Types of investigations

From Wikibooks, open books for an open world
Jump to navigation Jump to search
Introduction to Digital Forensics
Types of investigations

Helpful Hint!
You might like to read the Wikipedia article about computer crime which includes a lot more detail on the subject

Digital forensics is traditionally associated with criminal investigations and, as you would expect, most types of investigation centre on some form of computer crime. This sort of crime can take two forms; computer based crime and computer facilitated crime.

Computer based crime
This is criminal activity that is conducted purely on computers, for example cyber-bullying or spam. As well as crimes newly defined by the computing age it also includes traditional crime conducted purely on computers (for example, child pornography).
Computer facilitated crime
Crime conducted in the "real world" but facilitated by the use of computers. A classic example of this sort of crime is fraud: computers are commonly used to communicate with other fraudsters, to record/plan activities or to create fraudulent documents.

Not all digital forensics investigations focus on criminal behaviour; sometimes the techniques are used in corporate (or private) settings to recover lost information or to rebuild the activities of employees.


Digital forensics is used to supplement investigations, much like any other forensic discipline. In 2007 prosecutors used a spreadsheet recovered from the computer of Joseph E. Duncan III to show premeditation and secure the death penalty. In 2006 Sharon Lopatka's killer was identified after email messages from him, detailing torture and death fantasy, were found on her computer.

Types of investigation[edit | edit source]

Helpful Hint!
Wikipedia has material on eDiscovery and digital evidence which might be of interest.
w:Wireshark, a common tool used to monitor and record network traffic

There are four main types of investigation performed by digital forensics specialists. The first three are broadly similar in the activities the involve, but differ in terms of the legal restrictions and guidelines imposed as well as the type of digital evidence and form of report.

Criminal forensics
The largest form of digital forensics and falling under the remit of law enforcement (or private contractors working for them). Criminal forensics is usually part of a wider investigation conducted by law enforcement and other specialists with reports being intended to facilitate that investigation and, ultimately, to be entered as expert evidence before the court. Focus is on forensically sound data extraction and producing report/evidence in simple terms that a lay man will understand.
Intelligence gathering
This type of investigation is often associated with crime, but in relation to providing intelligence to help track, stop or identify criminal activity. Unless the evidence is later to be used in court forensic soundness is less of a concern in this form of investigation, instead speed can be a common requirement.
Electronic discovery (eDiscovery)
Similar to "criminal forensics" but in relation to civil law. Although functionally identical to its criminal counterpart, eDiscovery has specific legal limitations and restrictions, usually in relation to the scope of any investigation. Privacy laws (for example, the right of employees not to have personal conversation intercepted) and human rights legislation often affect electronic discovery.
Intrusion investigation
The final form of investigation is different from the previous three. Intrusion investigation is instigated as a response to a network intrusion, for example a hacker trying to steal corporate secrets. The investigation focuses on identifying the entry point for such attacks, the scope of access and mitigating the hackers activities. Intrusion investigation often occurs "live" (i.e. in real time) and leans heavily on the discipline of network forensics.

Evidence and analysis[edit | edit source]

Obviously the main aim of any investigation is to recover some form of digital evidence, objective data that is relevant to the examination. On top of that the investigator might be asked to make some form of analysis of that evidence; either to form an expert conclusion, or to explain the meaning of the evidence.

Here are some examples of the kind of analysis an examiner might be asked to undertake:

Meta data and other logs can be used to attribute actions to an individual. For example, personal documents on a computer drive might identify its owner.
Alibis and statements
Information provided by those involved can be cross checked with digital evidence. For example, during the investigation into the Soham murders, the offenders alibi was disproven when mobile phone records of the person he claimed to be with showed she was out of town at the time.
Helpful Hint!
Mens rea, or intent, is one half of proving a criminal act. There must also be actus reus, the actual criminal act, which is where the digital evidence comes in!
As well as finding objective evidence of a crime being committed, investigations can also be used to prove the intent (known by the legal term mens rea). For example, the Internet history of convicted killer Neil Entwistle included references to a site discussing How to kill people.
Evaluation of source
File artifacts and meta-data can be used to identify the origin of a particular piece of data; for example, older versions of Microsoft Word embedded a Global Unique Identifier into files which identified the computer it had been created on. Proving whether a file was produced on the digital device being examined or obtained from elsewhere (e.g., the Internet) can be very important.
Document authentication
Related to "Evaluation of Source", meta data associated with digital documents can be easily modified (for example, by changing the computer clock you can affect the created date of a file). Document authentication relates to detecting and identifying falsification of such details.

Test yourself[edit | edit source]

Here's a quick test for this page, try to fill in the answers without cheating.

1 There are four common forms of forensic investigation


2 eDiscovery is an investigation into criminal matters


3 Which of these is Computer facilitated crime?

Child pornography

4 Digital forensics is only used to investigate crime


Introduction to Digital Forensics
A history Types The forensic process