Professional Documents
Culture Documents
Cyber Forensic Operating Procedures: C-DAC/Kolkata C-DAC All Rights Reserved
Cyber Forensic Operating Procedures: C-DAC/Kolkata C-DAC All Rights Reserved
www.cdackolkata.in
C-DAC/Kolkata
www.cdackolkata.in
Information
is
the
quantity
required
for
preservation/collection. Information is an element of an
organizations regular operations
Records are a form of information, regardless of the medium
or format, that have value to an organization. The term is
used to describe both documents and recorded data.
Evidence can be anything (testimony, documents, tangible
objects) that tends to prove or disprove the existence of an
alleged fact .
E-discovery is eDiscovery is a related term that has gained use
to incorporate electronically stored information (ESI) into
the discovery process which is compulsory disclosure, at a
party's request, of information that relates to the litigation.
2
www.cdackolkata.in
C-DAC/Kolkata
www.cdackolkata.in
www.cdackolkata.in
Preliminary Analysis
Deposition/
Affidavit
Image
Acquisition/
Recovery
Detailed
Analysis
C-DAC/Kolkata
Preliminary/
Final Report
C-DAC All Rights Reserved
Presentation
5
www.cdackolkata.in
www.cdackolkata.in
C-DAC/Kolkata
C-DAC/Kolkata
Investigating officer
principal investigator &
legal advisor
Forensic Analysis of
Digital evidence
Preparation of analysis
report
Preparation and
presentation of case in
court of law
Investigating officer ,
principal investigator &
legal advisor
www.cdackolkata.in
www.cdackolkata.in
www.cdackolkata.in
10
C-DAC/Kolkata
www.cdackolkata.in
11
Step 3 Guidelines
Guide lines of step 3
www.cdackolkata.in
C-DAC/Kolkata
12
Step 3 Guidelines
www.cdackolkata.in
C-DAC/Kolkata
13
Step 3 Guidelines
Take Hash Value: After All electronic data should be hashed at
the point of acquisition, transfer of custody and modification .
www.cdackolkata.in
C-DAC/Kolkata
14
www.cdackolkata.in
C-DAC/Kolkata
15
Content Analysis
Content (what type of data)
Comparison (against known data)
www.cdackolkata.in
Transaction (sequence)
Extraction (of data)
Deleted Data Files (recovery)
Format Conversion
Keyword Searching
Password (decryption)
Limited Source Code (analysis or compare)
Storage Media (many types)
C-DAC/Kolkata
16
Yes
If item or discovered
information can generate new
Data Search Leads, document
new leads to Data search
Lead List
Who/What
Where
Where was it found/where did it came from
Does it show where relevant event took place
When
How
Registry entry
Application/System logs analysis
If item or discovered
information can generate
New Source of Data ,
document lead on new
source of data lead list
www.cdackolkata.in
Start Forensic
Reporting to
Document findings
C-DAC/Kolkata
17
C-DAC/Kolkata
www.cdackolkata.in
18
C-DAC/Kolkata
www.cdackolkata.in
19
www.cdackolkata.in
C-DAC/Kolkata
20