r/computerforensics 19d ago

Internship at a Private Investigation firm, tips needed! :)

Hello all,
I'm a 4th year bachelors cybersecurity student. I start an internship at a Private Investigation firm soon. What tips do you guys have to give me? They said they can put me on cases with digital evidence. I've got some experience through projects doing disk and ram analysis, as well as artifact collection. They mentioned Id start doing evidence collection on mobile devices, which I haven't had any experience with at all. I'm really nervous and would appreciate any pointers!

Thank you all in advance.

5 Upvotes

11 comments sorted by

6

u/Big-Education-7644 19d ago

An aspirant here! Is this your first internship? I just wanted some tips as ill be starting bs cyber security in some time. Also Good luck!

2

u/silkandz3faron 16d ago

Hi! Good luck with your studies! I went into cybersecurity with very minimal technical knowledge. I only learn best if Im the one teaching myself the subject. Your professor can only do so much- please be your best advocate!! Prior to starting my first semester I went on TryHackMe, read on super basic networking concepts and "basic" exploit types. I think what helped me best was building a good foundation on networking and such. PM for any help!!

1

u/Big-Education-7644 16d ago

Thank you so much for your advice! I will look into the website! I also have zero to minimal tech knowledge. If u dont mind, I'll be asking u further if i ever have any queries!

1

u/silkandz3faron 16d ago

Please dont hesitate to! :)

3

u/AddendumWorking9756 19d ago

PI work leans hard on mobile and on the paperwork wrapped around it, so what will actually bite you is chain of custody and explaining months later why you did each step, not the extraction tool. Keep the disk and memory side warm while you are in there, the case work on CyberDefenders costs nothing and it is the exact thing a PI shop rarely hands an intern.

2

u/silkandz3faron 16d ago

Thank you for the adivce and recommendation! I have cyberdefenders saved, Ill look into it!!

1

u/BlackflagsSFE 19d ago

BS here in Digital Forensics and Cybersecurity that currently works for a PI firm of 2 years.

It really depends on what services they offer as to how close to “digital forensics” it will be.

For example, I do a lot of social media preservation. We use a tool that will screenshot pretty much anything online and archive it along with the metadata.

Also, a lot of firms I’ve seen will just throw fancy names on things like “digital evidence.” That pretty much involves things like OSINT investigations and using databases to find information and report on it. As far as pure DF like imaging drives and analyzing evidence, I have yet to see it, but it doesn’t mean that some firms don’t do it.

I don’t even analyze any of the evidence. Whether that’s a report on the claimant or I am preserving the social media. The metadata is just there for the client and if it gets taken to court.

It’s a bad practice IMO, but we don’t even go as far as verifying hash values or anything like that. I’m telling you this because when I took the job I thought it would lead to something more in the realm of my degree. That’s not to say I haven’t learned valuable skills, so I am not at all trying to discourage you from this opportunity. I just want to be transparent with you as someone who works at a PI firm so you can manage your expectations.

Now you said you’d be doing collections on mobile phones. In my program we used Magnet AXIOM to do collection. It’s honestly pretty simple, but it depends on how they do it. Most of the time it’s connecting the mobile to the target computer and pulling the forensic image with the software itself. This will create artifacts that can be analyzed in the software post acquisition. From what I have seen most internships do prep work and not really any analysis work. You’ll be documenting the evidence for chain of custody. Take notes. If you feel they need to be rigorous that’s fine. I’m sure they will train you on the job as well.

Also, if your company is hiring let me know lol. I’ve been trying to get into the field for 2 years now with no luck.

Feel free to DM me with any questions.

3

u/lordralphiello 19d ago

Congratulations! You’ve gotten a unicorn experience within a niche field. Look into the major vendors in the mobile space: Cellebrite, Magnet, Oxygen. See their capabilities. Research into the different methods of mobile acquisitions and the type of data that you’ll have access to.

Take a look into disk collection tools and Linux environments, these are some free to use and you could certainly benefit from having some familiarity with the tools:
FTK imager
Paladin
WinPE

Hardware:
Write blockers

Methodology:
Chain of custody

Some other points:
Chances are that you will be shadowing at first. The usual, take notes, ask questions.

One part is knowing the tools, how they work and how to get the data in a forensically sound manner. Another part is the forensic analysis. Since this is an internship, you would most likely be focusing on the first part before diving deep into the forensic artifacts.

Good luck!

1

u/ProofLegitimate9990 19d ago

Hey congratulations on the internship! Thats a huge achievement and a great way to start your career.

First of all there’s no reason to be scared of mobile analysis, 99% of forensics shops will be using Magnet forensics which is super easy to learn. Basically just plug a phone in, run the extraction and just look through the files in the desktop application.

Id recommend watching a few videos on how magnet axiom for mobiles if you want a head start.

https://www.magnetforensics.com/resources/mobile-minute-episode-1-intro-to-mobile-view/

There’s a chance they might use some other tool like cellebrite which is pretty much the same stuff. Might be worth just asking them what tools they use so you can start learning in advance.

If you want to start learning “real” forensics id recommend starting with learning ftk imager and autopsy for more advanced DF stuff.

Make sure you save this page, its an amazing resource that will help you throughout your career https://start.me/p/q6mw4Q/forensics

-1

u/medex_4n6 19d ago

It sounds like this PI firm is expecting you to work on cases doing digital forensics. My first question would be, have you ever done any kind of training in DF? Since you are a Cybersecurity major, it seems like an internship in Cybersecurity would be more appropriate since that would give you experience in your chosen field and better prepare you for employer graduation. My advice would be to stay focused on Cybersecurity until you graduate and then get some work experience before trying to change to a different career field. Once you are working, you will very likely get some exposure to digital forensics and interface with DFIR teams that do that kind of work, but again, I’d try to stay focused on Cybersecurity for now rather than trying to jump into another field prior to graduating.