Scene of the Cybercrime: Computer Forensics Handbook

In Chapter 9, we discussed methods of detecting that cybercrimes have occurred and tracking down the person(s) responsible. The next and perhaps most important step in prosecuting the offender is to collect the evidence that will be used to build the case to be presented at trial.
Forensics refers to the use of scientific or technological techniques to conduct an investigation or establish facts (evidence) in a criminal case. Computer forensics is defined as the application of computer investigation and analysis techniques in the interests of determining potential evidence, according to computer crime investigator Judd Robbins, quoted in Computer Forensic Legal Standards and Equipment on the SANS Institute Web site at http://rr.sans.org/incident/legal_standards.php. The field of computer forensics involves identifying, extracting, documenting, and preserving information that is stored or transmitted in electronic or magnetic form (that is, digital evidence). Like fingerprints, digital evidence can be visible (such as files stored on disk that can be accessed via the normal directory structure using standard file management tools such as Windows Explorer) or it can be latent (not readily visible or accessible, requiring some sort of processing via special software or techniques to locate and identify it). An important aspect of computer forensics involves finding and evaluating this hidden data for its evidentiary value.
Computer forensics standards have been developed that apply to the collection and preservation of digital evidence, which differs in nature from most other types of evidence and thus requires different methods of handling. Following procedures that are proper, accepted, and,...