BATTLEFIELD DIGITAL FORENSICS
BDF_Battlefield_Digital_Forensics_final
BDF_Battlefield_Digital_Forensics_final
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Portable device<br />
found<br />
Laptop Type of device<br />
Phone, tablet, GPS, ...<br />
Status of device<br />
Turned ON<br />
Turned OFF<br />
Status of device<br />
Turned ON<br />
Screen is unlocked<br />
Laptop locked or<br />
logged off?<br />
Do NOT turn it on!<br />
Do NOT turn it off!<br />
YES<br />
Destructive<br />
process visible<br />
Laptop locked<br />
Abruptly pull the<br />
plug or remove the<br />
laptop battery<br />
NO<br />
Do NOT turn it off!<br />
Place in Faraday bag<br />
Place in Faraday bag<br />
with battery supply<br />
If possible, volatile<br />
data acquisition<br />
Turned OFF<br />
Support charging<br />
Gather any<br />
associated cables<br />
and accessories<br />
DOCUMENT<br />
SECURE, SUSTAIN<br />
Flowchart 4. Portable devices collection process.<br />
If the found device is a laptop, the SOF operator must check if the device is turned on or off. The power state<br />
can be determined as follows [27]:<br />
<br />
<br />
<br />
check for any LEDs showing activity;<br />
check for disks spinning;<br />
check for fan running;<br />
other signs of activity (feel for heat or vibrations, ...);<br />
<br />
check whether any connected output or input devices show any activity.<br />
Make sure that the laptop is switched off – some screen savers may give the appearance that the computer is<br />
switched off, but hard drive and monitor activity lights may indicate that the machine is switched on [28]. Be<br />
aware that some laptop computers may power on by opening the lid.<br />
44