Podcast
Questions and Answers
What is one of the main services provided by the Digital & Multimedia Evidence Section?
What is one of the main services provided by the Digital & Multimedia Evidence Section?
Which sub-discipline is NOT mentioned in the Digital & Multimedia Evidence Section's capabilities?
Which sub-discipline is NOT mentioned in the Digital & Multimedia Evidence Section's capabilities?
What is crucial for the timely processing of DME examinations?
What is crucial for the timely processing of DME examinations?
Where is the Digital & Multimedia Evidence Section located?
Where is the Digital & Multimedia Evidence Section located?
Signup and view all the answers
What should individuals do if there are significant changes in the investigation?
What should individuals do if there are significant changes in the investigation?
Signup and view all the answers
Which of the following is NOT involved in DME examination services?
Which of the following is NOT involved in DME examination services?
Signup and view all the answers
Who should be contacted for inquiries regarding Digital & Multimedia Evidence?
Who should be contacted for inquiries regarding Digital & Multimedia Evidence?
Signup and view all the answers
What is the importance of timely submission of evidence for DME examinations?
What is the importance of timely submission of evidence for DME examinations?
Signup and view all the answers
What is a technique used to enhance specific details of a person or object in video analysis?
What is a technique used to enhance specific details of a person or object in video analysis?
Signup and view all the answers
Which of the following methods reduces the visual speed of a recorded video?
Which of the following methods reduces the visual speed of a recorded video?
Signup and view all the answers
What should be included in the digital multimedia evidence submission to assist analysis?
What should be included in the digital multimedia evidence submission to assist analysis?
Signup and view all the answers
What is the purpose of applying a date/time filter during the analysis of parsed data?
What is the purpose of applying a date/time filter during the analysis of parsed data?
Signup and view all the answers
Which of the following is a guideline for processing digital evidence?
Which of the following is a guideline for processing digital evidence?
Signup and view all the answers
What is a potential benefit of frame averaging in video analysis?
What is a potential benefit of frame averaging in video analysis?
Signup and view all the answers
What is a necessary step before submitting digital evidence for analysis?
What is a necessary step before submitting digital evidence for analysis?
Signup and view all the answers
Which of the following items is not required when submitting digital evidence?
Which of the following items is not required when submitting digital evidence?
Signup and view all the answers
What should a device be placed in to ensure proper protection during evidence packaging?
What should a device be placed in to ensure proper protection during evidence packaging?
Signup and view all the answers
What is one method that allows skipping the shielding step for device packaging?
What is one method that allows skipping the shielding step for device packaging?
Signup and view all the answers
What should be included on the DME Submission Supplement form?
What should be included on the DME Submission Supplement form?
Signup and view all the answers
What can be applied to parsed data unless otherwise directed?
What can be applied to parsed data unless otherwise directed?
Signup and view all the answers
What material should be used to wrap a device if a Faraday bag is not available?
What material should be used to wrap a device if a Faraday bag is not available?
Signup and view all the answers
What indication should be labeled on the storage bag if the battery has been removed?
What indication should be labeled on the storage bag if the battery has been removed?
Signup and view all the answers
What type of authentication information is important to provide for device analysis?
What type of authentication information is important to provide for device analysis?
Signup and view all the answers
How many times should aluminum foil be wrapped around a device for effective protection?
How many times should aluminum foil be wrapped around a device for effective protection?
Signup and view all the answers
Which type of device is included in the category of computer devices?
Which type of device is included in the category of computer devices?
Signup and view all the answers
What kind of information can be recovered from digital devices?
What kind of information can be recovered from digital devices?
Signup and view all the answers
Which of the following is a method for acquiring data from devices?
Which of the following is a method for acquiring data from devices?
Signup and view all the answers
What does Video & Image Analysis primarily focus on?
What does Video & Image Analysis primarily focus on?
Signup and view all the answers
What type of multimedia files can be analyzed from digital devices?
What type of multimedia files can be analyzed from digital devices?
Signup and view all the answers
From what devices can video recordings originate for analysis?
From what devices can video recordings originate for analysis?
Signup and view all the answers
Which option is NOT a consideration during data acquisition from a device?
Which option is NOT a consideration during data acquisition from a device?
Signup and view all the answers
What are some elements of user activity that can be tracked from digital devices?
What are some elements of user activity that can be tracked from digital devices?
Signup and view all the answers
What is the first action to ensure that a device remains usable during the seizure process?
What is the first action to ensure that a device remains usable during the seizure process?
Signup and view all the answers
What should be done to shield a device from communication networks?
What should be done to shield a device from communication networks?
Signup and view all the answers
When is it crucial to submit the device to the Central laboratory?
When is it crucial to submit the device to the Central laboratory?
Signup and view all the answers
What specific action should be taken if the device is powered off when seized?
What specific action should be taken if the device is powered off when seized?
Signup and view all the answers
Where can a UICC or flash memory card typically be found in mobile devices?
Where can a UICC or flash memory card typically be found in mobile devices?
Signup and view all the answers
Why is packaging a mobile device at the time of seizure recommended?
Why is packaging a mobile device at the time of seizure recommended?
Signup and view all the answers
Which of the following is NOT a recommended action when preparing a device for lab submission?
Which of the following is NOT a recommended action when preparing a device for lab submission?
Signup and view all the answers
What is a potential consequence of removing the UICC from the device?
What is a potential consequence of removing the UICC from the device?
Signup and view all the answers
Study Notes
Digital & Multimedia Evidence
-
The Virginia Department of Forensic Science (DFS) Digital & Multimedia Evidence (DME) Section provides examination services for information stored in analog or digital formats.
-
The DME Section is divided into three sub-disciplines:
- Computer Device Analysis
- Mobile Device Analysis
- Video & Image Analysis
-
The DME Section has capabilities that include preservation, repair, acquisition, processing/identification, analysis/verification, clarification, and reporting.
-
The DME Section can analyze information from devices including:
- Computers: servers, desktops, laptops, game systems, magnetic card skimmers, and "Internet of Things" (IoT) devices
- Mobile Devices: cellular telephones, tablets, and GPS navigation devices
- Digital Storage Devices: hard disk drives, flash memory, and optical discs
-
DME Section has the capability to acquire decrypted physical and logical data from a variety of devices.
Computer and Mobile Device Analysis
- Computer and Mobile Device Analysis involve examining electronically stored information originating from a wide variety of devices.
- Analysis of devices can result in the identification and recovery of a wide variety of information, including:
- Existing and previously-existing (deleted) data
- Data decryption and security measure identification or circumvention
- Electronic communications such as email, chat, text/multimedia messages, call logs, and contacts
- Multimedia files such as pictures, audio recordings, and video recordings
- Documents and spreadsheets
- User activity or usage patterns, such as web-browser activity, location information, device or application usage, file activity, timeline of events, and activity attribution.
Video & Image Analysis
- Video & Image Analysis involves the scientific examination of analog or digital video recordings, and print or digital still images.
- Devices analyzed include:
- Cellular telephones
- Hand-held video cameras
- Body-worn cameras
- Security/surveillance systems
- Dashboard cameras
- Home videos or digital cameras
- Analysis of video recordings or still images can result in:
- Existing and previously-existing (deleted) recordings and still images
- Confirmation of correct visual display
- Clarification (enhancement) of specific details of a person or object
- Clarification techniques include:
- Image deblurring
- Magnification (aka Zoom)
- Frame Averaging
- Reduction in playback speed
- Demultiplexing
- Redaction of sensitive information or material
Collection Guidelines
- Evidence descriptions should be listed on the Request for Laboratory Examination (RFLE).
- The Area of Interest (AOI) (i.e., requested information and/or time frame) being sought should be indicated on the DME Submission Supplement form.
Computer or Digital Storage Devices
- Evidence should be in a rigid container protected from extreme temperature and strong magnetic sources.
- Only submit relevant items to be analyzed.
- Provide this information on the DME Submission Supplement form:
- The area(s) of interest to be identified/recovered
- Any removable storage devices
- Any power cables/adapters/manuals
- Any required passcodes
- Any damage present
- Any access to or modifications made
- Authorization to utilize potentially destructive processes
- Unless otherwise directed, a date/time filter may be applied to parsed data encompassing a time frame beginning (at most) six (6) months prior to the offense date listed on the RFLE, and ending with the most recent date/time of activity identified within the parsed data.
Mobile Device Analysis
- Ensure the device stays powered on and is sufficiently charged – DO NOT ALLOW THE DEVICE TO POWER OFF OR REBOOT
- Shield the device from communication networks by putting the device into Airplane Mode, removing its UICC, and/or placing it in a shielded enclosure.
- Submit the device to the Central laboratory as soon as possible.
Mobile Device Seizure
- Power down the device via its interface or by long-pressing its power button and, if applicable, remove its battery.
- If the device is seized powered off, remove its battery and UICC (if applicable).
UICC and Flash Memory Cards
- It is important to determine if the device contains a UICC or flash memory card such as a microSD card.
- These storage devices should be indicated on the RFLE as additional items of evidence, typically as sub-items to the handset.
Mobile Device Packaging
- Place in an anti-static container (e.g., paper envelope).
- Place in a >3 mil thick shielded enclosure (e.g., "Faraday" bag) or wrap in aluminum foil (5 times with heavy duty or 10 times with standard thickness).
- Place in an outer storage bag (container) and seal
- Packaging kits may be available from a third party vendor for purchase.
Mobile Devices Continued
- Provide this information on the DME Submission Supplement form:
- The area(s) of interest to be identified/recovered
- Any removable storage devices
- Any power cables/adapters
- Any required passcodes
- Any damage present
- Any access to or modifications made
- Authorization to utilize potentially destructive processes
- Unless otherwise directed, a date/time filter may be applied to parsed data encompassing a time frame beginning (at most) six (6) months prior to the offense date listed on the RFLE, and ending with the most recent date/time of activity identified within the parsed data.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Description
Explore the crucial role of the Digital & Multimedia Evidence (DME) Section of the Virginia Department of Forensic Science. This quiz covers various sub-disciplines such as Computer Device Analysis, Mobile Device Analysis, and Video & Image Analysis, along with the capabilities involved in analyzing digital information from various devices.