<<< Computer Forensic Science | Index | Steps in Processing Digital Evidence >>> |
Technology pushes the limits of hardware, software, removable media, and mobile devices.
Forensics examiners must understand OSs, file systems, and volumes of related technical documentation.
Having to do an analysis on proprietary systems such as embedded systems can be a significant challenge.
Digital storage media with very large capacities pushes the limits on many existing file systems to the limits, which will be reached during the newest wave of storage technology.
For example, new Secure Digital Extended Capacity, (SDXC) specification was announced in 2009, with capacities that could reach up to 2 TB, using relatively new proprietary Microsoft exFAT file system. A forensics examiners must be on the front lines studying and dissecting the exFAT internals.
Reference: SANS Institute InfoSec Reading Room, Reverse Engineering the Microsoft exFAT File System.
<<< Computer Forensic Science | Index | Steps in Processing Digital Evidence >>> |