Drug trafficking in the digital era is increasingly sophisticated with the utilization of information technology, one of which is the use of steganography techniques to hide information in digital media. This research analyzes the digital evidence hidden in steganography files using the Live Forensics approach. The method used in this research is the National Institute of Standards and Technology (NIST), which consists of four main stages: collection, examination, analysis, and reporting. Digital evidence acquisition was conducted on active devices to obtain data stored in RAM as well as traces of activity in the TOR Browser and Telegram apps. The analysis process used forensic tools such as FTK Imager, WinHex, and Steghide to detect and extract hidden messages in the steganography files. During the investigation, there were several technical challenges, such as the use of TOR Browser which made it difficult to trace the source of the data traffic, as well as other anti-forensic techniques that attempted to erase traces of communication and file storage locations. Addressing these challenges requires live forensics strategies and the utilization of volatile memory to access information that is not permanently stored. The results show that the Live Forensics method is effective in uncovering digital evidence related to drug communication and trafficking, including the storage location of evidence disguised through steganography. With these findings, steganalysis techniques can be used as anti-forensic mitigation in cyber crime investigations. This research contributes to the development of the digital forensics field by demonstrating the successful application of a combination of live forensics acquisition and steganalysis techniques in real-life situations. In addition, the findings generated can be used as a reference in designing standard procedures for investigating cybercrime cases that utilize steganography techniques.
Copyrights © 2025