How to catch a cybercriminal: Tales from the digital forensics lab

How to catch a cybercriminal: Tales from the digital forensics lab

What is it like to defeat cybercrime? A peek into how computer forensics professionals help bring cybercriminals to justice.



Many people ask me about what it was like working for law enforcement. More often than not, however, they are actually enquiring about how computer crime is truly investigated. Whether it’s questions about how accurately it is portrayed on TV, the constraints felt by the police, the associated myths, or about how to find closely guarded tactics and secrets, people seem to have a morbid fascination with the dark world of digital forensics.


Before joining ESET, I was a computer forensics examiner for the UK police for nearly a decade. My job was to perform deep forensic analysis of computers, hard drives, phones and other devices that had been instrumental in crimes, including murder, child abuse and fraud. With some of the best forensic tools at my disposal, I delved not only into these devices but, metaphorically, into the lives of the suspects who had been locked up or released on bail. Performing such an analysis could take anything from a day to a few months, depending on what was required, the state and security of the storage medium, or more importantly, the magnitude of the case.


From being able to locate a suspect’s Google search history, their photo galleries, their online chats, and even their deleted items, once I was into the devices, I was able to see a lot more than just the data on the drives. Going through a person’s computer or phone is like going through their minds – it is intense. And people would ask me things like, “is it just like in the movies?” or, “can you ..

Support the originator by clicking the read the rest link below.