Two-Step Injection Method for Collecting Digital Evidence in Digital Forensics


  • Nana Rachmana Syambas Telematics Laboratory, School of Electrical and Informatics Engineering, Institut Teknologi Bandung, Jl. Ganesha No. 10, Bandung 40132, Indonesia
  • Naufal El Farisi Telematics Laboratory, School of Electrical and Informatics Engineering, Institut Teknologi Bandung, Jl. Ganesha No. 10, Bandung 40132, Indonesia



In digital forensic investigations, the investigators take digital evidence from computers, laptops or other electronic goods. There are many complications when asuspect or related person does not want to cooperate or has removed digital evidence. Alot of research has been done with the goal of retrieving data from flash memory orother digital storage media from which the content has been deleted. Unfortunately,such methods cannot guarantee that all data will be recovered. Most data can only berecovered partially and sometimes not perfectly, so that some or all files cannot beopened. This paper proposes the development of a new method for the retrieval ofdigital evidence called the Two-Step Injection method (TSI). It focuses on theprevention of the loss of digital evidence through the deletion of data by suspects orother parties. The advantage of this method is that the system works in secret and can becombined with other digital evidence applications that already exist, so that theaccuracy and completeness of the resulting digital evidence can be improved. Anexperiment to test the effectiveness of the method was set up. The developed TSIsystem worked properly and had a 100% success rate.


