What is the difference between computer forensics and digital forensics?
The terms computer forensics and digital forensics are often used interchangeably. Both fields are closely related because they deal with computerized devices. However, computer forensics typically deals with desktops, laptops, servers and hard drives.
Because of the prevalence of these systems, digital forensics experts are often part of investigations for both physical crimes and cybercrimes.
What is a digital forensics investigator?
Digital forensics investigators are computer scientists who use their skills to find and collect evidence from computers, mobile phones, tablets and other digital devices. They coordinate with attorneys and other investigators to collect evidence and locate those responsible for criminal activities.
In some cases, digital forensics experts play a specific role, such as extracting information from a suspect’s mobile phone. However, they may be the primary investigators in cases involving cybercrime.
What techniques do digital forensics investigations use?
Digital forensics investigators use specific techniques to carry out their inquiries. Here are some additional investigative methods cyber investigators use:
- Software toolkits — Forensic experts use special software to examine the contents of devices and files.
- Network analysis — Investigators often look at traffic and activity history on a network.
- File recovery — Investigators usually need to find and recover deleted files, which is often possible with the help of software.
- Live analysis — This involves collecting information, such as software, files and metadata, from a device while it’s running. It can also include collecting encrypted files for later decryption.
- Malware forensics — This focuses on finding and examining malware programs on a system to get information about their origin.
- ISP and file monitoring — In some cases, forensics experts can locate suspects by allowing them to access a compromised file or network and then tracking them digitally.