Federal Forensics Group
Federal Forensics Group
Forensic Computer Investigations and Analysis
Federal Forensics Group
Investigative Process
Preliminary
The goal of a preliminary computer forensic investigation is to quickly examine the hard drive media to either recover a specific known file or to determine what kind of data recovery is possible. Additionally, it will determine if potential evidence exists which warrants a more thorough Level 1 or Level 2 examination.

In a preliminary exam, the original hard drive or media is viewed, but not copied. A preliminary computer forensic exam is limited in its scope and would not be sufficient for court room admissibility. A preliminary computer forensic exam is appropriate when the contents of the media or hard drive are known and the client needs a recommendation on strategies for moving forward with the investigation.
Level 1 Examination
A level one standard computer forensic investigation involves a detailed, methodical examination of the hard drive or media. A bit by bit copy of the original hard drive is created and then verified. For security purposes, the level 1 computer forensic exam takes place on the copy and the original is properly secured for safekeeping. The examination may focus on one or several aspects of the overall investigation.

For example, the client may seek to uncover specific evidence, or to prove certain files do not exist. Evidence may be incriminating or exculpatory in nature. We are always completely impartial and will report to you any evidence we find. A typical standard computer forensic investigation may focus upon:

  • Existing files
  • Deleted files
  • Extensive keyword or keyphrase searches
  • Extensive searches for particular file or evidence types
  • Internet browsing history
       - Sites visited
       - Graphics viewed
       - Cookies stored on computer
       - Files downloaded
       - Web mails sent and received
  • Email evidence
       - Outlook emails sent and received
       - Outlook Express emails sent and received
       - AOL mails sent and received
       - Deleted emails
       - Files sent and received
       - Other mail applications used
  • Typical business applications such as Microsoft Office
       - Files created in programs such as Word, Excel
       - Deleted files
       - Files sent and received
       - Financial data generated by QuickBooks, Intuit or other financial applications
  • Pictures created by digital cameras
  • File download applications (Kazaa, Morpheus, Napster, etc.)
Given the wide variances involved with media in hard drive recovery, a proper level 1 computer forensic investigation may take anywhere from 2-3 days or more. When we are in possession of the actual hard drive or media, we will provide a more accurate estimate of the time involved.

We do not take shortcuts. The software and examination methodology we use have been validated by numerous trial and appellate court rulings. It takes many hours to properly examine a computer and create a defensible set of reports and documents that will stand up to legal scrutiny.
Level 2 Examination
A level 2 computer forensic investigation is extremely comprehensive in nature. A level 2 exam is required when the client is looking for difficult-to-find evidence or is looking for specific exculpatory or incriminating evidence. Often, the data recovered can be corroborated with several pieces of evidence on the hard drive.

A level 2 computer forensic investigation is required when:
  • There are passwords that must be cracked
  • Data has been encrypted or deliberately hidden
  • There is an unusual hardware configuration
  • The system to be examined is a legacy system (the computer is old)
  • Elaborate cross-references need to be conducted to corroborate multiple pieces of data
  • A comprehensive analysis must be performed to establish patterns of activity or behavior
A level 2 examination encompasses all aspects of a level 1 exam, but focuses on a particular aspect of the investigation in order to help win your case. A level 2 examination is designed to withstand court-room cross examination. It generally involves extensive documentation and reporting tailored to the particular case.

Both Level 1 and 2 computer forensic investigations are designed to withstand scrutiny and cross-examination in a court of law.
Reports
A stellar examination process is pointless if the reports generated do not withstand legal scrutiny. We painstakingly prepare each forensic report to ensure clarity and accuracy. Our reports are designed to be understood by the lay-person.
1. Do not start the computer. Simply turning on a computer can destroy crucial evidence or render it inadmissable.
2. Secure the computer. If the computer is not running, place it in a secured area with controlled access.
3. Control Access. If the computer is running, contact us and will advise you proper procedure. Do not let anyone access the computer.
Federal Forensics Group
5777 W. Century Blvd., Ste. 1015, Los Angeles, CA 90045 •  310.318.1073 direct  310.388.1523 fax
Home | Services | Methods & Techniques | Data Recovery | Contact