Top 10 Ways People Damage Evidence

on the computerSimply, DON’T! Computers like to be very
The biggest no-no. It writes large amounts of dataorderly, so when you shut down they will do a lot of
to the hard disk, potentially wiping all traces of a‘housekeeping’ — tidying up files,
deleted file forever. Data is automatically updated andoverwriting deleted information and changing times
therefore altered. Turning the computer on affectsand dates which are vital to any investigation. If you
the swap file and registry as well as the list of mosthave to turn the computer off, simply pull the plug.
recently used documents. Dates when a file wasThis freezes it and creates a ‘snapshot’ in
created, last modified, last accessed and updated cantime which can be forensically examined using a
all be unwittingly altered.whole range of tools.
Investigating email with emailJumping to conclusions
Investigating emails with an email client carries a hostA common mistake when a computer crime is
of potential dangers. Going into a suspect’scommitted is to assume guilt and embark on a witch
inbox in Outlook and reading an email which has nothunt for the culprit.
been opened before may create a read receipt,But is vital not to jump to conclusions. Just because
leaving a clear trace of the activity. Although oftenthere is incriminating material on somebody’s
done to try and confirm suspicions, it can becomputer does not mean they put it there.
considered tampering with the evidence.Somebody else may have hacked their password, or
Losing evidenceit could have been a Trojan horse or other virus of
Failing to either make a forensic image of the hardwhich they had no knowledge, and therefore no
drives of staff when they leave, or replace the hardcontrol over.
drive and store the original, runs the risk of losingIgnoring the evidence
important data and therefore being unable toMany ‘first responders’ will miss vital
substantiate claims made at a later date.evidence by failing to follow correct procedures.
Creating a copy of a person’s computer as itSimply pulling the plug on thecomputer will wipe the
was when last used is key to preserving data.contents of RAM, which may contain useful
DIY data recoveryinformation, particularly in cases of hacking or server
Unskilled staff attempting to recover data fromdamage. CDs, DVDs, digital cameras and personal
machines they suspect contain evidence is a bigorganisers on a person’s desk are also often
problem. Often, people can’t resist the urgeoverlooked.
to ‘have a quick look’ when an incidentIncorrectly marked tapes
occurs. And although in many cases technical supportThis is the bane of the life of a forensic analyst. It is
will be called in, unfortunately, they will generally notextremely frustrating when investigating an incident
have the specialist skills needed to investigate in anto find that he data on a back-up tape is different
evidentially-sound manner. Correctly recovering data isfrom what is stated on the label. It is vital to have a
expert work and should only be carried out bydata back-up and retention policy and be consistent
suitably qualified professionals.in the implementation of it. Everyone involved in
Following evidential URLssecurity must be aware of what their
This is really dangerous territory. Apart from the riskorganisation’s back-up procedures are.
of incriminating yourself — in the case of child abuseBeing careless with evidence
images you are essentially committing the sameBadly-handled evidence can stop a criminal
‘offence’ as the suspect — there is alsoinvestigation in its tracks. Evidence should always be
the possibility of compromising confidential data. Youcarefully secured and then packaged with care. If
should never click on links in emails, even when theynot, fragile date can be damaged or even lost while
are from a supposedly trusted source.stored or being transported.
Preserving digital evidence - Shutting down the PC