The 5 Principles of Digital Forensics
# The 5 Principles of Digital Forensics 1. **Lawfulness** All evidence must be collected legally and ethically. Unauthorized access or unlawful searches can render evidence in…
19 published notes
# The 5 Principles of Digital Forensics 1. **Lawfulness** All evidence must be collected legally and ethically. Unauthorized access or unlawful searches can render evidence in…
# Core Principles of Forensic Science These principles form the philosophical foundation of all forensic disciplines—physical, biological, and digital. They explain *why* evidenc…
# Synthesis: Core Forensic Principles in Practice Today's session connected the foundational **[[Core Principles of Forensic Science]]** with the procedural **[[The 5 Principles …
# Evidence Acquisition Fundamentals Acquisition is the bridge between the *existence* of a digital trace and its *usability* as evidence. It is where the philosophical principles…
## Convergent vs. Divergent Thinking These two complementary modes of thinking describe how we approach problems and process information. ### Divergent Thinking - **Definition**…
The forensic analyst occupies a uniquely privileged position: they have the technical access to discover, preserve, and interpret evidence, but they also have the ability to manip…
In network forensics, the **footprint** is the impact an investigator leaves on the systems under examination. Every interaction with a live system modifies it in some way—just as…
**Direct evidence** is testimony from a **direct witness** who personally observed the act or event in question. It is based on firsthand human perception rather than inference fr…
**Hearsay** is an out-of-court statement offered to prove the truth of the matter asserted. Under the **U.S. Federal Rules of Evidence (FRE)**, hearsay is generally **not admissib…
**Business records** are documents or data that an enterprise routinely generates and retains as part of its normal operations, and that are considered accurate enough to guide ma…
**Network-based digital evidence** is digital evidence produced as a result of **communications over a network**. It is a subset of **[[Digital Evidence]]**, but it is distinguish…
**Real evidence** is a physical, tangible object that played a relevant role in the event being investigated. It is the kind of evidence a jury can see and touch, such as the murd…
The **TCP three-way handshake** is the process used by the **Transmission Control Protocol (TCP)** to establish a reliable, bidirectional connection between two hosts. It is a fou…
[[Circumstantial Evidence]] is evidence that does **not directly prove a conclusion**, but can be linked with other evidence to **deduce** what happened. It requires inference and…
**[[Best Evidence]]** is the **best available evidence that can be produced in court** to prove the content of a writing, recording, or photograph. Under the **U.S. Federal Rules …
PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …
# Baseline in Digital Forensics A **baseline** is a captured snapshot of a system's normal state under known-good conditions. It records what processes, services, network connect…
In forensic and analytical work, thinking is not enough. You must build a **testable chain** between your ideas and the evidence. ## The core loop 1. **Observe** — Notice someth…
# Maximum Transmission Unit (MTU) The **Maximum Transmission Unit (MTU)** is the largest size (in bytes) of a single protocol data unit that can be transmitted over a network lin…