Digital Forensic Investigations

3729 Words8 Pages

? Abstract?Digital forensic investigations has become an important field in this era due to the raise of cybercrimes. Therefore, most governments and companies found the urgent need to invest more in research related to digital forensic investigations. To perform digital forensic investigations covering extraction, analysis, and reporting of digital evidences, new methods and techniques are required. One of these methods used when applying digital forensics on a Windows operating system, is PowerShell. While PowerShell is mainly used to configure, manage and administrate the Windows operating system and other installed programs, this paper will also show that it could be used to collect forensic evidences from a Windows operating system. This …show more content…

Information is being stored and exchanged using these different digital devices or machines. Such level of usage and the people?s dependency on these devices, lead to the exposure of a new type of threat and crime. Such threats and crimes could be named ?cyber threats? and ?cybercrimes?, respectively. Threats that are targeting such devices require a special kind handling. Crimes that are done, whether against or using such devices will need to be investigated differently in order to reach the proper evidence to either incriminate the suspect or refute him/her. Digital forensic investigation defined as ?the use of scientifically derived and proven methods toward the preservation, collection, validation, identification, analysis, interpretation, documentation and presentation of digital evidence derived from digital sources for the purpose of facilitating or furthering the reconstruction of events found to be criminal, or helping to anticipate unauthorized actions shown to be disruptive to planned operations? [1]. It?s mainly related to criminal and unauthorized actions …show more content…

However, collecting artifacts only not sufficient without analysis by connecting each artifact with other according to the relation between them. Afterward, all artifacts should order according to the time to reach the final solution of the case. Therefore, timeline is one of the important things in the investigation and should be considered in the final report as it will include full story of the case. Thus, J. Atkinson didn?t forget to include forensic timeline convertor to PowerForensics which convert artifacts to timeline style and can export it to different formats. Fig. 6 present an example of an exported timeline in comma separated value

Open Document