"

Main Body

Chapter 14: The investigation

Much has happened in the scenario. A series of profoundly serious crimes have been identified with many references to the available technology. There is also activity where technology may capture events, which are not directly referenced, to expand your critical thinking.

To an experienced detective, this form of crime would have been solved by a series of methodical steps and old-fashioned detective work. Due to the complexity of the crime and multiple scenes of activity, initial scene examination and evidence examination would take several days, allowing Sledge to dispose of evidence he took from Alex after his death if he wanted to, or thought of it. Forensic examination of the digital evidence takes time, especially if the storage capability of a device is large and applications and storage are based on cloud service accounts. Access to data can be complex and involve a number of actions such as obtaining passwords and gaining lawful authority to access devices, especially with cloud computing where the evidence may be located in a foreign jurisdiction.

There is plenty of information that an experienced team of detectives could use to solve this crime without relying on technology, however, as technology exists all around the scenes and suspects and this book has been written to help understand and apply technology in crime scenes, we will use it.

As this scenario contains multiple items of technology, we will review and apply the data obtained by these devices. Not all will be relevant or be able to advance the investigation, and this is the same for any items seized within a scene. In reality, some digital evidence may conflict with others, and there are legitimate reasons why this may be so, such as time zones on devices being set to different regions by the manufacturer or user. Logs set by manufacturers can be very difficult to synchronise in a controlled environment as some log formats are proprietary to the manufacturer and are not human-readable.

The methodology used in the scene examination and subsequent investigations is a possible methodology only. In effect, it is an oversimplification of the investigation of a series of very serious crimes to ensure readers can follow the evidence without being led into the multitude of different leads and investigator theories that are common in practical investigations. In reality, real-world investigations contain many sources of leads, many of which are useful, and many which turn out not to be but must be investigated anyway. So it is with digital evidence. Not all will be useful, but all must be considered.

Experienced investigators reading this book will have their own methodologies which their jurisdiction requires as well as their own learned experiences. They will also understand very well that a line of inquiry that initially seemed highly promising can turn out to be a false trail after days of extensive investigation have been devoted to it. This is part of the nature of large and complex investigations.

Detective Inspector (D/I) Sarah Coltrane is appointed the lead investigator.


  1. Cellebrite (n.d.) Accelerate justice with Cellebrite. Cellebrite. https://cellebrite.com/en/home/
definition

Licence

Icon for the Creative Commons Attribution-NonCommercial 4.0 International License

Digital Evidence Manual Copyright © 2024 by Graeme Edwards is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License, except where otherwise noted.