Digital Forensics for Private Investigators

What is Digital Forensics?examination techniques are able to expose more
Digital Forensics is the terminology used whenevidence then several days of surveillance and
digital artifacts are collected from a computerdumpster diving. Deleted data from digital devices
system in a forensically sound manner. In othersuch as cell phone text messages and other acts
words, digital artifacts such as documents,are often recoverable; for example, did your
spreadsheet, pictures and email can be retrievedclient’s spouse have an instant messaging
from a computer, PDA or any other type ofconversation? Are those deleted emails
digital device with storage capability. The materialrecoverable? What websites did the suspect visit?
is then analyzed and preserved. This operation canSeveral examples below elaborate how Digital
often be done even if the data has beenforensics can assist the privateinvestigator in
intentionally erased. Digital Forensics procedures willspecific cases and tasks:
allow the forensic examiner to reveal digitalAdultery cases:
evidence, and display the exact time and date theOnline chats or sms text messages are often
information was created, installed, or downloaded,used to arrange meetings and providecovert
as well as when it was last accessed. Althoughcommunication to avoid suspicions by the spouse.
the first computer crimes occurred in theFraud Cases:
1970’s, computer forensics is still a relativelyIt is often possible to determine when and if a
new field. While we now have more PC anddocument was altered. Unless the document was
mobile device users then ever, the demand forproduced by a typewriter, there always is or at
Digital Forensics is quickly increasing. Laptopleast has existed an electronic copy somewhere.
computers, PDA’s and mobile phones with theIn addition the most common word processor,
capability of storing pictures, connecting to the“Microsoft Word” which is part of the
Internet and e-mails, more and more oftenMicrosoft office suite embeds Meta data into each
require the need of Digital Forensics to determinedocument. This Meta data can provide vital
the action to be taken in criminal litigation cases,information such as the identity of the author and
corporate espionage, and accusations of childthe computer on which the document was
pornography, Likewise, acts of terrorism as wellcomposed. The same applies to Microsoft Excel
as the practices of disgruntled employees and thespreadsheet applications.
behavior of cheating spouses, all have one thing inTailing a suspect:
common: they frequently utilize computerWhen tailing a suspect, imagine how informative it
systems and mobile devices to assist them incould be to know his/her previous destinations,
their unethical actions and crimes. The evidenceprior to starting the assignment. Impossible you
that these activities leave behind is readilysay! This is not necessarily so especially if the
detected through the procedures of digitalindividual had traveled by automobile and used a
forensics.GPS (Global Positioning System). Some of the
most recent advancements in Digital Forensics
Digital Forensics or Computer Forensics?allow for the retrieval of information from the
In the past, computer forensic investigations havemost common GPS systems.
had PC and Laptop systems as their primaryHarassment cases:
target for examination. Within the past years, theThere are many different types of harassment. It
computer forensic field has been forced tois often the case that your client may not only be
broaden its scope, tools and investigativereceiving harassment in person, but also via
techniques in order to keep abreast of thephone, and/or email. A Forensic Examiner can
personal technology being used by commonpreserve logs of phone calls received from cell
citizens. Equipment such as Cell phones,phones and present them as evidence by strictly
PDA’s, Blackberrys and GPS systems aremaintaining a chain of custody. Every email sent
used on a daily basis, and can contain vitalfrom a given source to a specific destination
information from sms test messages, emails,leaves information embedded in that email. This
phone logs and previous GPS destinationinformation is referred to as the email header.
coordinates. Therefore the term Digital ForensicsThe forensic examiner can analyze the email
is becoming very popular as the computerheader and trace it back to the origins of the IP
forensic field expands and incorporates the digitaladdress from which it has been sent.
analysis of new technological devices.Surveillance:
When considering surveillance, most think of
What can a skilled Digital Forensic Examiner do?traditional techniques such as: tailing, stakeouts and
A skilled digital forensic examiner can recovervideo surveillance. However, modern computer
deleted files from a computer. He or she cantechniques can also be a valuable asset to the
view which websites have been visited from aprivate investigator. There are such devices as
specific computer even after the browser historyspy ware programs and keystroke loggers that
and cache have been cleared and deleted. A digitalwill provide real time information about what,
forensic examiner is able to review previouswhere and when things have occurred on a
communications sent and received via an instantsuspected computer.
messaging and chat application such as yahoo
instant messenger and msn messenger. TheWho has the right to search a computer or Digital
forensic process will also restore deleted or hiddendevice?
pictures and email messages. In addition theThe Fourth Amendment protection against
forensic examiner is trained to analyze andunlawful search and seizure only applies to
re-create deleted text messages and call logsgovernment entities such as law enforcement.
from cell phones, PDA’s and BlackberryThe Fourth Amendment does not apply to
devices. How the Private investigator can benefitprivate searches. A private search can be
from Digital Forensics Digital Forensics can assistconducted or authorized by anyone who has a
the private investigator in many ways principallylegal right to the data stored on the computer,
by identifying vital information and saving cost andsuch as employers or spouses.
time. Often 2-3 hours of digital forensic