Scenario*: You are a detective for the local police. You have some training in computer forensics.
The primary suspect in a murder investigation works at a large local firm. He is reported to have two computers at work in addition to one at home. His company has issued him a cell phone for business use, but you do not know if this is the only cell phone he has or uses.
You will be the first responder to both scenes.
So, what do you do? To get the discussion started:
Can Locard’s Exchange Principle be applied to a digital crime scene, in general? -to these digital crime scenes? Why or why not?
What do you need to do? What do you base the preliminary assessment on? -the platform? -the software? -the user’s Internet browsing history? -other?
Would the sniper forensics
perspective be useful?
What are the potential traps and pitfalls for you as the investigator?
What’s happening in the news right now to support your viewpoint?
Be prepared to both defend your position and challenge the position of others.
Your first post is due in Week 4 and all replies need to be submitted by the end of week 5.
* This scenario used Case Project 4-1 (Nelson and others, 2015, p. 180) as its starting point.
Required Readings
Text: Nelson, Phillips, and Steuart. Guide to Computer Forensics and Investigations
Chapter 2: The Investigator’s Office and Laboratory
Chapter 3: Data Acquisition
https://www-sciencedirect-com.library.esc.edu/science/article/abs/pii/S1742287605000940
https://dl-acm-org.library.esc.edu/doi/10.1145/1655737.1655740
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
