Collecting Evidence

  • Chapter
  • First Online:
Fundamentals of Digital Forensics

Abstract

Digital forensics is all about examining digital evidence, and that implies that you need to collect the evidence before it can be examined. Every action that you carry out on a computer will leave traces, and that contradicts with the facts that evidence must be handled in a way that ensures that it is not altered. This chapter discusses the key points of securing digital evidence in a forensically sound manner. Doing that ensures that the examination can be conducted in a way that does not contaminate the evidence. The concept of using a write blocker to create a forensic copy of the evidence is also introduced. The reminder of the chapter provides an in-depth discussion on live investigations, examining computers that are running. A model that can be used to plan forensically sound live investigations is presented as well as the constraints that must be taken into consideration when working with live evidence.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Springer+ Basic
EUR 32.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or Ebook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now
Chapter
EUR 29.95
Price includes VAT (Germany)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
EUR 67.40
Price includes VAT (Germany)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Hardcover Book
EUR 85.59
Price includes VAT (Germany)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free ship** worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

References

  • Lazaridis I, Arampatzis T, Pouros S (2016) Evaluation of digital forensics tools on data recovery and analysis. In: The third international conference on computer science, computer engineering, and social media (CSCESM2016)

    Google Scholar 

  • Oxford Dictionaries (2017) Definition of evidence in English. Available online: https://en.oxforddictionaries.com/definition/evidence. Fetched 6 Jul 2017

  • Tobin P, Le-Khac NA, Kechadi MT (2016) A lightweight software write-blocker for virtual machine forensics. Sixth international conference on innovative computing technology (INTECH) 2016. IEEE, New Jersey, pp 730–735

    Chapter  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Joakim Kävrestad .

Rights and permissions

Reprints and permissions

Copyright information

© 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Kävrestad, J., Birath, M., Clarke, N. (2024). Collecting Evidence. In: Fundamentals of Digital Forensics. Texts in Computer Science. Springer, Cham. https://doi.org/10.1007/978-3-031-53649-6_8

Download citation

  • DOI: https://doi.org/10.1007/978-3-031-53649-6_8

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-031-53648-9

  • Online ISBN: 978-3-031-53649-6

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics

Navigation