|
Things that computer forensics investigator looks for
A computer forensics investigator looks for many things and can find
many things on a computer. The best thing about computer forensics is that once
something has been saved on a computer you can’t completely get rid of
it. There is a chance that even if someone tried to burn their computer that
the information on the computer could still be found by a computer forensics
investigator. The most evidence that is usually found is the attempt that was
made to remove the data.
Computer forensics investigators can find many different types of files on computers.
One type of file that a computer forensics investigator can find is saved files.
These files are data files that exist in a form that can be used often. Most
computer forensics investigators will look for files that are hidden in strange
directories or even marked hidden on the system.
Computer forensics investigators can find files on a computer system that have
been deleted. When files are deleted they are not affected or defaulted at all.
The operating system is just told to ignore that it exists and a computer forensics
investigator has the information to recall all the information that is deleted.
Other files that can be found by a computer forensics investigator are temporary
files. If you get a large number of electronic documents, the computer forensics
investigator uses programs to cull them for review.
This is usually done by providing him with key words or phrases that will be
found in the documents of interest. Once the documents are found that he is
looking for he can then do what is needed to view them. The most common report
of this type is a time line of document creation, editing and reading. This
is one of the ways that a computer forensics investigator can find and look
at data on your computer that you may not realize is still there.
|