Cell phones and computer hard drives are filled with information that can be used as evidence. This evidence can be quite helpful when investigating cases for court. However, sorting through the information contained on a phone or hard drive can be a laborious, expensive process. Luckily, there are some forensic tools out there that can be used to simplify the process of extracting information.
Trying to manually figure out where a person’s phone has been over a specific timeframe is a nightmare. Fortunately, when a photo or video is taken, the location and time is usually also saved. This information shows where the phone, and presumably its owner, was at the moment the photo or video was taken. WiFi hotspots at public places (coffee shops, stores, etc.) also save data location.
Passwords have the potential to be hundreds of alphanumeric digits and may include letters from different languages and even emojis. Until recently, existing technology was only able to test random combinations at around 60,000 passwords per second. The latest password cracking forensic tools are able to try about 7.7 million combinations per second. Password cracking has gone from taking weeks or months to only taking a few minutes or hours to complete.
Recovering Deleted Files
When something is deleted, it is never really gone. Often times, digital evidence can be found by restoring deleted files. New forensic tools have been developed to restore and extract those deleted files faster.
What to do after a mountain of data has been collected from phones and hard drives? It is important to have a thought out process, correct software, and possibly a forensic technician to proceed. One search method is to make a list of key words and perform a search of those words on texts, emails, documents, etc. Adopting the newest forensic tools for data recovery and analysis techniques helps streamline the process, reduces wasted time, and often reduces costs.
For more Tidbits & Thoughts, please click here.