DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of...

32
DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Transcript of DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of...

Page 1: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

DIGITAL FORENSICSForensic Toolkit: a tool to process born digital records

Emma Jolley Curator of Digital Archives

Page 2: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Why Digital Forensics?The process of identifying, preserving, analysing and presenting digital evidence in a manner that is legally

acceptable.

ProvenanceOriginal Order

Chain of CustodyIdentifying

Authenticity

Page 3: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Forensic Toolkit

Page 4: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Case Summary

Page 5: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Overview of FTK Screen

Page 6: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Explore View

Page 7: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Explore View – Additional Technical Metadata

Page 8: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Explore View – Additional Technical Metadata (part – 2)

Page 9: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Overview View

Page 10: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Overview View

Page 11: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Viewing Content

Page 12: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Email View - 1

Page 13: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Email View 1 – Deleted Items

Page 14: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Email View 1 – Calendar view

Page 15: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Email View 2

Page 16: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Email View 2

Page 17: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Graphics View

Page 18: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Graphics View – Properties view (metadata)

Page 19: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Video View

Page 20: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Audio Player

Page 21: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Bookmarks (Serialisation – Arrangement and Description)

Page 22: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Bookmarks (Serialisation – Arrangement and Description)

Page 23: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Labels (Analysis)

Page 24: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Searching (Index)

Page 25: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Searching (Index) – Copyright and IP statements

Page 26: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Visualisation – Time Series (Email)

Page 27: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Visualisation – social analyser (email)

Page 28: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Reporting

Page 29: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Reporting – Finding-aid

Page 30: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Reporting – Donors List (Finding-aid)

Page 31: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Issues and Challenges• Professional interactions (vocabulary)• Donors metadata• Description• Hybrid collections• Perceptions of the challenge• No two collections are the same• Getting the Description into CMS

Page 32: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives.

Lessons Learnt• Plan, Plan, Plan, visit and plan some more• Expect the unexpected• Digital Transfer is very resource hungry• Appraisal must be at CDP level (and Functions)• A single person isn’t going to do it (need a

village)• Theory is the same regardless of format