An automation is a program which consists of files (compiled executable, scripts, etc.) and may access resources on the
TS (other files, libraries, peripherals, etc.). It is worth noting that any accesses to system resources produce a potential
modification of the system state which may be revealed by a digital forensic analysis. Unfortunately for the AM, not all the
traces left by the automation are suitable to prove his presence in a given place at a given time. Some of these traces may
reveal the execution of the automation and expose the attempt of false alibi instead. Substantially, two categories of evidence
can be distinguished: wanted and unwanted evidence.