Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

When You Think Digital Data is Gone Forever, All is Not Lost
Forensic Magazine ^ | October 08, 2021 | Heather Mahalik, Paul Lorentz

Posted on 10/09/2021 11:35:28 PM PDT by nickcarraway

What do you do when you know a crucial piece of digital evidence should be somewhere in a phone’s file, or in the Cloud, or in the social media account – yet it’s nowhere to be found? What are your options for finding that text message or photo?

This scenario is a fairly common one for forensic examiners – and one you should be aware of as you climb up the law enforcement career ladder. We estimate that in perhaps 40 percent of cases, examiners have to grapple with the fact that key pieces of data have been deleted (intentionally or accidently) or have just gone missing.

Here’s the good news: The technology that helps digital forensic examiners unearth evidence also includes highly advanced tools for data recovery, such as data carving, described below. With access to devices, and the ability to perform data extractions, law enforcement has a good chance of recovering data that can bring criminals to justice or exonerate the innocent.

The Basics Of “Data Carving” With the right technology, digital forensic examiners can use a technique called “data carving” to piece together evidence that appears lost. It’s more of an art than a science, albeit one where examiners rely on technology to perform their “magic.” Today’s technology solutions allow examiners to conduct data carving in different ways, but on a high level, examiners look at a piece of data and try to recover parts or portions of that data that have gone missing or been deleted. This applies to computers, phones, and almost any type of media or data you’re dealing with. (For more basics on data carving, listen to our recent webinar on the subject.)

There are always advantages and disadvantages as to how any digital forensics vendor implements data carving methodologies. But regardless of which solution you’re using, the carving process can help recover data, piece data back together that’s been fragmented, and search for data in spots where it wouldn’t normally be stored. Without delving too deep into the technical aspects, basic file signature carving or “search” functionality is common among most tools. Where things start to branch out is in the proprietary methods, or “magic.”

Here’s an example of using data carving to find a deleted photo. If the picture gets sent as part of a text message, even though it’s deleted from the camera roll, it could be embedded in the chat application’s database file. And if the tool does a proper “carving,” examiners can potentially start digging into some of these files and pull them out. Even though the picture appears to be deleted, it may still be on the device in some other form or location. It’s simply knowing where to look for it.

Best Practices For Finding Missing Evidence Here are some standard operating procedures that every examiner should follow:

Look for what you don’t know is missing. Yes, this does indeed seem counterintuitive: How can you find what you’re looking for if you don’t exactly know what you’re looking for? In many cases, witnesses or victims may tell you they sent photos and messages to suspects or that they received such messages, giving you a solid lead about the existence of a piece of evidence. But this isn’t always the case.

This is where technology can be a big help because it helps bring pieces of evidence to the forefront that can deliver more insights about a case.

Start investigating digital evidence as soon as possible. Say a witness deleted a photo they didn’t think was important to an investigation – but forensic examiners think it could be. If it takes a month to investigate the device’s data, the chances the data may be overwritten are very high. The difference between doing forensic data extractions within 24 hours versus waiting a week or a month is significant. Modern digital operating systems have mechanisms for cleaning up files that aren’t being used. You don’t want these clean-up tools to remove a useful piece of evidence before you’ve had time to consider it. The longer you wait to extract/acquire the data, the lower your chances will be of recovering it.

Pieces of evidence can make a difference – so they’re worth tracking down. An incomplete piece of digital evidence can still have value. Sometimes you don’t have that full-on smoking gun – you just have the building blocks of a case built on circumstantial evidence. It may be that a suspect’s act of deleting a piece of evidence speaks to the person’s intention to commit a crime. Deleting evidence can speak volumes to a court.

This strategy is, in part, how investigators for the South Wales Police in the United Kingdom helped put together a case against a person suspected of distributing indecent images of children. Officers received a tip that the suspect was using file-transfer services such as Mega and Telegram to share images. Using Digital Intelligence tools, investigators found artifacts of both Mega and Telegram, demonstrating that the person had deleted the apps. The discovery inspired investigators to keep searching for the indecent images, which they found in a secured folder. (The case is ongoing and may come to court by fall 2021.)

Create standard operating procedures. The SOPs that investigators or frontline officers implement will significantly impact the likelihood of success that the forensic lab examiner will have down the line when trying to bring lost evidence to light. The SOPs will reduce the likelihood that officers or examiners themselves will inadvertently delete data – and yes, that can happen.

Also, the SOPs that dictate how quickly digital evidence is examined can help reduce the chance that a device could be remotely wiped by a suspect – and yes, this can happen, too.

We don’t want to paint too rosy a picture of the ability to retrieve every lost piece of data 100 percent of the time – what with encryption now commonplace, and scenarios including badly damaged hardware, some searches may yield little. We’ve seen forensic examiners get data off of phones that had been at the bottom of a lake for a month, or piece together circuit boards that were ripped in half. So the possibility is always there.

One more thing to remember is cloud data. If data is on a phone, it’s likely stored somewhere else as a backup. The Cloud is perhaps the ultimate storage backup and a key source for what might at first glimpse have appeared to be “lost data.”

Finally, it’s important to remember that you’re not in this alone. Cellebrite has helped investigative teams all over the world establish the right processes and SOPs to make investigations run more smoothly, so don’t hesitate to reach out for advice. As a trusted partner, we’re always here to help.


TOPICS: Computers/Internet
KEYWORDS:

1 posted on 10/09/2021 11:35:28 PM PDT by nickcarraway
[ Post Reply | Private Reply | View Replies]

To: nickcarraway

Will this work if you burn a phone to cinders or disassemble a hard drive and smash the platters to slivers, then pop them into a microwave oven for a few seconds?


2 posted on 10/10/2021 12:55:10 AM PDT by Rocco DiPippo (I)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rocco DiPippo

Yes, from the article, “If data is on a phone, it’s likely stored somewhere else as a backup.”


3 posted on 10/10/2021 1:08:49 AM PDT by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act)
[ Post Reply | Private Reply | To 2 | View Replies]

To: All

With a “backdoor” that almost certainly exists for every device, it’s impossible to proove what is genuine and what’s planted?


4 posted on 10/10/2021 1:10:43 AM PDT by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mr Radical

How about if you run a Google-free custom OS and upload nothing to the cloud and do not use text messaging at all?


5 posted on 10/10/2021 1:13:48 AM PDT by Rocco DiPippo (I)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Rocco DiPippo

Ask Hillary


6 posted on 10/10/2021 5:43:44 AM PDT by SMARTY (Republics decline into democracies & democracies degenerate into despotisms. Aristotle)
[ Post Reply | Private Reply | To 2 | View Replies]

To: nickcarraway

OK, so use it to read hillary’s “wiped” drives and put her in prison.


7 posted on 10/10/2021 5:52:20 AM PDT by I want the USA back (Buy a Let's Go Brandon! sticker. Show your disdain for the maniac in the White House. I did.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rocco DiPippo

There are non-google search engines and VPNs.


8 posted on 10/10/2021 7:08:48 AM PDT by cpt_dave
[ Post Reply | Private Reply | To 5 | View Replies]

To: SMARTY

You won best comment of the day!


9 posted on 10/10/2021 8:19:32 AM PDT by Rocco DiPippo (I)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Rocco DiPippo

😉


10 posted on 10/10/2021 8:51:05 AM PDT by SMARTY (Republics decline into democracies & democracies degenerate into despotisms. Aristotle)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Rocco DiPippo

I don’t know; but I should think that if a device communicates/transmits anything to an open network “interweb” then that data will be stored somewhere.


11 posted on 10/11/2021 12:50:52 AM PDT by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act)
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson