Digital Forensics Analysts
In 2016, the central bank of Bangladesh suffered one of the biggest bank heists in history — a criminal gang managed to steal $81 million from the country's largest bank, which was under tight security. That gang didn't storm the bank or fire a single shot like you'd see in the movies — it was an online heist. A group of internet hackers managed to break into the bank's computer systems and transfer $81 million from its accounts into other accounts belonging to them. That incident wasn't the first of its kind, nor the last — every day, thousands of financial institutions and businesses around the world face hacking attempts targeting their websites and accounts, whether for theft, ransom, or sometimes even a cyberterrorism attack meant to disrupt the operations of a country's sovereign institutions. For example, in 2022, dozens of American airports had their websites disrupted after being hit by hacker attacks. Hackers use specialized techniques, software, and specific viruses that let them launch cyberattacks, whether on companies' computer systems or even individuals' personal social media accounts. Any hacking or intrusion carried out online is called cybercrime, and it's no minor matter — most of it can cost the institutions targeted millions of dollars in losses. Cybercrimes are of course subject to extensive security investigations to track down the perpetrators and hackers and secure computer systems against any future attacks. That's why there are experts called "digital forensics investigators" who are responsible for investigating cybercrimes, searching for digital evidence, tracking down perpetrators, and uncovering the vulnerabilities in computer systems that were exploited in the breach. In the next paragraph, you'll learn in detail about the nature of the work digital forensics investigators do.
Meet the Writer: Waleed Abo Omiraa
What You'll Actually Do
The core tasks and responsibilities that fill a typical day.
- Adhere to legal policies and procedures related to handling digital media.
- Analyze log files or other digital information to identify the perpetrators of network intrusions.
- Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
- Create system images or capture network settings from information technology environments to preserve as evidence.
- Develop plans for investigating alleged computer crimes, violations, or suspicious activity.
- Develop policies or requirements for data collection, processing, or reporting.
- Duplicate digital evidence to use for data recovery and analysis procedures.
- Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.
- Maintain cyber defense software or hardware to support responses to cyber incidents.
- Maintain knowledge of laws, regulations, policies or other issuances pertaining to digital forensics or information privacy.
- Perform file signature analysis to verify files on storage media or discover potential hidden files.
- Perform forensic investigations of operating or file systems.
- Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.
- Preserve and maintain digital forensic evidence for analysis.
- Recommend cyber defense software or hardware to support responses to cyber incidents.
- Recover data or decrypt seized data.
- Write and execute scripts to automate tasks, such as parsing large data files.
- Write cyber defense recommendations, reports, or white papers using research or experience.
- Write reports, sign affidavits, or give depositions for legal proceedings.
- Write technical summaries to report findings.