2.2.2 Evidence Searching Phase

  •  Varies case to case.
    • Internet :- browser history , cache files , downloads 
    • OS :- presence of root kits , user accounts , installed software
  • Know the case -> list possible areas/locations of contact -> investigate that areas/locations
  • Search Techniques
    • Name of the file
    • Type of the file
    • File related Timestamps
    • #values in case of known files. 

2.3.2 Essential & Non-essential data