This presentation teaches investigators, forensic examiners, and prosecutors, how to create a virtual machine of the suspect’s computer using the forensic disk image. This process not only provides examiners with additional, critical evidence that is typically missed by all forensic software, but it also serves as one of the best methods for presenting CSAM case evidence in the courtroom. Attendees will learn how to create and “boot” the suspect’s system as a virtual machine, and how they can effectively present their case evidence, (just as the suspect interacted with it) to a judge and jury. If you have ever struggled to present technical data to a non-technical audience, you do not want to miss this presentation!
Learning Objectives:
Identify investigative benefits to virtualizing forensic image files.
Identify prosecutorial benefits of virtualizing forensic images for courtroom presentation of evidence.
Successfully learn how to easily create a virtual machine from a forensic disk image and how to capture and present that evidence in a courtroom.