Placing the Suspect Behind the Keyboard: Using Digital Forensics and Investigative Techniques to Identify Cybercrime Suspects
Brett Shavers · Syngress (Elsevier) · First edition · 2013
Identifier: ISBN 978-1-59749-985-9
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A book about the attribution gap: how you get from "this account or this machine did it" to "this person did it", using physical investigation, surveillance, interviews and case timelines alongside the forensic artifacts.
Who it is for, and when
The one book on this list aimed squarely at the weakest point in most digital cases. Read it before you write a report that implies a named person was at the keyboard, and read it if you are on the other side looking for the alternative-user hypothesis nobody excluded.
What it does not cover
Not a technical examination manual — it assumes someone else is doing the artifact work. Written before shared-device and cloud-account realities became the norm, so it says little about multi-user cloud sessions, mobile-device co-location data, or the modern volume of automated account activity.
Go to the source
Open at shop.elsevier.com (opens in a new tab)https://shop.elsevier.com/books/placing-the-suspect-behind-the-keyboard/shavers/978-1-59749-985-9
Details
- Type
- Book
- Written for
- Working examinerLawyers and courtsWorking examiner, Lawyers and courts
- Author
- Brett Shavers
- Publisher
- Syngress (Elsevier)
- Version verified
- First edition
- Year
- 2013
- Identifier
- ISBN 978-1-59749-985-9
- Topics
- case-studies, evidence-handling, reporting, legal-admissibility, expert-testimony
- Checked at source
Related entries
A single-author treatment of digital evidence that puts investigative reasoning and admissibility ahead of tooling, then works through Windows, Unix, Macintosh, mobile and network evidence sources. Roughly half the book is about how to reason from evidence to a defensible conclusion and how that conclusion survives a courtroom.
An 81-page NIJ guide on the legal handling of digital evidence: search and seizure issues including the Fourth Amendment, the Electronic Communications Privacy Act and the Privacy Protection Act; maintaining evidence integrity; pretrial preparation including authentication and hearsay; courtroom presentation and expert testimony; and a chapter on child pornography cases. Appendices include consent forms and evidence return stipulations.
Guidance on the content of reports issued by expert witnesses in the criminal justice system of England and Wales, setting out the legal requirements for expert reports, requirements imposed by certain prosecuting authorities, and advice on applying them.
The federal admissibility rule for expert testimony. The 2023 amendment moved the burden into the rule text — the proponent must demonstrate to the court that it is more likely than not that each of the four requirements is met — and rewrote subsection (d) so that the opinion must reflect a reliable application of the principles and methods to the facts of the case.
SWGDE's guidance for examiners who have to present digital evidence in court or other proceedings, covering preparation, exhibits, scope of testimony and staying within demonstrated competence. The version verified here is 23-Q-001-1.1 dated 2 February 2024.