Professional Documents
Culture Documents
Cybercrime Processing Bag and Tag Prodedure
Cybercrime Processing Bag and Tag Prodedure
Anti-Transnational and
Cyber Crime Division
1
PNP-CIDG
Anti-Transnational and
Cyber Crime Division
Objectives
Electronic Evidence
Computer evidence is
fragile. Investigators should
maintain the integrity of the
evidence through:
– Documentation
– Identification and seizure
– Packaging, transportation
and storage
– Chain of custody
Ask yourself:
* Do I have sufficient manpower to execute
the search?
* Are they trained in seizing electronic evidence?
* Do I know everything I can about the place
to be searched?
* Layout?
* Resistance?
* Network?
* Follow up searches?
Procedure:
* Select a group leader
* Assemble a search team
* Brief team on the nature of
the search
* Assign each officer a role
* Assemble evidence collection
kit
PNP-CIDG
Anti-Transnational and
Cyber Crime Division
On the Scene
Crime Scene
Crime Scene
Crime Scene
Crime Scene
Crime Scene
Crime Scene
Sketch:
* Layout
* Suspect location
* Room identification
* Location of Evidence
* Court Presentation
Interviewing the
Occupants
On the Scene
Occupants
On Scene Interview:
* Discovery or preservation of
additional evidence
* Additional Arrests
Interview Basics:
* Asking the right questions
* Documenting the interview
* Using evidence to formulate
questions
Occupants
* Electronic Interview:
* Ownership and / or control of the
items being seized
* Booby traps
* Login names and passwords
* Encryption
* Files of interest
* E-mail accounts and screen
names
* Internet service providers
* Off-site storage
* Hidden storage devices
Electronic Evidence
Electronic Evidence
Electronic Evidence
Computer Hardware:
* CPU Removable media:
* Hard drive(s) * Floppy diskettes
* Volatile memory
* CD / DVD
* Data tapes
* Zip / Jazz disks
* Memory cards
Electronic Evidence
Electronic Evidence
Demonstration
On the Scene – Step
Step--by
by--Step
Evidence
Evidence
Evidence
Step 3a: On the Scene
Evidence
Evidence
Evidence
Step 5
Evidence
Evidence
Step 7: Collection
Other items of interest:
* Note pads
* Video cassettes
* Audio cassettes
* Manuals and other
printed materials
* Use of collected evidence
to formulate questions
Packaging Non-
Non-Electronic Anti-Transnational and
Cyber Crime Division
Evidence
Evidence
Step 8: Labeling
When disassembling the computer ,
system,
* Label each part and peripherals .
so it can be reassembled in court,
if necessary.
* Use corresponding labels for any
cables or devices that were
connected.
* Label any empty ports “MTY”
Step 8: Before
Seizing Electronic Evidence
Step 8: After
Seizing Electronic Evidence
Working Notes:
PNP-CIDG
Evidence
Step 9a: Transport Prep
To help prevent accidental
booting of the system:
* Insert a blank disk in the floppy
diskette drive
* Place evidence tape over the disk
drives
* Be sure to check CDROM
* Place evidence tape over power
outlet
Evidence
Step 9b:
* Do not leave disks in the
disk drives
* Remove the CD / DVD from
the drive using a paperclip
(with power off)
Crime Scene
Evidence
Evidence
* Heat
* Police Radios
* Use bubble wrap not
Styrofoam
* Place computer in area of
car that is smoothest
Evidence
Start of Investigation
Start of Investigation
* Log files from the IDS indicates that there are series
of scan attempts for vulnerability exploit.
PNP-CIDG
IP Addresses of the Anti-Transnational and
Cyber Crime Division
Attacker
Network Intrusion
Dedicated Line
Suspect’s Computer
PNP-CIDG
Subpoena to Anti-Transnational and
Cyber Crime Division
GLOBE TELECOM
* Issuance of various “SUBPOENA DUCES
TECUM” to concerned TELCO’s and
Internet Service Provider (ISP).
PNP-CIDG
Anti-Transnational and
GLOBE TELECOM
PNP-CIDG
Anti-Transnational and
On--Site Investigation
On
* Set of IP addresses identified and analyzed by
ATCCD-CCU came from U.P.Visayas Linux
Gateway computer.
PNP-CIDG
Anti-Transnational and
On--Site Investigation
On
Examination
Administrative Investigation
Cont’…
Cont’… CASE REFERRAL TO Cyber Crime Division
DOJ
PNP-CIDG
RESOLUTION BY THE STATE Anti-Transnational and
Cyber Crime Division
PROSECUTOR
PNP-CIDG
’… RESOLUTION BY
Cont’…
Cont THE Anti-Transnational and
Cyber Crime Division
STATE PROSECUTOR
PNP-CIDG
Cont’… RESOLUTION BY
Cont’… THE STATE Anti-Transnational and
Cyber Crime Division
PROSECUTOR
PNP-CIDG
Anti-Transnational and
Cyber Crime Division
Warrant of Arrest
PNP-CIDG
Anti-Transnational and
Cyber Crime Division
Judgment
PNP-CIDG
CONVICTED HACKER
LIBEL CASE
THROUGH EMAIL
MESSAGING