A Step-by-Step Guide on Database Forensics in Pyramid Schemes Cases

Work Tips
2024-09-24

Pyramid schemes are characterized by a distinct hierarchical structure, primarily driven by a mechanism of recruiting new members. When law enforcement investigates these schemes, they often rely on database records to analyze this structure. These records detail the relationships between superiors and subordinates, allowing investigators to map out the organizational dynamics. In this article, we will explore how to utilize the database forensics tool to effectively analyze database files associated with pyramid schemes.

Case Anlysis

In August 2021, a XXX City Public Security Bureau cracked an illegal economic pyramid scheme case. An illegal pyramid scheme case centered on the sale of health products was successfully cracked, which attracted widespread attention from the society.

Following the resolution of the case, the focus shifted to analyzing the company’s organizational structure. With over 3,000 individuals involved, investigators faced a significant challenge. Relying solely on manual methods would require considerable time and effort, potentially exceeding a week. To expedite the process, they sought assistance from SalvationDATA to find a more efficient solution for this kind ofdatabase forensics.

1. Check case infomation in database files.

copied-database-files

2. Reinstall a database of the same version, mysql5.7.44, and import the database file. Connect through the navicat tool and view the database record information.

3. Import the required database file and replace the database file. Then view it through navicat.

replaced-database-files

Steps to Perform Database Forensics

Step 1. Load the database file with DBF Database Forensics Analysis System from SalvationDATA.

dbf-from-salvationdatacase-information-in-dbf

Step 2.  Click  “analyze” to start analyze the database file, and get the data from it.

select-a-database-file-to-analyze

Step 3.  View the data

view-the-data

Step 4. Choose the “Hierarchica” to analyze the selection table.

hierarchical-analysis

Step 5. Choose the” id “and “pid”, and select “realname” as the node name to help read the graph.

match-associated-fields

Step 6.  Get the hierarchical relationship map.

hierarchical-relationship-map

Here you can choose to export as a picture or export as a project file to facilitate the case handling unit to view:

export-data

Also interested in other database forensics cases?

How to Troubleshoot SQL Server Database in Recovery?

A Complete Guide for Database Analysis : 5 Steps

Mastering Corrupt Database Recovery: Essential Tips

Conclusion

It is challenging to analyze large database files by using traditional manual methods. This approach not only consumes significant time and resources but can also compromise accuracy due to the complexity and volume of data. Professional database forensics software, like  DBF Database Forenscis from SalvationDARA, has revolutionized case detection. Its ability to automatically classify and organize data enables quick identification of key information, such as personnel structure, capital flow, and communication networks within pyramid scheme organizations. This streamlined process not only reduces the case analysis cycle dramatically but also enhances the accuracy and integrity of data processing.