**Abstract**

Digital forensic investigators are faced with multimedia retrieval and discovery challenges that require innovation and application of evolving methodologies. This work is made more difficult in critical infra-structure environments where the acquired evidence is in many formats, types and presentations. Penetration testing is one of the techniques used to focus an investigation and to target the potential case information from the vulnerability identification phase, through to the media identification phase. In this chapter a review of these processes is made and a framework example developed to show how the investigator discovers relevant evidence. The problem for the digital investigator is the vast array of media in which evidence is stored or transmitted. Some work is from live retrieval and others static. A framework of methods that is flexible and adaptable to the context of investigation is proposed and the discovery methods for multimedia environments elaborated.

**Keywords:** penetration testing, digital forensics, critical infrastructures, evidence extraction, process framework
