Table of Contents:
  • Foreword
  • Technical Working Group for the Investigation of High Technology Crimes
  • Ch. 1. Introduction and investigative issues
  • ch. 2. Tracing an Internet address to a source
  • ch. 3. Investigations involving e-mail
  • ch. 4. Investigations involving web sites
  • ch. 5. Investigations involving instant message services, chat rooms, and IRC
  • ch. 6. Investigations involving file sharing networks
  • ch. 7. Investigations of network intrusion/denial of service
  • ch. 8. Investigations involving bulletin boards, message boards, listservs, and newsgroups
  • ch. 9. Legal issues
  • Appx. A. Glossary
  • Appx. B. Domain name extensions
  • Appx. C. Accessing detailed headers in e-mail messages
  • Appx. D. File sharing investigative suggested checklist
  • Appx. E. Simple subpoenas and reports
  • Appx. F. Examples of potential sources of evidence in network investigations
  • Appx. G. Sample language for preservation request letters unde 18 U.S.C. 2703 (f)
  • Appx. H. Sample language for 2703(d) court order and application
  • Appx. I. Technical resource list
  • Appx. J. Legal resource list
  • Appx. K. List of organizations.