The 5 Principles of Digital Forensics

# The 5 Principles of Digital Forensics 1. **Lawfulness** All evidence must be collected legally and ethically. Unauthorized access or unlawful searches can render evidence in…

Core Principles of Forensic Science

# Core Principles of Forensic Science These principles form the philosophical foundation of all forensic disciplines—physical, biological, and digital. They explain *why* evidenc…

Synthesis: Core Forensic Principles in Practice

# Synthesis: Core Forensic Principles in Practice Today's session connected the foundational **[[Core Principles of Forensic Science]]** with the procedural **[[The 5 Principles …

Evidence Acquisition Fundamentals

# Evidence Acquisition Fundamentals Acquisition is the bridge between the *existence* of a digital trace and its *usability* as evidence. It is where the philosophical principles…

Convergent vs Divergent Thinking

## Convergent vs. Divergent Thinking These two complementary modes of thinking describe how we approach problems and process information. ### Divergent Thinking - **Definition**…

Forensic Analyst as Insider Threat

The forensic analyst occupies a uniquely privileged position: they have the technical access to discover, preserve, and interpret evidence, but they also have the ability to manip…

Footprint (Forensic)

In network forensics, the **footprint** is the impact an investigator leaves on the systems under examination. Every interaction with a live system modifies it in some way—just as…

Direct Evidence

**Direct evidence** is testimony from a **direct witness** who personally observed the act or event in question. It is based on firsthand human perception rather than inference fr…

Hearsay

**Hearsay** is an out-of-court statement offered to prove the truth of the matter asserted. Under the **U.S. Federal Rules of Evidence (FRE)**, hearsay is generally **not admissib…

Business Records

**Business records** are documents or data that an enterprise routinely generates and retains as part of its normal operations, and that are considered accurate enough to guide ma…

Digital Evidence

**Network-based digital evidence** is digital evidence produced as a result of **communications over a network**. It is a subset of **[[Digital Evidence]]**, but it is distinguish…

Real Evidence

**Real evidence** is a physical, tangible object that played a relevant role in the event being investigated. It is the kind of evidence a jury can see and touch, such as the murd…

TCP Three-Way Handshake

The **TCP three-way handshake** is the process used by the **Transmission Control Protocol (TCP)** to establish a reliable, bidirectional connection between two hosts. It is a fou…

Circumstantial Evidence

[[Circumstantial Evidence]] is evidence that does **not directly prove a conclusion**, but can be linked with other evidence to **deduce** what happened. It requires inference and…

Best Evidence

**[[Best Evidence]]** is the **best available evidence that can be produced in court** to prove the content of a writing, recording, or photograph. Under the **U.S. Federal Rules …

PowerShell EventLog CmdLets

PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …

Baseline in Digital Forensics

# Baseline in Digital Forensics A **baseline** is a captured snapshot of a system's normal state under known-good conditions. It records what processes, services, network connect…

Hypothesis-Driven Analytical Investigation

In forensic and analytical work, thinking is not enough. You must build a **testable chain** between your ideas and the evidence. ## The core loop 1. **Observe** — Notice someth…

Maximum Transmission Unit (MTU)

# Maximum Transmission Unit (MTU) The **Maximum Transmission Unit (MTU)** is the largest size (in bytes) of a single protocol data unit that can be transmitted over a network lin…