Digital Forensics Lab1: Building a Computer Forensics Lab
Prepared by: Fatimah Albrahimi
Outline • What we mean in setting up forensics lab • Ensure the evidence is not modified. • create a data recovery and analysis process. • Present all the file on the device from one tool.
Prepared by: Fatimah Albrahimi
Setting up computer forensic lab • A computer Forensics lab (CFL) is a location designated for conducting computer-based investigation with regard to the collected evidence. • The lab houses instruments, software and hardware tools, suspect media, and forensics workstations required to conduct the investigation.
Physical Physical Human
Planning location and Work area Forensic security resource And structural considerati s lab Budget design on recomm consider consideration licensing endation ation
Prepared by: Fatimah Albrahimi
Tools for Investigation Process All this tools should not download on evidence device < just on forensics lab for colon (other copy) or device that used in analysis. • EeasUs Data recovery file: https://www.easeus.com/datarecoverywizard/free-data-recovery-software.htm
Prepared by: Fatimah Albrahimi
Tools for Investigation Process All this tools should not download on evidence device < just on forensics lab for colon (other copy) or device that used in analysis. • Recuva: https://www.ccleaner.com/recuva/download
Prepared by: Fatimah Albrahimi
Tools for Investigation Process • HashCalc: compute hash( cryptography function) for any file you choose: https://hashcalc.en.softonic.com/?utm_source=SEM&utm_medium=paid&utm_campaign=EN_desktop_Saudi_Arabia_DS A_Adobe_affiliate&gclid=CjwKCAjwq-WgBhBMEiwAzKSH6If2LUnbert3fpW8j5eTYk _4VkUnnKMTuGYXoSGeTMj4o9jhPMZrxoC8t4QAvD_BwE
Prepared by: Fatimah Albrahimi
Tools for Investigation Process • Free File viewer : https://www.freefileviewer.com/