Forensic Analysis
Beyond Push Button Forensics
Forensic software can process evidence, but examiner analysis is still required to validate findings and explain limitations.
Modern forensic tools can acquire a device, process amounts of data and organize the results into a searchable report. These capabilities are essential. Generating a report is not the same as conducting a forensic analysis.
A forensic tool can only display the data it recognizes and successfully parses. If the software does not understand an application, database, field or file structure relevant information may not appear in the report even though it still exists within the extraction.
The software processes the data.
The examiner must determine what the data means.
No Tool Can Parse Everything
Mobile devices contain a constantly changing collection of applications. Developers regularly change database structures, storage locations, encryption methods and synchronization behavior. Operating system updates can also affect how data is created and retained.
Several excellent forensic platforms are available. No single tool can effectively parse every application, every version and every possible data structure.
A tool may successfully identify the database used by an application while missing related information stored in journal files, caches, backups, notification records, system databases or cloud synchronization data.
A clean forensic report does not necessarily mean that all relevant information was recovered. It may only mean that the tool displayed everything it knew how to interpret.
Relevant Data May Exist Elsewhere
Information on a device is rarely stored in only one location.
A message may leave records in the application database, attachment folders, notification data, synchronization records, temporary files, backups or database journal files.
Location information may appear in photographs, navigation applications, browser records, system services, fitness applications and other application databases.
When the automated report does not fully answer the question the examiner should examine the underlying files and databases rather than assume the information does not exist.
The absence of an artifact from a report is not always the same as the absence of that artifact from the extraction.
Evidentiary Results Should Be Validated
The Scientific Working Group on Digital Evidence states:
"Items that may be of evidentiary value and deemed admissible in court cases should be validated."
One recognized method of validation is to examine the data where it resides within the device extraction. Many forensic tools identify the source file, database, table or record used to create a parsed artifact.
This allows the examiner to verify that the software located the data and interpreted it properly.
For example the examiner may need to confirm the source database, timestamp format, time zone conversion, message direction, status field, text encoding or relationship between linked records.
This is particularly important when the software labels an artifact as deleted, sent, received, created, accessed or modified. Those labels should not be accepted without understanding the underlying data and what the relevant field means within that specific application.
A software generated label is not automatically a conclusion.
The Examiner Must Understand the Tool
Tool specific training is valuable. Examiners should understand how to operate the platforms they use and recognize their capabilities and limitations.
However knowing how to use one software interface is not enough.
When automated parsing is incomplete the examiner may need to work with databases, file systems, timestamps, encoded data, application folders and journal files.
This is why broader forensic education and vendor neutral training remain important. They help an examiner understand the evidence independently of how one particular platform chooses to display it.
The software should assist the examination. It should not define the limits of the examiner's knowledge.
The Examiner Is Responsible for the Analysis
Forensic software does not understand the question.
It cannot independently determine whether missing information resulted from deletion, synchronization, unsupported parsing, routine application behavior, database maintenance or the passage of time.
Those conclusions require examiner judgment.
A qualified examiner should be able to explain where the data came from, how it was interpreted, whether it was manually verified, what limitations affected the examination and which conclusions cannot be reached.
Digital evidence does not always provide an answer. A defensible opinion must be limited to what the evidence supports.
Push button processing is efficient.
Push button analysis does not exist.
Forensic tools can organize valuable evidence, but they cannot guarantee that every relevant artifact has been identified or interpreted correctly.
It is the examiner's responsibility to look beyond the report, examine the underlying data, validate findings and explain both the evidence and its limitations.
The tool processes the data.
The examiner performs the analysis.