Legal Cyber Academy
BookPaidCurrent

Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet

Eoghan Casey · Academic Press (Elsevier) · Third edition · 2011

Identifier: ISBN 978-0-12-374268-1

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A single-author treatment of digital evidence that puts investigative reasoning and admissibility ahead of tooling, then works through Windows, Unix, Macintosh, mobile and network evidence sources. Roughly half the book is about how to reason from evidence to a defensible conclusion and how that conclusion survives a courtroom.

Who it is for, and when

Read it when you need the vocabulary and the reasoning discipline that examiners and lawyers share: evidence dynamics, reconstruction, chain of custody, the difference between an artifact and an inference. It is the book to hand a new examiner who can already run a tool but cannot yet explain why their conclusion follows. It is also the most useful single text for a lawyer who has to cross-examine a forensic examiner.

What it does not cover

The technical chapters are 2011-vintage: nothing on cloud accounts as a primary evidence source, modern smartphone full-disk encryption, APFS, Windows 10/11 artifacts, or SSD/TRIM recovery limits. The US and European legal discussion predates more than a decade of Fourth Amendment and data-protection development, so the law here must be re-checked, not cited.

Go to the source

Open at shop.elsevier.com (opens in a new tab)

https://shop.elsevier.com/books/digital-evidence-and-computer-crime/casey/978-0-12-374268-1

Details

Type
Book
Written for
Working examinerLawyers and courtsWorking examiner, Lawyers and courts
Author
Eoghan Casey
Publisher
Academic Press (Elsevier)
Version verified
Third edition
Year
2011
Identifier
ISBN 978-0-12-374268-1
Topics
foundations, evidence-handling, legal-admissibility, case-studies, expert-testimony
Checked at source
  • A book about the attribution gap: how you get from "this account or this machine did it" to "this person did it", using physical investigation, surveillance, interviews and case timelines alongside the forensic artifacts.

  • Eoghan Casey's paper in IJDE 2002, Volume 1, Issue 2, which took apart the then-common claim that digital evidence is exact and argued that error, uncertainty and data loss are intrinsic to it and must be stated. It proposed expressing a level of certainty in conclusions rather than asserting them flatly.

  • The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.

  • The UK guide that states the four ACPO principles for handling digital evidence — do not change the original data, record everything done, have a competent person do any live examination, and place responsibility for compliance on the officer in charge. Its own front matter records that ACPO agreed the revised guide for adoption by police forces in England, Wales and Northern Ireland.

  • A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.