Investigative topic support in CASE
The CASE narrative examples gallery illustrates snippets of CASE data that would appear in cyber investigations, using narratives to provide a cohesive demonstration. The concepts used in those illustrations can be grouped into various topics of investigative relevance.
Other illustrations of concepts are available at the CASE Examples Github repository, and in the output of some of the CASE code bases. Specific illustrations are linked below.
CASE supports other investigative topics beyond what are listed on this page. The community continues to build this page, cataloguing the competency questions CASE addresses. If you are interested in helping to document investigative needs, we welcome your participation.
The Chain of Custody is crucial in investigations as it helps establish and maintain integrity of the evidence throughout various stages (i.e. seizure, transfer, analysis, etc.). Due to the increasing reliance of digital media in our every-day tasks, digital components are becoming more prominent in investigations. CASE seeks to represent that cyber aspect of a Chain of Custody. Those aspects that can be represented in CASE are properties of a device (manufacturer, model, serial number, storage size, etc.), tools used to acquire and/or analyze the device, and the context of data pertaining to the device.
Name | IRI | Illustrations |
---|---|---|
Investigative action |
|
Among queries in the Urgent Evidence narrative
See other usage in CASE-Examples |
Digital evidence content-integrity records |
|
Among queries in the Owl Trafficking scenario
|
Evidentiary chains |
|
Among queries in the Urgent Evidence narrative
|
Exhibit numbers |
|
Among queries in the Urgent Evidence narrative
|
Pictures in investigations have their embedded technical metadata analyzed as well as their depicted contents.
Name | IRI | Illustrations |
---|---|---|
EXIF dictionary |
|
See picture location extraction in the CASE ExifTool implementation |
Locations in investigations include semantic places and geospatial points.
Name | IRI | Illustrations |
---|---|---|
Location as a semantic place |
|
Among queries in the Urgent Evidence narrative
See other usage in CASE-Examples |
Coordinates |
|
See picture location extraction in the CASE ExifTool implementation See other usage in CASE-Examples |