A computer forensics examiner typically works as part of a law enforcement agency or police organization in analysis and interpretation of computer data for investigation of a crime. The specific tasks carried out by this type of forensics examiner usually involve computer data and can include anything from analysis of metadata on an e-mail to imaging and analysis of a computer hard drive. Other common tasks include re-creation of deleted computer files and use of various software programs to evaluate computer evidence and properly document the process for use in court. A computer forensics examiner will also often provide testimony in court regarding computer evidence that was found and used during an investigation.
Much of the work done by a computer forensics examiner takes place during a criminal investigation or civil discovery process. For criminal investigations, this work usually involves examination and analysis of hardware, software, and computer files to provide evidence regarding a suspect or build a case for the guilt or innocence of a suspect. In civil discovery, the work performed by a computer forensics examiner is often used to determine if someone is lying or misrepresenting the facts in a case.
Regardless of the type of case being worked on, a computer forensics examiner will typically examine large amounts of computer data. This can include computer hardware, such as hard drives or discs, and data files, such as e-mails and documents on a computer. Using specialized software and a variety of techniques, a computer forensics examiner can re-create deleted files on a system, determine where an e-mail may have been sent from, and read encrypted files. Throughout the late 20th and early 21st centuries, the work done by computer forensics examiners led to arrests in numerous cases, including the infamous “BTK” killer who was caught in 2005 due to metadata on a floppy disk he sent to police that indicated his first name and a location in which the disk had been used.
A computer forensics examiner will also typically work after an investigation to provide court testimony and expert opinions on a case. As the examiner works on an investigation, he or she will document each step and the work performed to meet the standards of evidence that will be introduced in a court case. Once this is complete, he or she may need to present the work and defend it against cross-examination by an attorney. A computer forensics examiner will also typically have to explain the methods used to find evidence in a way that judges and jury members can effectively understand.