

Preserving Digital Evidence For Court
Presentation by: Sgt. Andrew Obushowski
Sgt. Andrew Obuchowski sets forth the necessary steps needed to preserve digital evidence whether it is from instant messaging, email, or the information that can be found on a computer. Preservation, subpoena and search warrants are covered extensively as well crime processing.
Table of Contents
Internet Basics
- Getting Online
- Work, home, schools, library, handhelds, wireless
- Internet Service Providers
- Dial-up, DSL/cable modem, wireless, T1 and T3 lines
- IP Addresses
- Static, dynamic
Instant Messaging Investigations
- File Transfer Protocol
- Transferring of files among computers in 3 ways: Web, Dos, GUI (Cute FTP, Dreamweaver, Front Page)
- Can be used to copy files illegally
- Peer-To-Peer File Sharing
- Share files and music between computers
- Chat
- IM public and private
- IM Recording and Investigating
- How to's
Email Investigations
- Email
- Most widely used
- Geographical location can be found
- Almost all investigations will involve email
- Easy ways to hide identity; spoofing/masquerading
- Email addresses
- Post Office Protocol (POP)
- Protocol for receiving email
- Mail sent to mail server and stored in user folder
- Simple Mail Transfer Protocol (SMTP)
- Protocol for sending email
- Mail is sent to mail server then to recipients
- Tracing Email
- Need original email file
- Some information is difficult to forge
- Need to view full email headers
- Email Body Reading
- Anonymous Re-Mailers & Proxy Servers
- Re-mailers change certain fields
- Re-mailers strip header information
- Sometimes bounce email to other re-mailers
- Recording Email Evidence
- 12 steps for recording evidence
- Web based instructions
- Email Investigation Summary
- Locate originating IP address
- Lookup information for IP address
- Send preservation letter
- Government process for information
Preservation, Subpoena, Search Warrants
- Freeze Orders/Preservation Letters
- Types of Orders to Obtain
- Administrative subpoena
- Grand jury subpoena
- Search warrant
- Subpoena v. Search Warrant
- What type of information do you want?
- Do you have probable cause?
- Requirements for Government Access
- Search Warrant Exceptions
- Consent
- Third party & implied
- Exigent circumstances
- Plain view
- Search incident to a lawful arrest
- Basic Information
- Obtain thru subpoena
- Transactional Records
- Obtain thru Articulable Facts Order -- 18 USC 2703(d)
- Credit card information
- Activity logs
- Content
Scene Processing
- Understanding personal computers & peripherals
- Intelligence gathering
- Raid precautions
- Basic scene toolkit
- Scene "Do Nots"
- Computer shutdown
- Scene processing
- Storage control
DVD Price: $95.00
Click here for a printable version (pdf) to fax your order.
or click below to order using a credit card.