http//
For those that are new to the field, check out what a digital forensics witness goes through..I couldn't say if this would be 'typical' of the process, but a real eye opener none the less.
Thanks, I have been searching the forums for this post for some time now.
Thanks for the video.
Joel.
- "Do you use different forensic applications other than cellbrite to evaluate whether there is data on the sim card that can be retrieved?"
- "It's nearly a process of removing the sim card from the back of the phone device and plugging it in to the cellbrite that accommodates the simcard, and instruct the cellbrite device as you scroll through the menu options for data extraction that it recognise that now it have a sim card to look at and it will extract the data from the simcard"
In other words that actually answers the question No roll
So, if i understand correctly standard practice is not to look at the internal memory storage of a phone for call logs, messages (etc) - it all focus on the, maby 64K, Sim card and what is stored on that? If so, there is plenty of room for improvement in the world of mobile phone forensics.
So, if i understand correctly standard practice is not to look at the internal memory storage of a phone for call logs, messages (etc) - it all focus on the, maby 64K, Sim card and what is stored on that? If so, there is plenty of room for improvement in the world of mobile phone forensics.
Mobile telephone evidence and examination as a discpline in my view should be open to those who wish to work the 'highest standards' (derived from knowledge, skill and experience) because that is the perception that person wants to be held out to the rest of the world by working in our field of forensic endeavour.
Where an examiner assumes or is under the belief a 'tool' possesses the pre-requisite range of knowledge, skill and experience and equally assumes or believes those obligations are met just by placing a 'DUT' into or connecting to a 'tool' really should not be giving evidence.
Hi,
From my own experience and processes and that of other examiners (which include the sausage factory variety), this is definitely not the case.
So, if i understand correctly standard practice is not to look at the internal memory storage of a phone for call logs, messages (etc) - it all focus on the, maby 64K, Sim card and what is stored on that? If so, there is plenty of room for improvement in the world of mobile phone forensics.