|
Emailing Adult Material
- Connect OnScene Investigator

- Perform email search

- Copy email files such as, outlook.pst, inbox.mdb, note.nsf and other relevant files

- Open email files and search for images
- Check the folders in \Local Settings\Temporary Internet Files\Content.Outlook (or Content.MSO)

- If evidence is found create an image of the drive to an external USB hard drive

Viewing Adult material via the internet
- Connect OnScene Investigator

- Open hard drive and browse to
Internet Explorer -[username]\Local Settings\Temporary Internet Files\Content.IE5
Mozilla - \Documents and Settings\[username]\Local Settings\Application Data\Mozilla\Firefox\Profiles\[profilename]\Cache

- Set OnScene Investigator to thumbnail view and search for incriminating images

- Perform browser history search using OnScene LHF to create a report on the users internet history

- If evidence is found create an image of the drive to an external USB hard drive

IP (Intellectual Property) Theft
- Connect OnScene Investigator

- Search for keywords that match the data theft

- Check for links to hotmail, gmail, yahoo mail and other various webmail access

- Check the cache for getmsg{#}, compose, gmail, inboxlight[#] cached page
- Check the folders in \Local Settings\Temporary Internet Files\Content.Outlook for documents viewed in Outlook

- If evidence is found, create an image of the drive to an external USB hard drive

Cyber-Stalking/Harrasment
- Connect OnScene Investigator

- Perform email search

- Copy email files such as, outlook.pst, inbox.mdb, note.nsf and other relevant files

- Open the copy of outlook.pst and search for incriminating emails
- Perform browser history search using OnScene LHF to create a report on the users internet history

- Check for access to hotmail, gmail, yahoo mail and other various webmail access

- Check the cache for getmsg, compose, gmail, inboxlight cached page
- Check the folders in \Local Settings\Temporary Internet Files\Content.Outlook for documents viewed in Outlook

- Open hard drive with Windows explorer

- Navigate to Content.IE and view cache as thumbnails to search for incriminating images (eg, pictures of victim)

- If evidence is found create an image of the drive to an external USB hard drive

Data Misuse (corporate crime)
- Connect OnScene Investigator

- Perform email search

- Copy email files such as, outlook.pst, inbox.mdb, note.nsf and other relevant files

- Open outlook.pst and search for incriminating emails
- Perform search for common document types (Word, Excel, Quickbooks, etc)

- Check if .lnk files are available that point to the stolen data being copied to or from a removable drive

- Copy files to investigator’s computer and/or create an image of the drive to an external USB hard drive.

Using Peer-to-Peer clients
- Connect OnScene Investigator

- Search for P2P applications
- Check common download folders

- <Perform search for common download file types

- If files are found, open with Windows explorer, check contents of downloaded files

-
If evidence is found, create an image of the drive to an external USB hard drive

|