The five phases of recovering digital evidence
This is the second post in a series about the five phases of recovering data structures from a stream of bytes (a form of digital evidence recovery). In the last post we discussed what data structures were, how they related to digital forensics, and a high level overview of the five phases of recovery. In this post we’ll examine each of the five phases in finer grained detail.
In the previous post, we defined five phases a tool (or human if they’re that unlucky) goes through to recover data structures. They are:
1. Location
2. Extraction
3. Decoding
4. Interpretation
5. Reconstruction
752 views
Post new comment