Digital Forensics is a powerful tool to help in internal investigations and support in litigation. After a forensic image is acquired of a devise, the following items can be provided to aid in effort to determine next steps;
- List of USB devices (Thumb drive,IPhone, external hard drive etc.) installed on the device
- List of files that were deleted. Including the date the file was last accessed and believed deleted.
- Recovery of deleted files that were not overwritten.
- List of all files on the devices and critical metadata included (date the file was created, date it was last accessed, date it was modified and what user was logged into the device at the time.)
- Internet History Report
- Link File Analysis (search for any links showing that a file was moved to a USB device)