(Criminology Reviewer)
What is Cybercrime Investigation?
Cybercrime Investigation is the process of identifying, collecting, preserving, analyzing, and
presenting digital evidence to determine who committed a cybercrime and how it was carried
out. Investigators use computers, mobile devices, networks, and forensic tools to uncover digital
evidence while maintaining its integrity.
Common Types of Cybercrime
Cybercrime Definition
Hacking Unauthorized access to a computer or network.
Phishing Fake emails or websites used to steal personal information.
Identity Theft Using another person's identity for fraud.
Online Fraud/Scams Deceiving people online to obtain money or information.
Cyberbullying Harassing or threatening someone through digital platforms.
Malware Attack Installing malicious software such as viruses or ransomware.
Data Breach Unauthorized access to confidential data.
Denial-of-Service
Overloading a server or network to make it unavailable.
(DoS/DDoS)
Crimes involving child abuse or exploitation through the
Child Exploitation
internet.
Attacks against government or critical infrastructure using
Cyber Terrorism
technology.
Goals of Cybercrime Investigation
• Identify the offender.
• Collect digital evidence.
• Determine how the attack happened.
• Recover stolen or damaged data.
• Support criminal prosecution.
,Basic Steps in Cybercrime Investigation
1. Identification
Determine:
• What happened?
• What systems were affected?
• What evidence exists?
Example:
A company reports that customer information was stolen.
2. Preservation
Protect digital evidence from alteration.
Examples:
• Disconnect the device from the internet.
• Create a forensic image.
• Do not modify original files.
Golden Rule:
Never work directly on the original evidence.
3. Collection
Gather digital evidence from:
• Computers
• Laptops
• Mobile phones
• Hard drives
• USB drives
• Servers
• Cloud storage
• CCTV systems
• Email accounts
, • Social media
4. Examination
Investigators use forensic software to recover:
• Deleted files
• Hidden files
• Browser history
• Login credentials
• Email records
• Chat messages
• Metadata
5. Analysis
Determine:
• Who committed the crime?
• How was it done?
• When did it happen?
• Which tools were used?
• What damage occurred?
6. Reporting
Prepare a forensic report containing:
• Evidence collected
• Investigation procedures
• Findings
• Conclusions
• Expert opinion
7. Presentation