This process finds legitimate evidence from computer or other digital storage media. There are various parts in digital forensics depending on what is the target, i.e., network forensic, database forensic or mobile forensic. Digital forensic procedure is as follows.
Preparation |
Confirm the closing of the case Determine the scope of investigation |
---|---|
Collection |
Confirm the type of evidence Evidence preservation Evidence data imaging |
Examination |
Confirm usage tools for each evidence Recover data Check phenomenon |
Analysis |
Check relationship between evidences collected Check the facts of evidence |
Reporting |
Make a report on findings Keep results |
This procedure should be conducted by appropriately trained personnel using the tools designated for forensic investigation. Forensic tools used in this process can be largely divided into hardware and software. Software correspond to analysis tool and can be further divided into tools that can be used as a standalone type and online tools. Evidence can be obtained from digital data using these software tools. Such evidence may include data obtained from the system currently in use, data searched from the stored data and data retrieved from the deleted parts.
Digital forensic investigators should perform various technical approaches according to the procedure and find the suitable evidence while examining important factors. For this process, skilled personnel and tools optimized for investigation are required. IN INFORMATION Co., Ltd. possess various kinds of technology and tools and can provide the best service for customers through this.
With forensic technology on database, mobile and general storage media, IN INFORMATION Co., Ltd. has tried our best to easily obtain effective evidence that customers want in a response to various situation, using various forensic tools.