All posts
Adli Bilişim

The Investigation Process of a Forensic Incident and the Rules to Follow

Hello everyone, today I will talk about the processes involved in a forensic incident and the rules we need to follow when managing these processes. Without…

Hello everyone, today I will talk about the processes involved in a forensic incident and the rules we need to follow when managing these processes. Without further ado, let’s begin. :)

We can generally group the examination of a forensic incident and its stages under three main headings. These are;

  • Identification, collection, and preservation of evidence
  • Uncovering, examining, and analyzing the evidence
  • Reporting of the evidence

The point at which digital forensics engineers become involved in a forensic incident is the point at which evidence is seized. Consequently, mistakes made during the procedures carried out at the scene, which is where the process begins, can undermine the authenticity and reliability of the evidence and can disrupt the entire process.

All procedures carried out at the scene are performed in accordance with Article 134 of the Code of Criminal Procedure and Article 17 of the Regulation on Judicial and Preventive Searches.

We can list the main points that the response team at the scene of the examination must pay close attention to as follows:

  • The security of the scene must be adequately ensured against the alteration or corruption of evidence.
  • At least one digital forensics expert should be present at the scene whenever possible.
  • The expert who will work on the evidence must have adequate equipment on hand.
  • All stages carried out must be checked against previously prepared checklists.
  • As many photographs as possible should be taken before starting any procedure.
  • During the work, cameras should be positioned to record all materials, including their locations within the room, as well as the information visible on computer screens.
  • All materials found at the scene that may constitute evidence must be labeled with evidence tags.
  • By creating an inventory, all objects seized at the scene must be recorded together with their serial numbers.
  • Copying the inventory and having each copy signed off must not be neglected.
  • Any device or connection providing remote access to the computers must be identified and labeled without cutting off access.
  • All connections that allow such devices to communicate with one another must be recorded.
  • Since it can damage digital data, chemical substances must not be used at the scene to obtain latent traces before the digital evidence is collected.
  • The BIOS information of the computer systems being examined must be recorded. If the BIOS date/time information differs from the actual time, this must be noted in the report.
  • A different computer must be used during the imaging process, and care must be taken with naming and labeling so that the images are not mixed up.
  • During the scene examination, all devices must be examined carefully, since something that appears to be a different object may actually be a computer.
  • Any notes found around the computer or the desk must be recorded and photographed.

Acquisition of Digital Evidence

Digital evidence is generally acquired at the scene by law enforcement, or afterward by forensic experts (often in a laboratory environment). Procedures performed at the scene are generally referred to as “collection of evidence”, while procedures performed in the laboratory environment are referred to as “recovery of evidence” or “analysis of evidence”.

The MD5 and SHA hash values of all digital evidence acquired, as well as of the image (copy) captured from that evidence, must be recorded, and noting these values in the incident report can help prevent objections that might arise later.

It should be kept in mind that the tapes used in CD/DVDs and backup units are sensitive data storage media, and care must be taken to ensure they are not damaged in any way.

All evidence collected for examination in laboratories must be kept away from environments that could cause damage, such as dust, moisture, humidity, excessive heat, and magnetic fields.

If the system is left running, live analysis can be performed using certain examination tools. Some of these tools are free software such as Helix, F.I.R.E., and Deft Linux.