NetSieben Logo
Center Image
Right Image
Home
-----
About Us
-----
Services
-----
Products
-----
Partners
-----
Store
-----
Contact Us
 
Shadow
P
SEARCH THIS SITE

P
-----
 
Assessment
Remediation
Managed Service
Computer Forensics


P
Forensics Methodology

NetSieben uses well established forensic methodology that allows it's engineers to identify and extract information relevant to the case. They preserve the chain of evidence and safeguard the admissibility of the evidence. NetSieben is skilled in working with a variety of hardware platforms and a variety of storage media formats.

Our engineers can acquire data from multiple operating systems including Windows, DOS, Mac OS X and Linux. They can retrieve data from multiple file systems, including Windows FAT12, FAT16, FAT32, NTFS, Macintosh HFS, HFS+, Sun Solaris UFS, Linux EXT2/3, ReiserFS, BSD FFS, AIX JFS, CDFS, UDF and ISO 9660.

NetSieben engineers can extract Emails from multiple sources, including Outlook PSTs/OSTs ('97-'03), Outlook Express DBXs, Lotus Notes, Yahoo, Hotmail, Netscape Mail, MBOX, as well as, AOL 6.0, 7.0, 8.0 and 9.0 Personal File Cabinets (PFCs). They can examine browser cache and history, retrieve deleted evidence from encrypted, compressed and password protected files and media.

NetSieben will determine the possible source and locations of relevant data by identifying obvious and hidden sources such as deleted files and slack space of a file system.

Once the identification of the data location is complete, NetSieben will safely gather and document the evidence for further examination using the following processes:

  1. Secure the subject system from being tampered.
  2. Make byte-by-byte copies of all magnetic and optical media.
  3. Create digital signatures of files and disk images to ensure that any modification will be detected.
  4. Verify the electronic data signature and rechecked it each time evidence file is accessed.
  5. Identify and recovery all files including those which were deleted.
  6. Access/Copy hidden, protected and temporary files.
  7. Study 'special' areas on the magnetic media (eg: residue from previously deleted files).
  8. Investigate data/settings from installed applications/programs.
  9. Assess the system as a whole, including its structure.
  10. Consider general factors relating to the user activity.
  11. Create a detailed report for the customer.
  12. Store data images in secure vaults for later examination until the investigation is complete.
  13. Ensure data is stored in a climate controlled environment, away from harmful influences such as magnetic fields.
  14. Restrict access to authorized personnel only.
  15. Provide data to the court appointed authorities in the format requested.

NetSieben can assist with collection, examination and preservation of electronic evidence in both legal and internal corporate investigations. Our company can also assist companies and individuals in data and password recovery.



For more information or pricing please call us at (866) 395-1047 or fill out this secure form.



   
Home   ::   Company   ::   Contact   ::   Sitemap
Pixel
©2006 NetSieben Technologies Inc. All Rights Reserved.
footrowmid
Pixel
 
Pixel
Pixel
Pixel
Pixel