Have your company secrets been stolen? Has your customer information been compromised by malicious people? Are you receiving insulting e-mails targeting your company or your personality? Have your customers' bank accounts been emptied? Has your organization's website been hacked? Have your company computers been used for illegal activities? Do you have employees that you suspect of performing unauthorized actions?
As ADEO, Turkey's leading company in forensic informatics which has proven itself with the high success rate it has achieved so far in the elucidation of cybercrimes with its experienced forensic informatics experts, we are at your side in all your needs regarding forensic informatics.
What is Forensic Informatics?
Forensic informatics covers the processes of collecting, storing and analyzing digital data in accordance with the requirements of evidence and submission to the court.
- Collect Digital Evidence
- Preserve Digital Evidence
- Analyze Digital Evidence
The chain of custody principle requires that the digital evidence collected within the scope of this service must be collected in a manner that ensures its integrity and authenticity and it must be documented and tracked to show the custody of the evidence from the point of collection to the point of analysis or presentation in court. This is essential to ensure that the evidence is admissible in court and has not been tampered with or altered in any way.
The digital evidence and information that can be collected within the scope of this service include:
• Forensic copies of systems affected by the cyber attack
• Memory images of systems affected by the cyber attack
• Volatile data (running applications, open network connections, etc.) or other sources of digital evidence needed in incident response (incident logs, file system records, etc.) to be obtained through live inspection on systems affected by the cyber attack
• Raw packet data or network flow data to be obtained over the network in case the cyber incident continues
Other types of evidence (e.g. operating system event logs, file system logs, network flow data, etc.) within the types of evidence listed above and used during the analysis of cyber incidents are examined within the scope of this service if needed. The examination is carried out in forensic laboratories with internationally recognized hardware and software and by experts with internationally recognized certificates.
Forensic Investigations
- Disc images
- Memory images
- Malicious applications
- Network data
Why is Forensic Informatics Investigation Conducted?
The discovery, recovery, or retrieval of existing data in IT systems, including deleted, encrypted, or damaged files and information can be crucial in legal proceedings and litigation. Many devices that we use daily including personal, family and professional information stored on these devices, have the potential to serve as evidence in criminal or civil cases. Information stored on various devices such as mobile phones, computer disks, MP3 players, CDs, DVDs, flash drives, SIM cards, servers, and modems can provide clear evidence of any event that has occurred.
In many criminal and civil cases, electronic evidence obtained from digital media is increasingly being used as evidence in court decisions. As a result, we see forensic investigations of digital devices being conducted not only for IT crimes, but also for any crime involving the use or involvement of an information system such as commercial or divorce cases. These investigations can provide crucial evidence in legal proceedings and litigation.
With the introduction of technology into all areas of our lives, it is important to remember that the evidence that can be obtained through these technologies has also increased and that many incidents are illuminated with digital evidence obtained through these technologies.
Forensic Investigation Steps
A forensic investigation basically consists of four substeps.
1- Identifying/Detecting Digital Evidence
During the first stage of the digital evidence life cycle, experts in information crimes identify and detect potential evidence. One of the critical factors during this phase is protecting volatile data which refers to data stored in temporary recording zones on computer systems and is reset when the power is cut off.
2- Preserving Digital Evidence
After the evidence has been successfully collected, the preservation phase comes. This stage can be addressed in two dimensions:
- Digital preservation encompasses a variety of mechanisms to prove that the evidence has not changed since it was first received and that its integrity has not been compromised. One of the most commonly used techniques is the cryptographic hashing of data. By using hash functions such as MD5, SHA1, etc., the digital integrity of the data can be protected.
- Physical preservation, on the other hand, involves transporting the evidence to the place where it will be examined without any deterioration, storing it in suitable environments until the trial and preventing any deterioration during transport to the court. Ideally, the evidence should be transported or stored in environments similar to the conditions in which it was collected. It's also important to label and seal all evidence properly after it has been packaged.
3- Analyzing Digital Evidence
The analysis phase of digital evidence is usually carried out by forensic informatics experts. After all the evidence obtained in the appropriate environment under appropriate conditions is collected and gathered together, the first thing to be done is to make exact copies and protect the originals. Usually, there are four copies: One for the court, the second for analysis, the third for the prosecutor and the fourth for the defense. All procedures and analyses to be carried out should be planned in advance, documenting which persons carried out which procedures on which evidence and digital signatures should be added to the documents to verify the experts. The analysis phase requires the most intensive technical knowledge and takes the longest time.
4- Presenting Digital Evidence
After all examinations are completed, the final stage is the presentation of the collected evidence to the court. All reports and documents prepared are collected together and documents are created in the appropriate format for the presentation of the evidence to the court. All procedures must be carried out meticulously and all processes must be clearly expressed in the document. All systems used to ensure the integrity and verification of the evidence should be described in detail.