Lounge of Tomorrow

€uromeinke, FEJ. and Ghoulish Delight RULE!!! NA abides.  


Go Back   Lounge of Tomorrow > A.S.C.O.T > Egg Head
Swank Swag
FAQ Members List Calendar Today's Posts Clear Unread

Reply
 
Thread Tools Search this Thread Display Modes
Old 09-25-2007, 01:42 PM   #1
Moonliner
8/30/14 - Disneyland -10k or Bust.
 
Moonliner's Avatar
 
Join Date: Jan 2005
Posts: 9,022
Moonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of coolMoonliner is the epitome of cool
Send a message via AIM to Moonliner Send a message via MSN to Moonliner Send a message via Yahoo to Moonliner
Hard Disk Forensics expertise?

Has anyone round here worked with hard disk forensics in relation to legal actions?

I'm looking for information not on the technical side of the equation but rather on the rules, procedures and certifications that are needed in the legal world.

Is there a nationally recognised certification for individuals performing hard disk analysis?

Are there set procedures to secure chain of custody, etc...

Thanks for any help.






Ps: No I'm not facing any legal action, It's for a friend. No really it is.
__________________
- Taking it one step at a time.
Moonliner is offline   Submit to Quotes Reply With Quote
Old 09-25-2007, 01:57 PM   #2
€uroMeinke
L'Hédoniste
 
€uroMeinke's Avatar
 
Join Date: Jan 2005
Location: A.S.C.O.T.
Posts: 8,671
€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool
Send a message via Yahoo to €uroMeinke Send a message via Skype™ to €uroMeinke
Usually going to forensics only happens in extreme circumstances - where a party is presumed to have deliberated deleted or altered their hard drive to cover up illeagle activity or fraud.

Usually it happens after hardware is siezed in a legal action and the chain of custody falls on the organization doing the seizing. There is no set standard, and usually the effort is proportional to the severity of the case but might include: witnessed testimony, access control logs, documented and audited processes (if this is an organization we're talking about).

To my knowledge, there is no certification standards for forensics, tbut there are a number of private companies (as well as government organizations) that specialize in these activities to different levels complexeity - Apparently the CIA has technology that can read back 7 re-writes of a hard drive.

I guess a lot depends on the circumstances:

Is your friend trying to find evidence of wrong doing on someone else's computer? And if so, is criminal procsecution an expected outcome?

Or is your friend trying to cover something up that may be on his computer?
__________________
I would believe only in a God that knows how to Dance.
Friedrich Nietzsche

€uroMeinke is offline   Submit to Quotes Reply With Quote
Old 09-26-2007, 08:50 AM   #3
€uroMeinke
L'Hédoniste
 
€uroMeinke's Avatar
 
Join Date: Jan 2005
Location: A.S.C.O.T.
Posts: 8,671
€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool€uroMeinke is the epitome of cool
Send a message via Yahoo to €uroMeinke Send a message via Skype™ to €uroMeinke
Your friend might find this article of interest
__________________
I would believe only in a God that knows how to Dance.
Friedrich Nietzsche

€uroMeinke is offline   Submit to Quotes Reply With Quote
Old 09-26-2007, 09:09 AM   #4
Alex
.
 
Join Date: Feb 2005
Posts: 13,354
Alex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of coolAlex is the epitome of cool
There are professional certification programs out there for computer forensics that are supposed to help with getting work with law enforcement agencies and certain private industrial applications.

But I don't know any of the details.
Alex is offline   Submit to Quotes Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -7. The time now is 12:03 PM.


Lunarpages.com Web Hosting

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.