of the hard drive means to take an exact copy of a hard drive including deleted files and areas of the hard drive that a normal backup would not copy; Never boot off of the hard drive; Use write protection software to protect the original evidence; Make a copy of the original evidence and do all work off of the copy; Document all aspects of the hard drive; …