Ask Homework Help/Study Tips Expert

In this assignment , you will be asked to forensically examine a hard drive for evidence. Your assignment is to examine the drive, gather evidence in a forensically-sound manner, and present a report of your investigation. The incident in question occurred in October, 2016. You should focus your investigation on that time window.

1. The Investigation Report - this is really the whole package

2. Physical evidence tag/label. Refer to textbook for information that should be included. If you use a template or example from the Interwebs, site your sources. ("Appendix A" to investigation report.)

3. Key Evidence listing. Should be a table of (at a minimum) files examined and their hashes. ("Appendix B" to the investigation report.)

4. Tools listing. Should be a table of (at a minimum) executables used to examine or process files, and their hashes. Definitely list a tool like "pasco". You probably don't need to include commands like "cd" or "ls". Unless you're doing a live system acquisition. ("Appendix C" to the investigation report.)

5. Your case investigation activity log (your notes). Either include scans of your notebook, or photos of the pages, or if you use electronic notes, the notes file.

A note on presenting actual evidence files. Do NOT create a printed version of the super timeline. In your report, highilight key events (e.g. software was installed, a document was deleted) and include the key timeline entry rows for the event, or the start/end of the event (software installation may produce many dozens of pages). Also Do NOT try to hexdumpthe entire hard drive and print it out.

INVESTIGATION REPORT:

The report should clearly and concisely present evidence. Avoid drawing any conclusions in the report. Start each section with a summary of the key findings for that section. List the basic steps you took to arrive at that conclusion. Make references to your notes ("see Case 001 notes, page 2"). Pictures with labels, or screenshots of tool output, are appropriate. Hashes are appropriate. Time and date labels of the steps are appropriate. Explanations such as "this file is of type XYZ and includes data about ABC" are appropriate. Pasting your command history from the terminal is too much detail. Use "Page X of YY" on every page. Label every page with the Case Number (you can make one up).

1. Title Page:

"CS 447/547: Case 0000-001, October 2016", author's name. File name.pdf.

2. Executive Summary

This should begin something like: "In the investigation of Case 0000-001, involving the examination of a suspect harddrive, I reviewed the filesystem, including X user profile(s), examined the activity of user "", and recovered Z deleted files. The evidence included in this report includes the following:" Use your own words, or mine.

3. Physical Evidence:

List the information you can determine from the drive you received, without opening it up and exposing the platters. Not necessary for this investigation.

4. File Systems and Partitions:

List the information you can determine about the file systems contained on this drive. Demonstrate that you have not altered the evidence.

5. Computer System Information

Mount the partitions and examine their contents. List the information you can determine about the system this was running on (e.g. what OS?, what users present? what software installed? important registry key values?)

6. Deleted files

Recover key deleted files and report on them.

7. Web browsing history

In one user's home directory, there is evidence of web-browsing activity. What can you determine from it?

8. Recovered emails

In one user's home directory, there is email. What can you recover from it?

9. Appendix A: Physical evidence

10. Appendix B: Key digital evidence

11. Appendix C: Tools used during investigation

12. Appendix D: Investigator's Notes

Homework Help/Study Tips, Others

  • Category:- Homework Help/Study Tips
  • Reference No.:- M92026171

Have any Question?


Related Questions in Homework Help/Study Tips

Review the website airmail service from the smithsonian

Review the website Airmail Service from the Smithsonian National Postal Museum that is dedicated to the history of the U.S. Air Mail Service. Go to the Airmail in America link and explore the additional tabs along the le ...

Read the article frank whittle and the race for the jet

Read the article Frank Whittle and the Race for the Jet from "Historynet" describing the historical influences of Sir Frank Whittle and his early work contributions to jet engine technologies. Prepare a presentation high ...

Overviewnow that we have had an introduction to the context

Overview Now that we have had an introduction to the context of Jesus' life and an overview of the Biblical gospels, we are now ready to take a look at the earliest gospel written about Jesus - the Gospel of Mark. In thi ...

Fitness projectstudents will design and implement a six

Fitness Project Students will design and implement a six week long fitness program for a family member, friend or co-worker. The fitness program will be based on concepts discussed in class. Students will provide justifi ...

Read grand canyon collision - the greatest commercial air

Read Grand Canyon Collision - The greatest commercial air tragedy of its day! from doney, which details the circumstances surrounding one of the most prolific aircraft accidents of all time-the June 1956 mid-air collisio ...

Qestion anti-trustprior to completing the assignment

Question: Anti-Trust Prior to completing the assignment, review Chapter 4 of your course text. You are a manager with 5 years of experience and need to write a report for senior management on how your firm can avoid the ...

Question how has the patient and affordable care act of

Question: How has the Patient and Affordable Care Act of 2010 (the "Health Care Reform Act") reshaped financial arrangements between hospitals, physicians, and other providers with Medicare making a single payment for al ...

Plate tectonicsthe learning objectives for chapter 2 and

Plate Tectonics The Learning Objectives for Chapter 2 and this web quest is to learn about and become familiar with: Plate Boundary Types Plate Boundary Interactions Plate Tectonic Map of the World Past Plate Movement an ...

Question critical case for billing amp codingcomplete the

Question: Critical Case for Billing & Coding Complete the Critical Case for Billing & Coding simulation within the LearnScape platform. You will need to create a single Microsoft Word file and save it to your computer. A ...

Review the cba provided in the resources section between

Review the CBA provided in the resources section between the Trustees of Columbia University and Local 2110 International Union of Technical, Office, and Professional Workers. Describe how this is similar to a "contract" ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As