Data Forensics Lab

Mission

The mission of the Data Forensics Lab is to help academic and professional staff across the University of Melbourne examine data in a forensically sound manner. The Data Forensics service offers the means to analyse, identify, recover and audit research data in contemporary or legacy computer storage media.

Forensic Equipment

Hardware

The Data Forensics Lab is equipped with the Forensic Recovery of Evidence Device (FRED), a state-of-the-art, purpose-built forensic machine that follows industry standards and is optimized for stationary laboratory acquisition and analysis

.Forensics Lab

We can currently process, analyse and recover data from a variety of storage media, including:

  • Hard disk drives (IDE, SATA, SCISI, SSD), both internal and external
  • 3.5 and 5.25 inch DS/HD and DS/DD floppy disks
  • Iomega zip disks
  • CD-ROM and DVD-ROM
  • USB Flash drives

We can investigate options for processing other types of storage media upon request.

Software

The Data Forensic Lab uses the Forensic Toolkit (FTK) platform by Access Data in order to forensically handle storage media and digital data. You can find more information about FTK here

Data Forensic Service

Each forensic investigation includes:

  1. Acquisition and imaging of data from one or more storage media.
  2. Investigation and examination of all information; this depends on the type and size of the equipment and the nature of each case.
  3. Data curation, including forensic accessioning of digital media; identification of storage media; characterisation of file formats; and preservation action (e.g. migration of obsolete file formats).
  4. A full, detailed forensic report.

Cost

The cost of a data forensic investigation varies, depending on the number of storage media involved and the complexity of the recovery of evidence.

For a detailed quote, or to discuss your specific requirements, please contact us.