Digital evidence is collected from many sources including: computers, cell phones, PDAs, digital cameras, hard drives, CD-ROM, USB memory devices, just to list a few.
In order to avoid spoliation of crucial evidence, special care must be taken when handling and analyzing computer evidence.
When acquiring electronic evidence, preservation of evidence is vital
.
Acquisition of evidence starts by creating a forensic image. We create a stream copy of the entire media being imaged, which is created by using a write protection device or application to prevent contamination and maintain evidentiary status.
Types of data often considered as critical evidence in litigation include: - e-mail
- plain text and documents
- images
- calendar files
- databases
- spreadsheets
- digital faxes
- audio files
- animation
- websites
- computer applications
- viruses and spyware