Digital investigation techniques :
James R Lyle, Barbara Guttman, John M. Butler, Kelly A. Sauerwein, Christina Reed, Corrine E. Lloyd · 2022
This document is an assessment of the current scientific foundations of digital forensics. We examined descriptions of digital investigation techniques from peer-reviewed sources, academic and classroom materials, technical guidance from professional organizations, and independently published sources. Digital investigation techniques are based on established computer science methods and when used appropriately are considered reliable. The process of evaluating, for example, the contents of a computer hard drive does not create information that was not there before the investigation started. However, because the field is rapidly changing, there are limitations that practitioners and stakeholders need to be aware of: (1) as with any crime scene not all evidence may be discovered; (2) when recovering deleted files, the results may include extraneous material; (3) examiners need to understand that as software (operating systems and applications) is revised the meaning and significance of digital artifacts created by different versions of the software can be different. In addition, because there are often multiple ways to search for information, two examiners may find different subsets of all potentially relevant information. The methods used in digital investigations are often not peer-reviewed in a formal process, but trustworthiness is established by members of the digital forensic community trying out proposed methods, testing, and circulating updates within the community. This process strengthens an examiner s awareness of the capabilities and limitations of their techniques.