Recovering Data
Much of the evidence a forensic investigator collects is stored as digital files on storage media. The general process of engaging in investigative activities to find and recover digital data for evidence is called e-discovery, or electronic discovery. E-discovery is an iterative process of examining storage media, searching for items of interest, identifying likely items that may have value as evidence, and then recovering those items. While some data may remain intact and readily visible to common tools, some data may have been deliberately deleted or be stored on damaged media. Part of a digital forensic investigator’s activities involves identifying and recovering data that is not easily accessible, for which the common term ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access