Networking Concept and Computer Forensics

computer network 300x225 Networking Concept and Computer ForensicsIn years past, computer forensics investigators would often seize a single standalone computer, process the disk evidence, and write a report detailing any artifacts of evidentiary value found on disks. The majority of the investigative challenges in these cases were found in the actual disk analysis phase. (more…)

Challenges to Computer Evidence (2)

Investigator Dave is examining the corporate evidence drive taken from the desktop computer of “John A. Suspect,” who is assigned the user network logon identification of “jasuspect.” In investigator Dave’s report, he states that “the user, John A. Suspect, performed a specified action on the computer because an event log showed that the user had accessed the file…” (more…)