Text
Placing the suspect behind the keyboard: using digital forensics and investigative techniques to identify cybercrime suspects
Table of Contents
Chapter 1. Introduction
Digital Evidence Collection
Simple File Copying
“Dead Box” Approaches
“Live Box” Approaches
Decision-Making FlowChart
Preview/Triage
SmartPhones and Cellular Devices
Chapter 2. High Tech Interview
Introduction
The Main Goal of Questioning a Suspect
The Line of Questions for Suspects
Questions for Victims
Questions for Network Administrators
Chapter 3. Physical Investigations
Introduction
Hazards of Acting Upon Minimal Information
Physical Surveillance
Electronic Surveillance
Obtaining Personal Information
Undercover and Informant Operations
Witnesses
Deconfliction
Chapter 4. Technical Investigations
Introduction
Digital Investigative Techniques
Who? What? When? Why? Where? and How?
“Other” Device Forensics
Online Social Networking
User Activity
Digital Authorship
Profiling
Biological Forensic Evidence
Triage and Previews
Chapter 5. Putting It All Together
“2+2=Putting it all together”
Timelines
Follow the Evidence
Rabbit Holes
Chapter 6. Investigative Case Management
Introduction
Bibliography
Chapter 7. Case Presentation
Introduction
It’s Not Whether You Win or Lose
Investigative Mindset
Your Audience
Preparation
Organizing Case Information
Value of Visuals
The Suspect’s Machine
Analogies
Avoid TMI (Too Much Information)
Your Presentation
Chapter 8. Cheat Sheets and Quickstart Guides
Introduction
Cheat Sheets and Quickstart Guides
Checklists
Chapter 9. Some Things Will Become Easier, Others Not So Much
Introduction
It Will Become Easier to Place a Suspect Behind the Keyboard
It Will Become More Difficult to Place a Suspect Behind the Keyboard
Chapter 10. Online Investigations
Introduction
Online Investigations
Capturing Webpages as Evidence
Chapter 11. Case Studies
Introduction
A Day in the Life of a Cybercriminal
The Life and Casework of a Cyber Investigator
Testifying to Your Work
No other version available