Legal Cyber Academy
BookPaidCurrent

Placing the Suspect Behind the Keyboard: Using Digital Forensics and Investigative Techniques to Identify Cybercrime Suspects

Brett Shavers · Syngress (Elsevier) · First edition · 2013

Identifier: ISBN 978-1-59749-985-9

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A book about the attribution gap: how you get from "this account or this machine did it" to "this person did it", using physical investigation, surveillance, interviews and case timelines alongside the forensic artifacts.

Who it is for, and when

The one book on this list aimed squarely at the weakest point in most digital cases. Read it before you write a report that implies a named person was at the keyboard, and read it if you are on the other side looking for the alternative-user hypothesis nobody excluded.

What it does not cover

Not a technical examination manual — it assumes someone else is doing the artifact work. Written before shared-device and cloud-account realities became the norm, so it says little about multi-user cloud sessions, mobile-device co-location data, or the modern volume of automated account activity.

Go to the source

Open at shop.elsevier.com (opens in a new tab)

https://shop.elsevier.com/books/placing-the-suspect-behind-the-keyboard/shavers/978-1-59749-985-9

Details

Type
Book
Written for
Working examinerLawyers and courtsWorking examiner, Lawyers and courts
Author
Brett Shavers
Publisher
Syngress (Elsevier)
Version verified
First edition
Year
2013
Identifier
ISBN 978-1-59749-985-9
Topics
case-studies, evidence-handling, reporting, legal-admissibility, expert-testimony
Checked at source
  • A single-author treatment of digital evidence that puts investigative reasoning and admissibility ahead of tooling, then works through Windows, Unix, Macintosh, mobile and network evidence sources. Roughly half the book is about how to reason from evidence to a defensible conclusion and how that conclusion survives a courtroom.

  • An 81-page NIJ guide on the legal handling of digital evidence: search and seizure issues including the Fourth Amendment, the Electronic Communications Privacy Act and the Privacy Protection Act; maintaining evidence integrity; pretrial preparation including authentication and hearsay; courtroom presentation and expert testimony; and a chapter on child pornography cases. Appendices include consent forms and evidence return stipulations.

  • Guidance on the content of reports issued by expert witnesses in the criminal justice system of England and Wales, setting out the legal requirements for expert reports, requirements imposed by certain prosecuting authorities, and advice on applying them.

  • The federal admissibility rule for expert testimony. The 2023 amendment moved the burden into the rule text — the proponent must demonstrate to the court that it is more likely than not that each of the four requirements is met — and rewrote subsection (d) so that the opinion must reflect a reliable application of the principles and methods to the facts of the case.

  • SWGDE's guidance for examiners who have to present digital evidence in court or other proceedings, covering preparation, exhibits, scope of testimony and staying within demonstrated competence. The version verified here is 23-Q-001-1.1 dated 2 February 2024.