{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T23:32:24Z","timestamp":1777764744686,"version":"3.51.4"},"reference-count":160,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T00:00:00Z","timestamp":1733875200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>The invention of transistors in the 1940s marked the beginning of a technological revolution that has impacted every aspect of our lives. However, along with the positive advancements, the malicious use of computing technologies has become a serious concern. The international community has been actively collaborating to develop digital forensics techniques to combat the unlawful use of these technologies. However, the evolution of digital forensics has often lagged behind the rapid developments in computing technologies. In addition to their harmful use, computing devices are increasingly involved in crime scenes and accidents, necessitating digital forensics to reconstruct events. This paper provides a comprehensive review of the development of computing technologies from the 1940s to the present, highlighting the trends in their malicious use and the corresponding advancements in digital forensics. The paper also discusses various institutes, laboratories, organizations, and training setups established at national and international levels for digital forensics purposes. Furthermore, it explores the initial legislations related to computer-related crimes and the standards associated with digital forensics. These reviews and discussions conclude at identifying the shortfalls in digital forensics and proposes an all-inclusive digital forensics process model meeting these shortfalls while complying to international standards and meeting regulatory and legal requirements of digital forensics.<\/jats:p>","DOI":"10.3390\/computers13120333","type":"journal-article","created":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T03:14:58Z","timestamp":1733886898000},"page":"333","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Unveiling the Dynamic Landscape of Digital Forensics: The Endless Pursuit"],"prefix":"10.3390","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0167-4694","authenticated-orcid":false,"given":"Muhammad","family":"Zareen","sequence":"first","affiliation":[{"name":"Department of Information Security, College of Signals, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baber","family":"Aslam","sequence":"additional","affiliation":[{"name":"Department of Information Security, College of Signals, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4737-0191","authenticated-orcid":false,"given":"Shahzaib","family":"Tahir","sequence":"additional","affiliation":[{"name":"Department of Information Security, College of Signals, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8958-672X","authenticated-orcid":false,"given":"Imran","family":"Rasheed","sequence":"additional","affiliation":[{"name":"Department of Information Security, College of Signals, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6609-5928","authenticated-orcid":false,"given":"Fawad","family":"Khan","sequence":"additional","affiliation":[{"name":"Centre for Intelligent Healthcare, Coventry University, Northampton Square, Coventry CV1 5RW, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,12,11]]},"reference":[{"key":"ref_1","unstructured":"(2017). Digital Forensics, Technical Report."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Kent, K., Chevalier, S., and Grance, T. (2006). Guide to integrating forensic techniques into incident, Guide to Integrating Forensic Techniques into Incident Response 800-86.","DOI":"10.6028\/NIST.SP.800-86"},{"key":"ref_3","first-page":"1","article-title":"Forensic analysis in the Digital World","volume":"1","author":"Palmer","year":"2002","journal-title":"Int. J. Digit. Evid."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Rohatgi, S., and Shrivastava, S. (2024). Combating Cybercrimes with Digital Forensics. Advancements in Cybercrime Investigation and Digital Forensics, Apple Academic Press.","DOI":"10.1201\/9781003369479-5"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"97","DOI":"10.2307\/2002620","article-title":"The electronic numerical integrator and computer (eniac)","volume":"2","author":"Goldstine","year":"1946","journal-title":"Math. Tables Other Aids Comput."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1858","DOI":"10.1109\/4.643644","article-title":"A history of the invention of the transistor and where it will lead us","volume":"32","author":"Brinkman","year":"1997","journal-title":"IEEE J. Solid State Circuits"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Pollitt, M. (2010, January 4\u20136). A history of digital forensics. Proceedings of the IFIP International Conference on Digital Forensics, Hong Kong, China.","DOI":"10.1007\/978-3-642-15506-2_1"},{"key":"ref_8","unstructured":"McPherson, S.S. (2009). Tim Berners-Lee: Inventor of the World Wide Web, Twenty-First Century Books, The Rosen Publishing Group, Inc."},{"key":"ref_9","unstructured":"Porterfield, J. (2015). Tim Berners-Lee, The Rosen Publishing Group, Inc."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Saxena, A.N. (2009). Invention of Integrated Circuits: Untold Important Facts, World Scientific.","DOI":"10.1142\/9789812814463"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"729","DOI":"10.1038\/21526","article-title":"The end of the road for silicon?","volume":"399","author":"Schulz","year":"1999","journal-title":"Nature"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1002\/bltj.2082","article-title":"The history of the microprocessor","volume":"2","author":"Betker","year":"1997","journal-title":"Bell Labs Tech. J."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Bardini, T. (2000). Bootstrapping: Douglas Engelbart, Coevolution, and the Origins of Personal Computing, Stanford University Press.","DOI":"10.1515\/9781503618367"},{"key":"ref_14","first-page":"58","article-title":"The tenth anniversary of the Altair 8800","volume":"23","author":"Mims","year":"1985","journal-title":"Comput. Electron."},{"key":"ref_15","unstructured":"Green, S. (2015). Apple, Bellwether Media."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1109\/MC.2011.193","article-title":"The IBM Personal Computer: A Software-Driven Market","volume":"44","author":"Bride","year":"2011","journal-title":"Computer"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"102","DOI":"10.1145\/253671.253741","article-title":"The past and future history of the Internet","volume":"40","author":"Leiner","year":"1997","journal-title":"Commun. ACM"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1145\/179606.179671","article-title":"The world-wide web","volume":"37","author":"Cailliau","year":"1994","journal-title":"Commun. ACM"},{"key":"ref_19","unstructured":"Max Roser, H.R., and Ortiz-Ospina, E. (2024, June 26). Internet. Our World in Data. Available online: https:\/\/ourworldindata.org\/internet."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Zeadally, S., Siddiqui, F., and Baig, Z. (2019). 25 years of bluetooth technology. Future Internet, 11.","DOI":"10.3390\/fi11090194"},{"key":"ref_21","unstructured":"Thomas, J. (2014, May 25). The History of WiFi. Available online: https:\/\/purple.ai\/blogs\/history-wifi\/."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Dahlman, E., Parkvall, S., Skold, J., and Beming, P. (2010). 3G Evolution: HSPA and LTE for Mobile Broadband, Academic Press.","DOI":"10.1587\/transcom.E92.B.1432"},{"key":"ref_23","unstructured":"Yu, A. (2003, December 10). USB Flash Disks: Say Goodbye to Floppy Disks. Available online: https:\/\/www.cityu.edu.hk\/its\/news\/2003\/12\/31\/usb-flash-disks-say-goodbye-floppy-disks."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Kim, J., Baratto, R.A., and Nieh, J. (2006, January 23\u201326). pTHINC: A thin-client architecture for mobile wireless web. Proceedings of the 15th International Conference on World Wide Web, Scotland, UK.","DOI":"10.1145\/1135777.1135803"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1109\/MITP.2007.78","article-title":"Understanding Web 2.0","volume":"9","author":"Murugesan","year":"2007","journal-title":"IT Prof."},{"key":"ref_26","first-page":"46","article-title":"English Language Learners as Digital Content Creators: An Exploration of Social Networking on the Perceived Development of Language Skills","volume":"25","author":"Shahid","year":"2024","journal-title":"Comput. Assist. Lang. Learn. Electron. J."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"118823","DOI":"10.1016\/j.eswa.2022.118823","article-title":"A systematic review of healthcare recommender systems: Open issues, challenges, and techniques","volume":"213","author":"Etemadi","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1145\/2721914.2721921","article-title":"A brief history of cloud offload: A personal journey from odyssey through cyber foraging to cloudlets","volume":"18","author":"Satyanarayanan","year":"2015","journal-title":"Getmobile Mob. Comput. Commun."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1007\/s00354-008-0081-5","article-title":"Cloud computing: A perspective study","volume":"28","author":"Wang","year":"2010","journal-title":"New Gener. Comput."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Zareen, M.S., and Tariq, M. (2014, January 8\u201310). Internet of things (IoT): The next paradigm shift but whats the delay?. Proceedings of the 17th IEEE International Multi Topic Conference 2014, Karachi, Pakistan.","DOI":"10.1109\/INMIC.2014.7097327"},{"key":"ref_31","unstructured":"Carton, B., Mongardini, J., and Li, Y. (2018, February 08). Smartphones Drive New Global Tech Cycle, but Is Demand Peaking?. Available online: https:\/\/blogs.imf.org\/2018\/02\/08\/smartphones-drive-new-global-tech-cycle-but-is-demand-peaking\/."},{"key":"ref_32","unstructured":"Guevarra, L.M. (2018, September 06). E-Commerce: The Past, Present, and Future. Available online: https:\/\/www.spiralytics.com\/blog\/past-present-future-ecommerce\/."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/s12599-017-0467-3","article-title":"Blockchain","volume":"59","author":"Nofer","year":"2017","journal-title":"Bus. Inf. Syst. Eng."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1016\/j.jnca.2018.10.019","article-title":"Blockchain\u2019s adoption in IoT: The challenges, and a way forward","volume":"125","author":"Makhdoom","year":"2019","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_35","unstructured":"Gartner (2021, April 01). Gartner Forecasts Global Devices Installed Base to Reach 6.2 Billion Units in 2021 Gartner Forecasts Global Devices Installed Base to Reach 6.2 Billion Units in 2021. Available online: https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2021-04-01-gartner-forecasts-global-devices-installed-base-to-reach-6-2-billion-units-in-2021."},{"key":"ref_36","first-page":"7","article-title":"An historical perspective of digital evidence: A forensic scientist\u2019s view","volume":"1","author":"Whitcomb","year":"2002","journal-title":"Int. J. Digit. Evid."},{"key":"ref_37","unstructured":"Nelson, B., Phillips, A., and Steuart, C. (2014). Guide to Computer Forensics and Investigations, Cengage Learning."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S1361-3723(04)00017-X","article-title":"The future for the policing of cybercrime","volume":"2004","author":"Sommer","year":"2004","journal-title":"Comput. Fraud. Secur."},{"key":"ref_39","unstructured":"(2024, August 21). About the High Technology Crime Investigation Association (HTCIA). Available online: https:\/\/htcia.org\/about\/."},{"key":"ref_40","unstructured":"Department of Homeland Security United States Secret Service (2018, December 14). US Secret Service (USSS) Electronic Crimes Special Agent Program (ECSAP) Directives, 2010\u20132015, Available online: https:\/\/www.governmentattic.org\/35docs\/USSSecsapd_2010-2015.pdf."},{"key":"ref_41","unstructured":"(2024, May 23). Seized Computer Evidence Recovery Specialist, Available online: https:\/\/www.fletc.gov\/seized-computer-evidence-recovery-specialist."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Jaishankar, K. (2020). Cyber victimology: A new sub-discipline of the twenty-first century victimology. An International Perspective on Contemporary Developments in Victimology: A Festschrift in Honor of Marc Groenhuijsen, Springer.","DOI":"10.1007\/978-3-030-41622-5_1"},{"key":"ref_43","unstructured":"(2024, February 28). IACIS History. Available online: https:\/\/www.iacis.com\/about\/history\/."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1007\/BF00150234","article-title":"A forensic methodology for countering computer crime","volume":"6","author":"Collier","year":"1992","journal-title":"Artif. Intell. Rev."},{"key":"ref_45","unstructured":"Stoll, C. (2005). The Cuckoo\u2019s Egg: Tracking a Spy Through the Maze of Computer Espionage, Simon and Schuster."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"S64","DOI":"10.1016\/j.diin.2010.05.009","article-title":"Digital forensics research: The next 10 years","volume":"7","author":"Garfinkel","year":"2010","journal-title":"Digit. Investig."},{"key":"ref_47","first-page":"1","article-title":"Recovering and examining computer forensic evidence","volume":"2","author":"Noblett","year":"2000","journal-title":"Forensic Sci. Commun."},{"key":"ref_48","unstructured":"Snyder, K.V. (2021). The Development of Current Digital Forensics Policies and Federal Legislation. [Ph.D. Thesis, University of Colorado at Denver]."},{"key":"ref_49","unstructured":"Pollitt, M.M. (2002, January 11\u201312). The very brief history of digital evidence standards. Proceedings of the Working Conference on Integrity and Internal Control in Information Systems, Bonn, Germany."},{"key":"ref_50","unstructured":"Citeseer (2001, January 16\u201319). Report on Digital Evidence. Proceedings of the 13th INTERPOL Forensic Science Symposium, Lyon, France."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"100076","DOI":"10.1016\/j.fsir.2020.100076","article-title":"ACPO principles for digital evidence: Time for an update?","volume":"2","author":"Horsman","year":"2020","journal-title":"Forensic Sci. Int. Rep."},{"key":"ref_52","unstructured":"(2024, September 26). About Us. Available online: https:\/\/www.npcc.police.uk\/About-Us\/about-us\/."},{"key":"ref_53","unstructured":"National Institute of Justice (2001). Technical Working Group for Electronic Crime Scene Investigation, Electronic Crime Scene Investigation: A Guide for First Responders."},{"key":"ref_54","unstructured":"(2023, November 25). European Committee on Crime Problems (CDPC) Bureau (CDPC-BU)-Strasbourg, 21\u201322 November 1996, Meeitng Report. Available online: https:\/\/rm.coe.int\/09000016804d6d2d."},{"key":"ref_55","unstructured":"SWGDE (1999, October 23). Digital Evidence: Standards and Principles Scientific Working Group on Digital Evidence (SWGDE) International Organization on Digital Evidence (IOCE), Available online: https:\/\/archives.fbi.gov\/archives\/about-us\/lab\/forensic-science-communications\/fsc\/april2000\/swgde.htm."},{"key":"ref_56","unstructured":"FSAB (2024, January 24). About the FSAB. Available online: http:\/\/thefsab.org."},{"key":"ref_57","unstructured":"Jones, G.R. (2003, December 03). Forensic Accreditation Board: An Accreditation Program for Forensic Specialty Programs, Available online: https:\/\/nij.ojp.gov\/library\/publications\/forensic-accreditation-board-accreditation-program-forensic-specialty-programs."},{"key":"ref_58","unstructured":"Sanju (2024, May 28). F.A.C.T. (The Forensic Association of Computer Technologists). Available online: https:\/\/www.hiox.org\/3300-fact.php."},{"key":"ref_59","unstructured":"ASCLD\/LAB (1994). Guidelines for Forensics Laboratory Management Practices, American Society of Crime Laboratory Directors (ASCLD). Technical Report."},{"key":"ref_60","unstructured":"(2024, July 12). Computer Technology Investigators Network. Available online: https:\/\/ctin.org."},{"key":"ref_61","unstructured":"Specht, J. (2020). The Origins and Evolution of DC3, Office of Special Investgations. Technical Report."},{"key":"ref_62","unstructured":"(2023, June 12). DC3 HISTORY. Available online: https:\/\/www.dc3.mil\/About-DC3\/History\/."},{"key":"ref_63","unstructured":"(2019, May 28). DC3 Chronological History. Available online: https:\/\/www.dc3.mil\/Portals\/100\/Documents\/DC3\/DC3_Home\/About_History\/History."},{"key":"ref_64","unstructured":"(2023, April 15). SafeBack3.0. Available online: http:\/\/www.forensics-intl.com\/safeback.html."},{"key":"ref_65","unstructured":"(2023, April 25). EnCase Forensic. Available online: https:\/\/security.opentext.com\/encase-forensic."},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Jones, G.M., and Winster, S.G. (2022). An Insight into Digital Forensics: History, Frameworks, Types and Tools, Cyber Security and Digital Forensics.","DOI":"10.1002\/9781119795667.ch6"},{"key":"ref_67","unstructured":"Pollitt, M.M. (1995, January 14\u201316). Principles, practices, and procedures: An approach to standards in computer forensics. Proceedings of the Second International Conference on Computer Evidence, Montreal, QC, Canada."},{"key":"ref_68","doi-asserted-by":"crossref","first-page":"1191","DOI":"10.1109\/COMST.2019.2962586","article-title":"A survey on the internet of things (IoT) forensics: Challenges, approaches, and open issues","volume":"22","author":"Stoyanova","year":"2020","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"ref_69","unstructured":"Palmer, G. (2001, January 7\u20138). A road map for digital forensic research. Proceedings of the First Digital Forensic Research Workshop, Utica, NY, USA."},{"key":"ref_70","unstructured":"(2023, April 26). About Us. Available online: https:\/\/dfrws.org\/about-us\/."},{"key":"ref_71","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1080\/15567280500541488","article-title":"The evolution of computer forensic best practices: An update on programs and publications","volume":"1","author":"Brill","year":"2006","journal-title":"J. Digit. Forensic Pract."},{"key":"ref_72","unstructured":"NIST (2019, November 18). National Software Reference Library (NSRL), Available online: https:\/\/www.nist.gov\/itl\/ssd\/software-quality-group\/national-software-reference-library-nsrl."},{"key":"ref_73","unstructured":"(2020, August 18). ITL History Timeline 1950-Present, Available online: https:\/\/www.nist.gov\/itl\/about-itl\/itl-history-timeline."},{"key":"ref_74","unstructured":"NIST (2019, November 15). Computer Forensics Tool Testing Program (CFTT), Available online: https:\/\/www.nist.gov\/itl\/ssd\/software-quality-group\/computer-forensics-tool-testing-program-cftt."},{"key":"ref_75","unstructured":"IFIP (2006). Factsheet WG 11.9 Digital Forensics, International Federation for Information Processing. Technical Report."},{"key":"ref_76","unstructured":"Kruse, W.G., and Heiser, J.G. (2001). Computer Forensics: Incident Response Essentials, Pearson Education."},{"key":"ref_77","first-page":"1","article-title":"An examination of digital forensic models","volume":"1","author":"Reith","year":"2002","journal-title":"Int. J. Digit. Evid."},{"key":"ref_78","first-page":"1","article-title":"Getting physical with the digital investigation process","volume":"2","author":"Carrier","year":"2003","journal-title":"Int. J. Digit. Evid."},{"key":"ref_79","unstructured":"Carrier, B., and Spafford, E. (2004). An event-based digital forensic investigation framework. Digital Investigation, Center for Education and Research in Information Assurance and Security."},{"key":"ref_80","unstructured":"Baryamureeba, V., and Tushabe, F. (2004, January 11\u201313). The enhanced digital investigation process model. Proceedings of the Digital Forensic Research Conference, Baltimore, MD, USA."},{"key":"ref_81","unstructured":"Mohay, G.M. (2003). Computer and Intrusion Forensics, Artech House."},{"key":"ref_82","first-page":"1","article-title":"An Extended Model of Cybercrime Investigations","volume":"3","year":"2004","journal-title":"Int. J. Digit. Evid."},{"key":"ref_83","first-page":"2","article-title":"Computer forensics field triage process model","volume":"1","author":"Rogers","year":"2006","journal-title":"J. Digit. Forensics Secur. Law"},{"key":"ref_84","unstructured":"Freiling, F.C., and Schwittay, B. (2007). A common process model for incident response and computer forensics. IMF 2007: IT-Incident Management & IT-Forensics, Bastian Schwittay Symantec (Deutschland) GmbH."},{"key":"ref_85","first-page":"38","article-title":"Digital Forensic Model based on Malaysian Investigation Process","volume":"9","author":"Perumal","year":"2009","journal-title":"Int. J. Comput. Sci. Netw. Secur."},{"key":"ref_86","unstructured":"(2023, April 25). OpenText Security Overview. Available online: https:\/\/security.opentext.com."},{"key":"ref_87","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1016\/j.scijus.2009.11.006","article-title":"Forensic science standards in fast-changing environments","volume":"50","author":"Sommer","year":"2010","journal-title":"Sci. Justice"},{"key":"ref_88","unstructured":"Wiki, F. (2023, April 25). Helix LiveCD. Available online: https:\/\/forensics.fandom.com\/wiki\/Helix_LiveCD."},{"key":"ref_89","unstructured":"(2023, April 25). History of The Sleuthkit. Available online: http:\/\/www.sleuthkit.org\/sleuthkit\/history.php."},{"key":"ref_90","unstructured":"(2023, April 25). Sleuthkit\/Sleuthkit. Available online: https:\/\/github.com\/sleuthkit\/sleuthkit\/releases?after=sleuthkit-3.1.2."},{"key":"ref_91","unstructured":"(2023, April 25). Sleuthkit\/Autopsy. Available online: https:\/\/github.com\/sleuthkit\/autopsy\/releases?after=autopsy-3.0.0."},{"key":"ref_92","unstructured":"(2023, April 25). History of Autopsy. Available online: http:\/\/www.sleuthkit.org\/autopsy\/history.php."},{"key":"ref_93","doi-asserted-by":"crossref","unstructured":"Daniel, L.E., and Daniel, L.E. (2012). Chapter 5-Overview of Digital Forensics Tools. Digital Forensics for Legal Professionals, Syngress.","DOI":"10.1016\/B978-1-59749-643-8.00005-5"},{"key":"ref_94","unstructured":"Rothstein, B.J., Hedges, R.J., and Wiggins, E.C. (2007). Managing Discovery of Electronic Information: A Pocket Guide for Judges, Federal Judicial Center Publication."},{"key":"ref_95","unstructured":"(2021, August 24). Reporting from the EDRM Mid-Year Meeting-CloudNine. Available online: https:\/\/cloudnine.com\/ediscoverydaily\/electronic-discovery\/reporting-from-the-edrm-mid-year-meeting\/."},{"key":"ref_96","unstructured":"(2021, August 18). EDRM Model|EDRM. Available online: https:\/\/edrm.net\/edrm-model\/."},{"key":"ref_97","unstructured":"Billard, D. (2009, January 26\u201328). An extended model for e-discovery operations. Proceedings of the IFIP International Conference on Digital Forensics, Orlando, FL, USA."},{"key":"ref_98","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1007\/s10506-010-9096-6","article-title":"E-Discovery revisited: The need for artificial intelligence beyond information retrieval","volume":"18","author":"Conrad","year":"2010","journal-title":"Artif. Intell. Law"},{"key":"ref_99","unstructured":"Conrad, J.G. (2007). E-Discovery Revisited: A Broader Perspective for Ir Researchers, Research & Development Thomson Legal & Regulatory."},{"key":"ref_100","doi-asserted-by":"crossref","unstructured":"Grobler, C., Louwrens, C., and von Solms, S.H. (2010, January 15\u201318). A multi-component view of digital forensics. Proceedings of the 2010 International Conference on Availability, Reliability and Security, Krakow, Poland.","DOI":"10.1109\/ARES.2010.61"},{"key":"ref_101","doi-asserted-by":"crossref","unstructured":"Alharbi, S., Weber-Jahnke, J., and Traore, I. (2011, January 15\u201317). The proactive and reactive digital forensics investigation process: A systematic literature review. Proceedings of the International Conference on Information Security and Assurance, Brno, Czech Republic.","DOI":"10.1007\/978-3-642-23141-4_9"},{"key":"ref_102","first-page":"118","article-title":"Systematic digital forensic investigation model","volume":"5","author":"Agarwal","year":"2011","journal-title":"Int. J. Comput. Sci. Secur. (IJCSS)"},{"key":"ref_103","unstructured":"National Institute of Justice, and U.S. Department of Justice (2004). Forensic Examination of Digital Evidence: A Guide for Law Enforcement, Technical Report."},{"key":"ref_104","doi-asserted-by":"crossref","unstructured":"Kyei, K., Zavarsky, P., Lindskog, D., and Ruhl, R. (2012, January 25\u201326). A review and comparative study of digital forensic investigation models. Proceedings of the International Conference on Digital Forensics and Cyber Crime, Lafayette, IN, USA.","DOI":"10.1007\/978-3-642-39891-9_20"},{"key":"ref_105","first-page":"175","article-title":"A new approach of digital forensic model for digital forensic investigation","volume":"2","author":"Ademu","year":"2011","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_106","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1016\/j.diin.2012.07.001","article-title":"An integrated conceptual digital forensic framework for cloud computing","volume":"9","author":"Martini","year":"2012","journal-title":"Digit. Investig."},{"key":"ref_107","doi-asserted-by":"crossref","first-page":"47","DOI":"10.4018\/jdcf.2012100104","article-title":"A model for hybrid evidence investigation","volume":"4","author":"Vlachopoulos","year":"2012","journal-title":"Int. J. Digit. Crime Forensics (IJDCF)"},{"key":"ref_108","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.cose.2013.05.001","article-title":"Integrated digital forensic process model","volume":"38","author":"Kohn","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_109","doi-asserted-by":"crossref","unstructured":"Lee, J., and Hong, D. (2011, January 4\u20136). Pervasive forensic analysis based on mobile cloud computing. Proceedings of the 2011 Third International Conference on Multimedia Information Networking and Security, Shanghai, China.","DOI":"10.1109\/MINES.2011.77"},{"key":"ref_110","first-page":"11","article-title":"A generic framework for network forensics","volume":"1","author":"Pilli","year":"2010","journal-title":"Int. J. Comput. Appl."},{"key":"ref_111","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MSP.2017.4251117","article-title":"The future of digital forensics: Challenges and the road ahead","volume":"15","author":"Caviglione","year":"2017","journal-title":"IEEE Secur. Priv."},{"key":"ref_112","doi-asserted-by":"crossref","unstructured":"Herman, M., Iorga, M., Salim, A.M., Jackson, R.H., Hurst, M.R., Leo, R., Lee, R., Landreville, N.M., Mishra, A.K., and Wang, Y. (2020). NIST Cloud Computing Forensic Science Challenges.","DOI":"10.6028\/NIST.IR.8006"},{"key":"ref_113","doi-asserted-by":"crossref","unstructured":"Zareen, M.S., Waqar, A., and Aslam, B. (2013, January 11\u201312). Digital forensics: Latest challenges and response. Proceedings of the 2013 2nd National Conference on Information Assurance (NCIA), Rawalpindi, Pakistan.","DOI":"10.1109\/NCIA.2013.6725320"},{"key":"ref_114","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1016\/j.compeleceng.2017.02.006","article-title":"Forensics framework for cloud computing","volume":"60","author":"Alex","year":"2017","journal-title":"Comput. Electr. Eng."},{"key":"ref_115","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1504\/IJESDF.2023.127745","article-title":"Cloud forensics and digital ledger investigation: A new era of forensics investigation","volume":"15","author":"Khan","year":"2023","journal-title":"Int. J. Electron. Secur. Digit. Forensics"},{"key":"ref_116","doi-asserted-by":"crossref","unstructured":"Zhang, W.E., Sheng, Q.Z., Mahmood, A., Tran, D.H., Zaib, M., Hamad, S.A., Aljubairy, A., Alhazmi, A.A.F., Sagar, S., and Ma, C. (2020, January 1\u20133). The 10 Research Topics in the Internet of Things. Proceedings of the 2020 IEEE 6th International Conference on Collaboration and Internet Computing (CIC), Atlanta, GA, USA.","DOI":"10.1109\/CIC50333.2020.00015"},{"key":"ref_117","doi-asserted-by":"crossref","unstructured":"Ryan, P.J., and Watson, R.B. (2017). Research Challenges for the Internet of Things: What Role Can or Play?. Systems, 5.","DOI":"10.3390\/systems5010024"},{"key":"ref_118","doi-asserted-by":"crossref","unstructured":"Alenezi, A., Atlam, H., Alsagri, R., Alassafi, M., and Wills, G. (2019, January 2\u20134). IoT forensics: A state-of-the-art review, callenges and future directions. Proceedings of the 4th International Conference on Complexity, Future Information Systems and Risk (COMPLEXIS 2019), Heraklion, Greece.","DOI":"10.5220\/0007905401060115"},{"key":"ref_119","doi-asserted-by":"crossref","unstructured":"Oriwoh, E., Jazani, D., Epiphaniou, G., and Sant, P. (2013, January 20\u201323). Internet of Things Forensics: Challenges and approaches. Proceedings of the 9th IEEE International Conference on Collaborative Computing: Networking, Applications and Worksharing, Austin, TX, USA.","DOI":"10.4108\/icst.collaboratecom.2013.254159"},{"key":"ref_120","doi-asserted-by":"crossref","unstructured":"Montasari, R., Jahankhani, H., Hill, R., and Parkinson, S. (2021). IoT Forensics: An Overview of the Current Issues and Challenges. Digital Forensic Investigation of Internet of Things (IoT) Devices, Springer International Publishing.","DOI":"10.1007\/978-3-030-60425-7"},{"key":"ref_121","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.comnet.2018.03.024","article-title":"Cyber-physical systems information gathering: A smart home case study","volume":"138","author":"Do","year":"2018","journal-title":"Comput. Netw."},{"key":"ref_122","doi-asserted-by":"crossref","first-page":"S38","DOI":"10.1016\/j.diin.2018.04.014","article-title":"Welcome pwn: Almond smart home hub forensics","volume":"26","author":"Awasthi","year":"2018","journal-title":"Digit. Investig."},{"key":"ref_123","doi-asserted-by":"crossref","unstructured":"Dorai, G., Houshmand, S., and Baggili, I. (2018, January 27\u201330). I know what you did last summer: Your smart home Internet of Things and your iPhone forensically ratting you out. Proceedings of the 13th International Conference on Availability, Reliability and Security, Hamburg, Germany.","DOI":"10.1145\/3230833.3232814"},{"key":"ref_124","unstructured":"(2024, September 14). Guidelines on Mobile Device Forensics, Available online: https:\/\/nvlpubs.nist.gov\/nistpubs\/specialpublications\/nist.sp.800-101r1.pdf."},{"key":"ref_125","unstructured":"Tamma, R., Skulkin, O., Mahalik, H., and Bommisetty, S. (2020). Practical Mobile Forensics: Forensically Investigate and Analyze IOS, Android, and Windows 10 Devices, Packt Publishing."},{"key":"ref_126","unstructured":"(2024, September 24). BlackBerry 10 and BlackBerry OS Services FAQ\u2014End of Life. Available online: https:\/\/www.blackberry.com\/us\/en\/support\/devices\/end-of-life."},{"key":"ref_127","doi-asserted-by":"crossref","unstructured":"Fernando, V. (2021, January 19\u201321). Cyber Forensics Tools: A Review on Mechanism and Emerging Challenges. Proceedings of the 2021 11th IFIP International Conference on New Technologies, Mobility and Security (NTMS), Paris, France.","DOI":"10.1109\/NTMS49979.2021.9432641"},{"key":"ref_128","doi-asserted-by":"crossref","unstructured":"Lwin, H.H., Aung, W.P., and Lin, K.K. (2020, January 27\u201328). Comparative analysis of Android mobile forensics tools. Proceedings of the 2020 IEEE Conference on Computer Applications (ICCA), Yangon, Myanmar.","DOI":"10.1109\/ICCA49400.2020.9022838"},{"key":"ref_129","doi-asserted-by":"crossref","first-page":"173359","DOI":"10.1109\/ACCESS.2020.3014615","article-title":"A review of mobile forensic investigation process models","volume":"8","author":"Ikuesan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_130","unstructured":"ISO\/IEC (2024). Information Technology\u2013Security Techniques\u2013Privacy Framework (Standard No. ISO\/IEC 29100:2024). Available online: https:\/\/www.iso.org\/standard\/85938.html."},{"key":"ref_131","unstructured":"(2021, December 11). General Data Protection Regulation (GDPR)\u2014Official Legal Text. Available online: https:\/\/gdpr-info.eu\/."},{"key":"ref_132","unstructured":"(2021, November 13). CCPA and CPRA\u2014iapp.org. Available online: https:\/\/iapp.org\/resources\/topics\/ccpa-and-cpra\/."},{"key":"ref_133","unstructured":"Goldman, E. (2020). An introduction to the california consumer privacy act (ccpa). Santa Clara University Legal Studies Research Paper, Santa Clara University."},{"key":"ref_134","unstructured":"Demmler, D., Krupka, D., and Federrath, H. (2022, January 22\u201323). Ontology in the Digital Forensics Domain: A Scoping Review. Proceedings of the INFORMATIK 2022, Virtual Event."},{"key":"ref_135","doi-asserted-by":"crossref","unstructured":"Mohammad, R.M. (November, January 28). A neural network based digital forensics classification. Proceedings of the 2018 IEEE\/ACS 15th International Conference on Computer Systems and Applications (AICCSA), Aqaba, Jordan.","DOI":"10.1109\/AICCSA.2018.8612868"},{"key":"ref_136","doi-asserted-by":"crossref","unstructured":"Tall\u00f3n-Ballesteros, A.J., and Riquelme, J.C. (2014). Data mining methods applied to a digital forensics task for supervised machine learning. Computational Intelligence in Digital Forensics: Forensic Investigation and Applications, Springer.","DOI":"10.1007\/978-3-319-05885-6_17"},{"key":"ref_137","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1016\/j.datak.2012.12.006","article-title":"An experimental study on the use of nearest neighbor-based imputation algorithms for classification tasks","volume":"84","author":"Hruschka","year":"2013","journal-title":"Data Knowl. Eng."},{"key":"ref_138","first-page":"425","article-title":"An overview on handling anti forensic issues in android devices using forensic automator tool","volume":"Volume 1","author":"Bhushan","year":"2022","journal-title":"Proceedings of the 2022 IEEE International Conference on Signal Processing, Informatics, Communication and Energy Systems (SPICES)"},{"key":"ref_139","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1016\/j.inffus.2017.10.006","article-title":"A survey on deep learning for big data","volume":"42","author":"Zhang","year":"2018","journal-title":"Inf. Fusion"},{"key":"ref_140","doi-asserted-by":"crossref","unstructured":"Al Neaimi, M., Al Hamadi, H., Yeun, C.Y., and Zemerly, M.J. (2020, January 25\u201326). Digital forensic analysis of files using deep learning. Proceedings of the 2020 3rd International Conference on Signal Processing and Information Security (ICSPIS), Dubai, United Arab Emirates.","DOI":"10.1109\/ICSPIS51252.2020.9340141"},{"key":"ref_141","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1145\/3065386","article-title":"ImageNet classification with deep convolutional neural networks","volume":"60","author":"Krizhevsky","year":"2017","journal-title":"Commun. ACM"},{"key":"ref_142","first-page":"91","article-title":"Artificial intelligence based model for incident response","volume":"Volume 3","author":"Hasan","year":"2011","journal-title":"Proceedings of the 2011 International Conference on Information Management, Innovation Management and Industrial Engineering"},{"key":"ref_143","doi-asserted-by":"crossref","unstructured":"Du, X., Le, Q., and Scanlon, M. (2020, January 15\u201319). Automated artefact relevancy determination from artefact metadata and associated timeline events. Proceedings of the 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), Dublin, Ireland.","DOI":"10.1109\/CyberSecurity49315.2020.9138874"},{"key":"ref_144","doi-asserted-by":"crossref","unstructured":"Toraskar, T., Bhangale, U., Patil, S., and More, N. (2019, January 26\u201328). Efficient computer forensic analysis using machine learning approaches. Proceedings of the 2019 IEEE Bombay Section Signature Conference (IBSSC), Mumbai, India.","DOI":"10.1109\/IBSSC47189.2019.8973099"},{"key":"ref_145","doi-asserted-by":"crossref","unstructured":"Mosli, R., Li, R., Yuan, B., and Pan, Y. (2016, January 10\u201311). Automated malware detection using artifacts in forensic memory images. Proceedings of the 2016 IEEE Symposium on Technologies for Homeland Security (HST), Waltham, MA, USA.","DOI":"10.1109\/THS.2016.7568881"},{"key":"ref_146","doi-asserted-by":"crossref","unstructured":"Lashkari, A.H., Li, B., Carrier, T.L., and Kaur, G. (2021, January 18\u201319). Volmemlyzer: Volatile memory analyzer for malware classification using feature engineering. Proceedings of the 2021 Reconciling Data Analytics, Automation, Privacy, and Security: A Big Data Challenge (RDAAPS), Hamilton, ON, Canada.","DOI":"10.1109\/RDAAPS48126.2021.9452028"},{"key":"ref_147","doi-asserted-by":"crossref","unstructured":"Liew, S.P., and Ikeda, S. (2019, January 9\u201312). Detecting adversary using Windows digital artifacts. Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9006552"},{"key":"ref_148","first-page":"1","article-title":"Machine learnin\u0123-based detection of C&C channels with a focus on the locked shields cyber defense exercise","volume":"Volume 900","author":"Meier","year":"2019","journal-title":"Proceedings of the 2019 11th International Conference on Cyber Conflict (CyCon)"},{"key":"ref_149","doi-asserted-by":"crossref","first-page":"111789","DOI":"10.1109\/ACCESS.2023.3321680","article-title":"A meta-heuristic method for reassemble bifragmented intertwined JPEG image files in digital forensic investigation","volume":"11","author":"Ali","year":"2023","journal-title":"IEEE Access"},{"key":"ref_150","doi-asserted-by":"crossref","first-page":"728","DOI":"10.1109\/ACCESS.2022.3233404","article-title":"Fronesis: Digital forensics-based early detection of ongoing cyber-attacks","volume":"11","author":"Dimitriadis","year":"2022","journal-title":"IEEE Access"},{"key":"ref_151","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/S1353-4858(11)70086-1","article-title":"Advanced persistent threats and how to monitor and deter them","volume":"2011","author":"Tankard","year":"2011","journal-title":"Netw. Secur."},{"key":"ref_152","unstructured":"(2019). Information Technology\u2014Electronic Discovery\u2014Part 1: Overview and Concepts (Standard No. ISO\/IEC 27050-1:2019). Available online: https:\/\/www.iso.org\/standard\/78647.html."},{"key":"ref_153","unstructured":"(2015). Information Technology\u2014Security Techniques\u2014Incident Investigation Principles and Processes (Standard No. ISO\/IEC 27043:2015). Available online: https:\/\/www.iso.org\/standard\/44407.html."},{"key":"ref_154","unstructured":"(2024, September 26). SANS Digital Forensics and Incident Response Blog|Consortium of Digital Forensic Specialists Is Launched; Will Focus on Standards and Advocacy|SANS Institute. Available online: https:\/\/www.sans.org\/blog\/consortium-of-digital-forensic-specialists-is-launched-will-focus-on-standards-and-advocacy\/."},{"key":"ref_155","unstructured":"(2024, September 26). CDFS-Advocacy. Available online: https:\/\/cdfs.org\/advocacy."},{"key":"ref_156","unstructured":"Turchi, F., and Giardiello, G. (2023). Developing a Judicial Cross-Check System for Case Searching and Correlation Using a Standard for the Evidence. European Law Enforcement Research Bulletin, CEPOL."},{"key":"ref_157","doi-asserted-by":"crossref","first-page":"S102","DOI":"10.1016\/j.diin.2015.01.014","article-title":"Leveraging CybOX\u2122 to standardize representation and exchange of digital forensic information","volume":"12","author":"Casey","year":"2015","journal-title":"Digit. Investig."},{"key":"ref_158","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1016\/j.diin.2017.08.002","article-title":"Advancing coordinated cyber-investigations and tool interoperability using a community developed specification language","volume":"22","author":"Casey","year":"2017","journal-title":"Digit. Investig."},{"key":"ref_159","unstructured":"Houck, M.M. (2023). Organization of Scientific Area Committees (OSAC) for Forensic Science. Encyclopedia of Forensic Sciences, Elsevier. [3rd ed.]."},{"key":"ref_160","doi-asserted-by":"crossref","unstructured":"Casey, E., Barnum, S., Griffith, R., Snyder, J., van Beek, H., and Nelson, A. (2018). The Evolution of Expressing and Exchanging Cyber-Investigation Information in a Standardized Form, Springer. Number 39, Handling and Exchanging Electronic Evidence Across Europe.","DOI":"10.1007\/978-3-319-74872-6_4"}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/13\/12\/333\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T16:51:55Z","timestamp":1760115115000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/13\/12\/333"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,11]]},"references-count":160,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2024,12]]}},"alternative-id":["computers13120333"],"URL":"https:\/\/doi.org\/10.3390\/computers13120333","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,11]]}}}