December 2008
Intermediate to advanced
576 pages
13h 57m
English
Solutions in this appendix
A good investigator will collect as much evidence as possible to build a strong case. Traditional forensic techniques often involved unplugging the suspect system, taking it back to the lab, and analyzing it, a process commonly referred to as dead box forensics. But technology continually emerges and changes and investigative procedures must adapt to deal with these changes.
Pulling the plug may have been a good technique to use on older computers running older operating systems, but starting with OS 10.3 (Panther) and later, FileVault could be implemented on the system you are ...
Read now
Unlock full access