The recovery and examination of material found in digital devices, including deleted files and file metadata. The 2005 arrest of BTK killer Dennis Rader followed the recovery of identifying metadata embedded in a Microsoft Word document he had sent investigators on a floppy disk.
Facts
What It ExaminesData recovered from computers, storage media, phones and networks, including deleted files, file metadata, communications and activity logs, preserved and analyzed for use as evidence. 1 Formalized YearSourced to the subject's own accountDated to the FBI's Computer Analysis and Response Team, an early institutional formalization; the discipline itself developed gradually rather than on a single date. Known LimitationSourced to the subject's own accountEncryption is a major constraint on examination: it can prevent investigators from locating pertinent evidence by keyword search or from accessing a device at all. 2 Cross-Tradition Connections
Associated With
A computer itself is a source of evidence in cybercrime investigations, the province of digital forensics.
Cases Where Used
Metadata recovered from a floppy disk identified Dennis Rader in 2005.
Digital forensic examination of Ross Ulbricht's seized laptop, including an in-use unencrypted session, produced much of the evidence at trial.
Sources
Reader Challenges (0 open reader challenges)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.
View At A Past Year
The atlas records no dated fact of its own for this entry, so there is no other year to choose.