Professional Documents
Culture Documents
Computer Forensics
Computer Forensics
By Rob Ferrill
Forensics in a Nutshell
Evidence Seizure
Investigation and Analysis
Reporting Results
www.fish.com/security/forensics.html
Chain of custody
Images
Media analysis
piece of evidence?
• 4 bytes
• An IP address in hex
data on a system
Extracted data may be introduced as
evidence
actions
Recovery and downtime major concerns