WHAT IS FORENSIC ANALYSE?
Total operations made for digital analyse of any information system to present it court, legal document in order to prove guiltiness or innocence. As a summary of process below may be presented; before analysing all record environments (hard disc, memory card, USB memory, mobile phone, SIM card, GPS navigation device etc.), one to one cloning should be made in laboratory. The gathered clone is same copy of original record environment and while imaging a unique hash (MD5 or SHA) value is calculated proving even a tiny change has not occurred on evidence. By this way the validity of evidence is kept as hash code will not change – in the case of intervention the hash code will change so it is not possible to make any operation on the evidence. Also, in order to prevent any change risk on evidence such as virus, user fault etc. while imaging original environment and while investigating on the evidence write-protect extra connection apparatus (write-blocker) is used.