Back | Data Autopsies Data Autopsies

U.S. vs. Scott (2010) — Write-Blocker Methodology

Intermediate 60 min 35 views 0 solutions

Overview

The defense successfully argued the forensic examiner booted the suspect's computer directly from the hard drive instead of using a write-blocker, altering last-access timestamps.

Case Details

## Background

The defense successfully argued the forensic examiner booted the suspect's computer directly from the hard drive instead of using a write-blocker, altering last-access timestamps.

## Learning Objective
Master the art of documenting the evidence lifecycle and surviving defense attorney cross-examinations.

## Scenario
You are the lead digital forensic investigator assigned to this case. Based on the real-world events described, you must analyze the available evidence, reconstruct the timeline, and produce a forensic report.

### Key Facts
- Case: U.S. vs. Scott (2010) — Write-Blocker Methodology
- Year: 2010
- Domain: Cyber Forensics
- Difficulty: Intermediate

## Evidence Available

Refer to the dataset at: https://github.com/arora200/aplly_case_db/tree/main/datasets/fss303-us-vs-scott

## Investigation Questions

1. What mistake did the forensic examiner make in U.S. vs. Scott?
2. How does a write-blocker prevent evidence contamination?
3. What happens to last-access timestamps when booting directly from a suspect's hard drive?
4. How can the defense exploit a 2-hour gap between seizure and imaging?
5. Design a forensic examination protocol that addresses all chain-of-custody concerns.

## Deliverables

1. Forensic Report — Document your findings, methodology, and conclusions
2. Timeline Reconstruction — Map the sequence of events
3. Evidence Log — Document all evidence collected with hash values
4. Legal Admissibility Checklist — Ensure your evidence meets evidentiary standards

## Expert Insight
On the stand, you are not defending the suspect; you are defending your methodology. If your methodology is airtight, the data speaks for itself.

## Forensic Takeaway
A broken chain (e.g., failure to use a write-blocker) gives the defense an opening to claim evidence tampering.

What You'll Learn

  • Problem-solving and analytical thinking
  • Data-driven decision making
  • Business strategy development
  • Professional report writing
0
Solutions Submitted
Difficulty Intermediate
Estimated Time 60 minutes
Relevance Fresh
Source Based on real-world cyber forensic investigations for FSS303 course